Additional scan result of Farbar Recovery Scan Tool (x64) Version:16-08-2015 Ran by [removed] (2015-08-17 11:19:19) Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\INetCache\IE\EWLM6RJ4 Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-742872120-2989202850-3023506694-500 - Administrator - Disabled) Guest (S-1-5-21-742872120-2989202850-3023506694-501 - Limited - Disabled) miket_000 (S-1-5-21-742872120-2989202850-3023506694-1001 - Administrator - Enabled) => C:\Users\miket_000 ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Bitdefender Antivirus Free Edition (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Antivirus Free Edition (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Reader XI (11.0.12) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated) Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden AMD Catalyst Install Manager (HKLM\...\{7BABDF85-566A-FCC6-E6FE-12DCFF3F9FEB}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) AMD VISION Engine Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AT&T Troubleshoot & Resolve (HKLM-x32\...\ATT-AT&T Troubleshoot & Resolve) (Version: 8.4.1.11 - AT&T) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.4 - Atheros Communications Inc.) Backup Manager v4 (x32 Version: 4.0.0.0059 - NTI Corporation) Hidden Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Bitdefender Antivirus Free Edition (HKLM\...\BitDefender Gonzales) (Version: 1.0.21.1099 - Bitdefender) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brother MFL-Pro Suite MFC-7340 (HKLM-x32\...\{46E1B1F2-A279-4356-9B17-029F9CC72EAE}) (Version: 2.0.0.0 - Brother Industries, Ltd.) Citrix Online Launcher (HKLM-x32\...\{6740FE60-43C1-4D15-8C4A-001624134B14}) (Version: 1.0.312 - Citrix) Classic Shell (HKLM\...\{CB00799C-0E4F-4FD1-A046-BD24321BCDFF}) (Version: 3.6.5 - IvoSoft) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.44.51 - Conexant) Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version: 3.0 - CutePDF.com) CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4220.52 - CyberLink Corp.) Delicious: Emily's True Love Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden eBay Worldwide (HKLM-x32\...\{A694AF57-9891-4D62-824C-7E55A1361A14}) (Version: 2.3.0630 - OEM) Epic (HKLM\...\Epic) (Version: - ) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ETDWare PS/2-X64 11.6.9.001_WHQL (HKLM\...\Elantech) (Version: 11.6.9.001 - ELAN Microelectronic Corp.) EZPlugin (HKLM-x32\...\{7E1B9573-D569-49BC-9AC0-CBBBDD476222}) (Version: 1.1.05 - Webcetera) Gateway Device Fast-lane (HKLM\...\{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}) (Version: 1.00.3007 - Gateway Incorporated) Gateway MyBackup (HKLM-x32\...\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0059 - NTI Corporation) Gateway Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3006 - Gateway Incorporated) Gateway Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3011 - Gateway Incorporated) Google Photos Backup (HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\Google Photos Backup) (Version: 1.1.0.239 - Google, Inc.) GoToMeeting 7.2.4.3215 (HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\GoToMeeting) (Version: 7.2.4.3215 - CitrixOnline) Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Gateway Incorporated) iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.) Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.6 - Gateway) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3004 - Gateway Incorporated) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.1.177.0 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 39.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden Nero 12 Essentials OEM.a01 (HKLM-x32\...\{9BF0D9FE-9893-4647-81B9-17B7BEA4E6FD}) (Version: 12.5.00000 - Nero AG) Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden Prerequisite installer (x32 Version: 12.0.0002 - Nero AG) Hidden Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.05 - Qualcomm Atheros) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.28124 - Realtek Semiconductor Corp.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Spotify (HKLM-x32\...\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB) Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden The Weather Channel App (HKLM-x32\...\The Weather Channel App) (Version: - ) Travelers AgentBrowserConfiguration (HKLM-x32\...\{15E5B0F4-3E84-4EB1-B5C9-EC618B339FD6}) (Version: 1.0.55.0 - Travelers, Inc.) Travelers AgentBrowserConfiguration (HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\{1989ca41-91a5-4cc2-9138-c5353fad12a0}) (Version: 1.0.29.0 - Travelers, Inc.) