Additional scan result of Farbar Recovery Scan Tool (x64) Version:17-12-2015 Ran by [removed] (2015-12-17 16:38:58) Running from C:\Users\[removed]\Downloads Windows 10 Home (X64) (2015-11-26 22:54:35) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2324462236-1183297055-1014908895-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2324462236-1183297055-1014908895-503 - Limited - Disabled) Guest (S-1-5-21-2324462236-1183297055-1014908895-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2324462236-1183297055-1014908895-1002 - Limited - Enabled) Rick (S-1-5-21-2324462236-1183297055-1014908895-1001 - Administrator - Enabled) => C:\Users\Rick ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 Premier (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton 360 Premier (Disabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton 360 Premier (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY) ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.9.160 - Adobe Systems, Inc.) AnswerWorks Runtime (HKLM-x32\...\AnswerWorks) (Version: - ) Battlefield Heroes (HKLM-x32\...\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version: - EA Digital illusions) Battlefield Play4Free (HKLM-x32\...\{87686C21-8A15-4b4d-A3F1-11141D9BE094}) (Version: - EA Digital illusions) Best Buy Software Installer (HKLM-x32\...\Best Buy Software Installer) (Version: 2.1.0.30 - Best Buy) Best Buy Software Installer (Version: 2.1.0.30 - Best Buy) Hidden Citrix Online Launcher (HKLM-x32\...\{E5F6D26D-E180-4547-A865-565EAB61000C}) (Version: 1.0.362 - Citrix) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Contents (x32 Version: 1.00.0005 - Corel Corporation) Hidden Corel Applications (HKLM-x32\...\Corel Applications) (Version: - ) Corel VideoStudio Express (HKLM-x32\...\_{CBC7FF57-42A3-414E-B8EA-D971C986BA40}) (Version: 1.5.0.265 - Corel Corporation) Cross Fire En (HKLM-x32\...\Cross Fire_is1) (Version: - Z8Games.com) DeviceIO (x32 Version: 1.00.0005 - Corel Corporation) Hidden DivX Setup (HKLM-x32\...\DivX Setup.divx.com) (Version: 1.0.2.23 - DivX, Inc. ) Easy Photo Scan (HKLM-x32\...\{F2132D5C-4C3F-41A9-865B-68966A06B01C}) (Version: 1.00.0000 - Seiko Epson Corporation) Epson Copy Utility 3.5 (HKLM-x32\...\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.5.0.0 - ) Epson Event Manager (HKLM-x32\...\{10144CFE-D76C-4CFA-81A1-37A1642349A3}) (Version: 3.01.0013 - Seiko Epson Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) e-Sword (HKLM-x32\...\{2CBE100E-B963-4B4B-8435-FEA8F5F93516}) (Version: 10.02.0001 - Rick Meyers) Freecorder 5 (HKLM-x32\...\Freecorder5.11) (Version: 5.11 - Applian Technologies Inc.) Freecorder Toolbar (HKLM-x32\...\Freecorder Toolbar) (Version: 6.8.5.1 - Freecorder) <==== ATTENTION Gateway InfoCentre (HKLM-x32\...\Gateway InfoCentre) (Version: 3.02.3000 - Gateway Incorporated) Gateway Photo Frame 4.2.3.10 (HKLM-x32\...\Gateway Photo Frame) (Version: 4.2.3.10 - I/O Interconnect) Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Gateway Incorporated) Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.02.3006 - Gateway Incorporated) Gateway ScreenSaver (HKLM-x32\...\Gateway Screensaver) (Version: 1.1.0812 - Gateway Incorporated) Gateway Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3017 - Gateway Incorporated) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.) Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden GoToMeeting 7.7.1.4099 (HKU\S-1-5-21-2324462236-1183297055-1014908895-1001\...\GoToMeeting) (Version: 7.7.1.4099 - CitrixOnline) ICA (x32 Version: 1.5.0.265 - Corel Corporation) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3002 - Gateway Incorporated) IncrediMail (x32 Version: 6.6.0.5288 - IncrediMail) Hidden IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5288 - IncrediMail Ltd.) IncrediMail MediaBar 2 Toolbar (HKLM-x32\...\IncrediMail_MediaBar_2 Toolbar) (Version: 6.1.0.7 - IncrediMail MediaBar 2) <==== ATTENTION Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.0.1006 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.1968 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) IPM_V (x32 Version: 1.52 - Corel Corporation) Hidden Java(TM) 6 Update 21 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216021FF}) (Version: 6.0.210 - Oracle) JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0000 - JMICRON Technology Corp.) Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Microsoft LifeCam (HKLM\...\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation) MLE (x32 Version: 1.00.0005 - Corel Corporation) Hidden Mozilla Firefox 43.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0 (x86 en-US)) (Version: 43.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.0.5820 - Mozilla) Need For Speed™ World (HKLM-x32\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.1229 - Electronic Arts) Norton 360 Premier (HKLM-x32\...\N360) (Version: 22.5.5.15 - Symantec Corporation) Number Press 6.5.2 (HKLM-x32\...\{B7D14513-966A-4EB1-AA48-70A9E0C0E9FA}_is1) (Version: - Praeter Software) Number Press Demo 6 (HKLM-x32\...\{7D8F5DDA-EB28-4943-9DDF-B7F7826B7282}_is1) (Version: - Praeter Software) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - ) Paltalk Messenger (HKLM-x32\...\PalTalk8.2) (Version: 10.0 - AVM Software Inc.) PDF Architect (HKLM-x32\...\{80A07844-CA64-4DE4-AB61-D37DDBE8074F}) (Version: 1.0.52.8917 - pdfforge) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.6.0 - Frank Heindörfer, Philip Chinery) Perfection V550 Photo Scanner Driver Update version 3.0.2.0 (HKLM-x32\...\ScannerDriverUpdatePerfection V550 Photo_is1) (Version: 3.0.2.0 - Epson America Inc.) Perfection V550 User’s Guide version 1.0 (HKLM-x32\...\UsersGuidePerfection V550 User’s Guide_is1) (Version: 1.0 - ) Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.) PureHD (x32 Version: 1.00.0005 - Corel Corporation) Hidden QuickTime (HKLM-x32\...\{8DC42D05-680B-41B0-8878-6C14D24602DB}) (Version: 7.55.90.70 - Apple Inc.) RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5969 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.2 - Roxio) Setup (x32 Version: 1.5.0.265 - Corel Corporation) Hidden Share (x32 Version: 1.00.0005 - Corel Corporation) Hidden Share64 (Version: 1.00.0005 - Corel Corporation) Hidden swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.40798 - TeamViewer) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.4053 (x32 Version: 1.1.0 - DivX, Inc) Hidden VDS10 (x32 Version: 1.00.0005 - Corel Corporation) Hidden VIO (x32 Version: 1.00.0005 - Corel Corporation) Hidden Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.00.3008 - Gateway Incorporated) Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Sign-in Assistant (HKLM-x32\...\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2324462236-1183297055-1014908895-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Rick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation) ==================== Restore Points ========================= 28-11-2015 11:12:08 Windows Update 03-12-2015 08:11:42 Windows Update 09-12-2015 13:08:04 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {03713B79-2628-4355-9322-2090E3C0431F} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {0473AC0A-E67D-4239-9AC3-63A3EEB86B34} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {08CA1E7C-37E6-4543-88EB-674414E8E010} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.) Task: {094D3E9C-39F1-49EC-AFCA-AC73722169DE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {0F56987F-AE1A-4B90-974B-405C7B22E041} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {1030A2AC-9D2D-4947-923E-0AC0E1F128D5} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {11322381-119B-4D42-AA5A-C6E5688DE04E} - System32\Tasks\G2MUpdateTask-S-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Users\Rick\AppData\Local\Citrix\GoToMeeting\4099\g2mupdate.exe [2015-12-16] (Citrix Online, a division of Citrix Systems, Inc.) Task: {181C8494-D4DC-4BB7-A8D2-07C3D474BBBE} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\SymErr.exe [2015-11-05] (Symantec Corporation) Task: {255B132D-E75F-4723-96D4-B5AD442EF44E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {25A49F2A-592B-42D5-8567-99976DD9B066} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {3189101C-DD81-4797-8A2C-451E1511A268} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {34A38EDF-87BD-4476-B0FE-DD3DEEFBED04} - System32\Tasks\G2MUploadTask-S-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Users\Rick\AppData\Local\Citrix\GoToMeeting\4099\g2mupload.exe [2015-12-16] (Citrix Online, a division of Citrix Systems, Inc.) Task: {42064B3F-9E01-481B-B831-63CBA2B3D653} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {42BF61B2-A162-4981-8433-1699C6F6096B} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {47D57C3E-5AE9-41F7-9692-4965662E1731} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {4AFF3253-BF65-418F-ADF0-B50624355D08} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {5058B560-09AE-409E-B6D6-7997F79FD3CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {512FDE9B-DBEC-40E3-9891-F4A6D5597BCC} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\WSCStub.exe [2015-11-20] (Symantec Corporation) Task: {5358FBFA-FE66-435C-9E28-7A254A9BDA4B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {572D6588-9F4A-409E-9380-48E0E29108B8} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {5F39965B-0E2F-48DC-8CB8-27B4AF01E1F8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {6065C7FD-5E8D-42C2-8B45-49475D124F2C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {60CD23A3-5A19-47FD-8380-C28C94BC8687} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {6830640F-DD45-40E2-858C-362C883B1B4E} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\SymErr.exe [2015-11-05] (Symantec Corporation) Task: {726683E0-B791-4359-9351-FB4BBEB41AF8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {757CA55F-7BB6-453C-8000-BBC6024181F4} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {77732438-9790-4E22-B66B-B9946985E296} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {80998995-6E57-4B19-9A1A-46455DE18DD6} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {92A1F795-AE43-4ABD-9714-B060F0F8520E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-10] (Adobe