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent) WildTangent Games App (x32 Version: 4.0.9.3 - WildTangent) Hidden Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-742872120-2989202850-3023506694-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\miket_000\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-742872120-2989202850-3023506694-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\miket_000\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-742872120-2989202850-3023506694-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\1157\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) CustomCLSID: HKU\S-1-5-21-742872120-2989202850-3023506694-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\miket_000\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-742872120-2989202850-3023506694-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\miket_000\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.) ==================== Restore Points ========================= ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {01DE4BEB-947A-458E-A0C1-9F83A03BBE38} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Gateway\Live Updater\liveupdater_agent.exe [2012-06-21] () Task: {189CEE7C-BCB9-4740-883F-9CAEACA8BD92} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation) Task: {212BF4B5-CACA-44E4-9518-5F9BA9B810B2} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-01-29] (Microsoft) Task: {405E54B8-AB61-47F0-9ADB-9BB1BD8AC0E9} - System32\Tasks\G2MUpdateTask-S-1-5-21-742872120-2989202850-3023506694-1001 => C:\Users\miket_000\AppData\Local\Citrix\GoToMeeting\3215\g2mupdate.exe [2015-08-12] (Citrix Online, a division of Citrix Systems, Inc.) Task: {925887AF-D0AB-47B2-9146-6CFC3DADC635} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-12] (Microsoft Corporation) Task: {93617B25-5FDD-4E84-B520-89F5286D3ADF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-742872120-2989202850-3023506694-1001Core => C:\Users\miket_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-04-27] (Google Inc.) Task: {AB9FFBB1-4814-423A-81F7-D29BD6309AE4} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation) Task: {B374A723-C266-48DF-ABC3-38EF942FAEB8} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser Task: {B851924C-7113-481F-912E-240447114D9D} - System32\Tasks\Power Management => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [2012-08-22] (Acer Incorporated) Task: {C35B866E-B9B5-496A-9DE0-D93BC57BEAB1} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation) Task: {C7901507-C4C7-4E63-8BED-777DB73C9F6A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {C971B406-EF22-470A-874F-46CAD9D547B3} - System32\Tasks\G2MUploadTask-S-1-5-21-742872120-2989202850-3023506694-1001 => C:\Users\miket_000\AppData\Local\Citrix\GoToMeeting\3215\g2mupload.exe [2015-08-12] (Citrix Online, a division of Citrix Systems, Inc.) Task: {CA3F79B6-1A94-44BF-9E81-C9A5AD6288A5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D253E569-8FC2-433D-92BB-F0ED8677C8F3} - System32\Tasks\ALU => C:\Program Files (x86)\Gateway\Live Updater\updater.exe [2012-08-29] () Task: {DF43220F-2D59-4743-B357-1CE577D702D0} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation) Task: {FE30C5E0-EB8F-4C58-A141-666BBE8A664D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-742872120-2989202850-3023506694-1001UA => C:\Users\miket_000\AppData\Local\Google\Update\GoogleUpdate.exe [2015-04-27] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-742872120-2989202850-3023506694-1001.job => C:\Users\miket_000\AppData\Local\Citrix\GoToMeeting\3215\g2mupdate.exe Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-742872120-2989202850-3023506694-1001.job => C:\Users\miket_000\AppData\Local\Citrix\GoToMeeting\3215\g2mupload.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-742872120-2989202850-3023506694-1001Core.job => C:\Users\miket_000\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-742872120-2989202850-3023506694-1001UA.job => C:\Users\miket_000\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-05-11 16:07 - 2013-03-19 12:07 - 00696632 _____ () C:\Program Files\Bitdefender\Antivirus Free Edition\sqlite3.dll 2015-05-11 16:07 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Antivirus Free Edition\BDMetrics.dll 2014-02-17 10:37 - 2013-10-23 16:24 - 00087600 _____ () C:\WINDOWS\System32\cpwmon64.dll 2014-07-04 22:33 - 2014-07-04 22:33 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2013-03-20 12:19 - 2012-09-25 11:26 - 01163264 _____ () C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe 2014-07-04 22:33 - 2014-07-04 22:33 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2012-08-23 01:26 - 2012-08-23 01:26 - 00465384 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\sqlite3.dll 2012-08-23 01:25 - 2012-08-23 01:25 - 00125504 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\MailConverter32.dll 2012-08-23 01:26 - 2012-08-23 01:26 - 00155712 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\VolumeSnapshot.dll 2012-08-23 01:25 - 2012-08-23 01:25 - 00118336 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\Online.dll 2012-08-23 01:25 - 2012-08-23 01:25 - 01081408 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\ACE.dll 2012-08-23 01:25 - 2012-08-23 01:25 - 00052288 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\OsSettingPort.dll 2012-08-23 01:26 - 2012-08-23 01:26 - 00727616 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\OutlookShadow.dll 2013-03-20 12:19 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\miket_000\OneDrive:ms-properties AlternateDataStreams: C:\Users\miket_000\Downloads\readerdc_en_ra_install (1).exe:BDU AlternateDataStreams: C:\Users\miket_000\Downloads\readerdc_en_ra_install (2).exe:BDU AlternateDataStreams: C:\Users\miket_000\Downloads\readerdc_en_ra_install.exe:BDU ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\billerweb.com -> billerweb.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\ezlynx.com -> hxxps://ezlynx.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\farmersinsurance.com -> farmersinsurance.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\foremostproducers.com -> foremostproducers.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\foremoststar.com -> foremoststar.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\msbexpress.net -> msbexpress.net IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\safeco.com -> hxxps://agent.safeco.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\travelers.com -> hxxp://travelers.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\travelers.com -> hxxps://travelers.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\travelerspc.com -> hxxp://travelerspc.com IE trusted site: HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\travelerspc.com -> hxxps://travelerspc.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-742872120-2989202850-3023506694-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\miket_000\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKU\S-1-5-21-742872120-2989202850-3023506694-1001\...\StartupApproved\Run: => "DW7" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{1AE9768E-8422-443E-A2CF-8DD167E28A37}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{C7F880EC-B37E-4D6B-B49D-0322DBF83B46}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe FirewallRules: [{B9EC22AF-1821-416D-AF8F-9C5950B25052}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe FirewallRules: [{7369D8C6-95E1-4EDD-B276-BBD47D1640FE}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe FirewallRules: [{7418FED6-FEF3-418B-B683-9EC37842D864}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe FirewallRules: [{917B84D0-4BE5-4CDC-A9A6-77D1FBED7231}] => (Allow) C:\Program Files (x86)\NTI\Gateway MyBackup\FileExplorer.exe FirewallRules: [{24BAEF47-97A6-494B-9411-A7A70255FA41}] => (Allow) C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe FirewallRules: [{D74DC7A7-E77E-45F1-935E-9C2350FFDA12}] => (Allow) C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManager.exe FirewallRules: [{5B50FB49-6A63-41FE-B527-8AC5B26BEA7E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{FA97B670-BE73-4AB9-8EF3-3E8757780D73}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3F16A5D1-8D24-4F1A-923F-2D6B524F523C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{755926A8-499A-4D70-974A-D80ABC6D1E7E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{D32E3524-1412-4106-9FFB-0F050383EF26}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E86EF5BE-5D3B-4B7F-93B9-435DF5763449}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A3DE32E0-B9CB-4E01-91B1-E440F4CA518E}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/17/2015 10:58:16 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: Windows cannot access the file C:\Windows\SysWOW64\winhttp.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft .NET Error Reporting Shim because of this error. Program: Microsoft .NET Error Reporting Shim File: C:\Windows\SysWOW64\winhttp.