Systems Incorporated) Task: {A1C4C12E-3A0F-4102-8741-0279EE14DBEC} - System32\Tasks\Norton 360\Norton Autofix => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\SymErr.exe [2015-11-05] (Symantec Corporation) Task: {A9A55780-70E8-4F8D-81D9-12389AE8968B} - \CCleanerSkipUAC -> No File <==== ATTENTION Task: {AB9D101D-ADFE-4BAF-B8D2-D857C108CB6D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {B157515C-6616-4E4C-AB5C-73A8AAB9624D} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {B4B52048-CC89-4743-8C63-61137D5B0A96} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {B64472BD-D58B-4C6F-97DB-116C59FFFACB} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {B752841F-5678-4909-BC58-6DA3F3280A87} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {BC544385-3AF1-4C7F-8990-B4C914863F15} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {C1936B83-88E2-451F-886C-DEDA0392269C} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {C1B24905-24F8-42BA-8621-7689EDC34778} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {C430026E-42BD-4B54-8B44-2A23691EE6A1} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {D289CA28-D0E3-4DF4-AC5C-5D4EC86A4240} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {D881CB7D-BD7C-4E5E-934E-8165D90989CA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {DBE9377B-9A01-4110-8B81-577D4ECFE833} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {E5EDCE7F-02C6-4008-B903-B8E1B6533976} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {E60CB91F-52B0-44D9-94AE-7B24FE095987} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {E8D1ACF9-632B-472B-97A4-F29A9C0B5C86} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {EC50F22F-FC9D-49C2-BF60-6E6BE485EDE7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {EDBF38C4-406A-4B81-9B56-BE6DF2EA037E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {F1779F30-A7CE-420A-B3D7-1E8520BEAE92} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2324462236-1183297055-1014908895-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {F2DE37BC-EB22-497C-8BEE-9982FCF40139} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {FA8F291F-AD51-4058-B4EE-19BB98033102} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {FFFABB21-FBFE-450E-B580-5FB180156F34} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2324462236-1183297055-1014908895-1001.job => C:\Users\Rick\AppData\Local\Citrix\GoToMeeting\4099\g2mupdate.exe Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2324462236-1183297055-1014908895-1001.job => C:\Users\Rick\AppData\Local\Citrix\GoToMeeting\4099\g2mupload.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2012-07-19 12:32 - 2014-09-22 10:23 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2015-12-03 07:51 - 2015-11-22 05:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-03 07:51 - 2015-11-22 05:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-10-30 02:17 - 2015-10-30 02:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2015-10-30 02:17 - 2015-10-30 02:17 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-12-03 07:50 - 2015-11-22 04:23 - 08005632 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-03 07:50 - 2015-11-22 04:18 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-03 07:51 - 2015-11-22 04:19 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-12-03 07:51 - 2015-11-22 04:21 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2012-11-26 23:54 - 2012-11-26 23:54 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2009-08-03 11:05 - 2009-08-03 11:05 - 00498160 _____ () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe 2010-06-02 19:50 - 2010-06-02 19:50 - 01144104 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2015-12-17 11:44 - 2015-12-17 11:44 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-09 08:29 - 2015-12-09 08:29 - 03682816 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1512.34020.0_x64__8wekyb3d8bbwe\Calculator.exe 2015-12-17 11:44 - 2015-12-17 11:44 - 09737216 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.5.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2014-11-14 08:47 - 2014-11-14 08:47 - 00272808 _____ () C:\Program Files (x86)\IncrediMail\Bin\ImLookExU.dll 2014-11-14 08:47 - 2014-11-14 08:47 - 00033128 _____ () C:\Program Files (x86)\IncrediMail\Bin\IMHttpComm.dll 2014-11-14 08:47 - 2014-11-14 08:47 - 00072104 _____ () C:\Program Files (x86)\IncrediMail\Bin\wlessfp1.dll 2013-10-01 15:02 - 2013-10-01 15:02 - 00108888 _____ () C:\Program Files (x86)\IncrediMail\Bin\pmc.dll 2009-06-12 18:37 - 2009-06-12 18:37 - 00032768 _____ () C:\Program Files (x86)\Gateway Photo Frame\IOIUSBLib.dll 2009-06-12 18:37 - 2009-06-12 18:37 - 00025088 _____ () C:\Program Files (x86)\Gateway Photo Frame\IOIHIDLib.dll 2014-11-14 08:47 - 2014-11-14 08:47 - 00080296 _____ () C:\Program Files (x86)\IncrediMail\bin\ImAppRU.dll 2014-11-14 08:47 - 2014-11-14 08:47 - 00133544 _____ () C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll 2010-06-02 19:51 - 2010-06-02 19:51 - 00095528 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2015-12-17 11:44 - 2015-12-17 11:44 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2015-12-17 11:44 - 2015-12-17 11:44 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2324462236-1183297055-1014908895-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Gateway01.