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C0000185 Disk type: 3 Error: (08/17/2015 10:58:16 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: dw20.exe, version: 2.0.50727.8007, time stamp: 0x537d7bc1 Faulting module name: WINHTTP.dll, version: 6.3.9600.17415, time stamp: 0x54503b2f Exception code: 0xc0000006 Fault offset: 0x0003beda Faulting process id: 0x11d8 Faulting application start time: 0xdw20.exe0 Faulting application path: dw20.exe1 Faulting module path: dw20.exe2 Report Id: dw20.exe3 Faulting package full name: dw20.exe4 Faulting package-relative application ID: dw20.exe5 Error: (08/17/2015 10:57:04 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17840, time stamp: 0x555fe1bb Faulting module name: winhttp.dll, version: 6.3.9600.17415, time stamp: 0x54503b2f Exception code: 0xc0000006 Fault offset: 0x0003beda Faulting process id: 0x%9 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Faulting package full name: IEXPLORE.EXE4 Faulting package-relative application ID: IEXPLORE.EXE5 Error: (08/17/2015 10:48:28 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: Windows cannot access the file C:\Windows\SysWOW64\winhttp.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft .NET Error Reporting Shim because of this error. Program: Microsoft .NET Error Reporting Shim File: C:\Windows\SysWOW64\winhttp.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C0000185 Disk type: 3 Error: (08/17/2015 10:48:28 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: dw20.exe, version: 2.0.50727.8007, time stamp: 0x537d7bc1 Faulting module name: WINHTTP.dll, version: 6.3.9600.17415, time stamp: 0x54503b2f Exception code: 0xc0000006 Fault offset: 0x0003beda Faulting process id: 0x5dc Faulting application start time: 0xdw20.exe0 Faulting application path: dw20.exe1 Faulting module path: dw20.exe2 Report Id: dw20.exe3 Faulting package full name: dw20.exe4 Faulting package-relative application ID: dw20.exe5 Error: (08/17/2015 10:48:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17840, time stamp: 0x555fe1bb Faulting module name: winhttp.dll, version: 6.3.9600.17415, time stamp: 0x54503b2f Exception code: 0xc0000006 Fault offset: 0x0003beda Faulting process id: 0x%9 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Faulting package full name: IEXPLORE.EXE4 Faulting package-relative application ID: IEXPLORE.EXE5 Error: (08/17/2015 10:47:15 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: Windows cannot access the file C:\Windows\SysWOW64\winhttp.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft .NET Error Reporting Shim because of this error. Program: Microsoft .NET Error Reporting Shim File: C:\Windows\SysWOW64\winhttp.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C0000185 Disk type: 3 Error: (08/17/2015 10:47:15 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: dw20.exe, version: 2.0.50727.8007, time stamp: 0x537d7bc1 Faulting module name: WINHTTP.dll, version: 6.3.9600.17415, time stamp: 0x54503b2f Exception code: 0xc0000006 Fault offset: 0x0003beda Faulting process id: 0x6e8 Faulting application start time: 0xdw20.exe0 Faulting application path: dw20.exe1 Faulting module path: dw20.exe2 Report Id: dw20.exe3 Faulting package full name: dw20.exe4 Faulting package-relative application ID: dw20.exe5 Error: (08/17/2015 10:44:39 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17840, time stamp: 0x555fe1bb Faulting module name: winhttp.dll, version: 6.3.9600.17415, time stamp: 0x54503b2f Exception code: 0xc0000006 Fault offset: 0x0003beda Faulting process id: 0x%9 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Faulting package full name: IEXPLORE.EXE4 Faulting package-relative application ID: IEXPLORE.EXE5 Error: (08/17/2015 10:37:58 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: Windows cannot access the file C:\Windows\SysWOW64\winhttp.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft .NET Error Reporting Shim because of this error. Program: Microsoft .NET Error Reporting Shim File: C:\Windows\SysWOW64\winhttp.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C0000185 Disk type: 3 System errors: ============= Error: (08/17/2015 10:31:52 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home. Error: (08/17/2015 10:20:23 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home. Error: (08/17/2015 10:08:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The AT&T Troubleshoot & Resolve service terminated unexpectedly. It has done this 3 time(s). Error: (08/17/2015 10:08:18 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The AT&T Troubleshoot & Resolve service terminated with the following error: %%4294967295 Error: (08/17/2015 10:08:16 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The AT&T Troubleshoot & Resolve service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. Error: (08/17/2015 10:08:15 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The AT&T Troubleshoot & Resolve service terminated with the following error: %%4294967295 Error: (08/17/2015 10:08:09 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The AT&T Troubleshoot & Resolve service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. Error: (08/17/2015 10:08:06 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The AT&T Troubleshoot & Resolve service terminated with the following error: %%4294967295 Error: (08/17/2015 10:06:39 AM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: NT AUTHORITY) Description: The system watchdog timer was triggered. Error: (08/17/2015 10:06:20 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Superfetch service terminated with the following error: %%1062 Microsoft Office: ========================= Error: (08/17/2015 10:58:16 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: C:\Windows\SysWOW64\winhttp.dllMicrosoft .NET Error Reporting ShimC00001853 Error: (08/17/2015 10:58:16 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: dw20.exe2.0.50727.8007537d7bc1WINHTTP.dll6.3.9600.1741554503b2fc00000060003beda11d801d0d905549c7a3eC:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeC:\WINDOWS\SYSTEM32\WINHTTP.dllc532823b-44f8-11e5-bed2-7054d2805fa2 Error: (08/17/2015 10:57:04 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: IEXPLORE.EXE11.0.9600.17840555fe1bbwinhttp.dll6.3.9600.1741554503b2fc00000060003beda Error: (08/17/2015 10:48:28 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: C:\Windows\SysWOW64\winhttp.dllMicrosoft .NET Error Reporting ShimC00001853 Error: (08/17/2015 10:48:28 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: dw20.exe2.0.50727.8007537d7bc1WINHTTP.dll6.3.9600.1741554503b2fc00000060003beda5dc01d0d904189601ffC:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeC:\WINDOWS\SYSTEM32\WINHTTP.dll66899433-44f7-11e5-bed2-7054d2805fa2 Error: (08/17/2015 10:48:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: IEXPLORE.EXE11.0.9600.17840555fe1bbwinhttp.dll6.3.9600.1741554503b2fc00000060003beda Error: (08/17/2015 10:47:15 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: C:\Windows\SysWOW64\winhttp.dllMicrosoft .NET Error Reporting ShimC00001853 Error: (08/17/2015 10:47:15 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: dw20.exe2.0.50727.8007537d7bc1WINHTTP.dll6.3.9600.1741554503b2fc00000060003beda6e801d0d90398b23d89C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeC:\WINDOWS\SYSTEM32\WINHTTP.dll3b4cd5d2-44f7-11e5-bed2-7054d2805fa2 Error: (08/17/2015 10:44:39 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: IEXPLORE.EXE11.0.9600.17840555fe1bbwinhttp.dll6.3.9600.1741554503b2fc00000060003beda Error: (08/17/2015 10:37:58 AM) (Source: Application Error) (EventID: 1005) (User: ) Description: C:\Windows\SysWOW64\winhttp.dllMicrosoft .NET Error Reporting ShimC00001853 CodeIntegrity: =================================== Date: 2015-07-29 11:08:13.395 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files\Windows Defender\NisSrv.exe that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-07-29 11:07:47.932 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-07-15 10:48:15.005 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume4\PROGRA~2\ACROSO~1\CUTEPD~1\CPWSave.exe that did not meet the Store signing level requirements. Date: 2014-07-15 10:28:32.432 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume4\PROGRA~2\ACROSO~1\CUTEPD~1\CPWSave.exe that did not meet the Store signing level requirements. Date: 2014-07-15 10:26:54.951 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume4\PROGRA~2\ACROSO~1\CUTEPD~1\CPWSave.exe that did not meet the Store signing level requirements. Date: 2014-07-15 10:26:44.596 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume4\PROGRA~2\ACROSO~1\CUTEPD~1\CPWSave.exe that did not meet the Store signing level requirements. ==================== Memory info =========================== Processor: AMD E1-1200 APU with Radeon(tm) HD Graphics Percentage of memory in use: 44% Total physical RAM: 3658.26 MB Available physical RAM: 2028.16 MB Total Virtual: 4810.26 MB Available Virtual: 2523.46 MB ==================== Drives ================================ Drive c: (Gateway) (Fixed) (Total:447.51 GB) (Free:303.28 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 44E5364F) Partition: GPT. ==================== End of log ============================