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{45550574-10F7-4CAC-B66D-36BC9E32B96F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5495FA03-60FF-4BC1-AE04-5D938A8075D7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{35F3000D-D312-4921-A59F-01B9D899A872}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{0060EAFA-F19C-423D-A957-A771F4698D79}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [UDP Query User{1763D2A6-0BFD-4A70-88A0-9E7AB24E38FF}C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe] => (Allow) C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe FirewallRules: [TCP Query User{972FCDDC-525F-42C2-8450-78A5D6BB5433}C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe] => (Allow) C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe FirewallRules: [{9F7E8EA1-7366-40EF-9999-D6A8370D13D5}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe FirewallRules: [{786742DB-3497-428C-AE2E-381D680AC024}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe FirewallRules: [{3C15D6E8-BA0D-4FB0-A6AE-FF9109D6C3B2}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe FirewallRules: [{961FDF3E-9F7D-4894-91FF-B32FA10B8ED4}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe FirewallRules: [{BCF6C12B-7714-457A-80B8-0D28529FCE62}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{40A0B8F1-8F73-4FDF-B3BE-98B3DFBA25D8}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{EC6158CE-B495-4DF9-801C-C1D4A869B3B0}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe FirewallRules: [{A4D9034D-E5FD-4F72-A748-54B3644366EC}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe FirewallRules: [UDP Query User{A753B453-ABCC-44CF-B589-7B06EC52424F}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{3F727215-527E-4A53-B908-B47EB4D32921}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [{9F7226FF-E0A7-4FF3-83D8-A12AC397ED55}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{658C0A05-D2FB-409D-A5C3-73855DF6B586}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{6D53E7FC-2FB0-49D2-96D6-FCF2940F3251}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{D76A5155-CCB2-447D-AA77-5825CEF20224}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{F87CE4B3-5E73-445A-9FAD-33736C38B352}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe FirewallRules: [{AB73E8E6-0E85-46EA-8608-925DAF154A09}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe FirewallRules: [{7CB0035A-ADE9-44F3-A764-82CFD8FA90EE}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe FirewallRules: [{A905B897-D43B-43E7-9AD3-ABA25333B4FF}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe FirewallRules: [{94C225B7-5462-4D70-BF08-0D630E3B40BF}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe FirewallRules: [{D9D5D7E0-3478-4C8C-B3E5-F148BA4507EA}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe FirewallRules: [UDP Query User{3B54E1FD-5A20-49E9-ABF6-987652E8B9FA}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{919EA612-F6FA-40C9-87C0-71E4EBA08837}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [{41931EB1-D991-4C26-BFCB-E1CF9352AEB8}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{7771D36D-90EC-4704-AE2B-7FCAAE2B6E21}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{DB73ABD5-59D1-4601-96A1-C3DE3A3BD45F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{9583C9B2-146B-47E8-BEAB-B9DEA408D93B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{6E2950D7-2CAB-4C65-AEAC-EC1787BAEBEC}] => (Allow) C:\Program Files (x86)\Z8Games\CrossFire\CF_G4box.exe FirewallRules: [{BE1D6435-D0E2-47F1-8421-BA6E5462D9D7}] => (Allow) C:\Program Files (x86)\Z8Games\CrossFire\CF_G4box.exe FirewallRules: [{33008088-8364-4C3F-934A-2005E025E829}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{C8927F21-05A7-49E7-B032-A51F20B93E84}] => (Allow) svchost.exe FirewallRules: [{6BCEB5D5-B24F-4A97-B177-182392F8B425}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{7CC965C1-2F84-4CAB-AB9D-BE54907E943B}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe FirewallRules: [{19C0F736-E743-4102-B638-2A2B66583907}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/17/2015 08:42:25 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program IncMail.exe version 6.6.0.5288 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 4cc Start Time: 01d138cc0be7cffa Termination Time: 20 Application Path: C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe Report Id: fbbbf6ab-a4c3-11e5-9cb8-90fba62bb1c9 Faulting package full name: Faulting package-relative application ID: Error: (12/16/2015 10:57:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: XboxIdp.exe, version: 10.0.10586.0, time stamp: 0x5632cb62 Faulting module name: CoreUIComponents.dll, version: 0.0.0.0, time stamp: 0x565185e4 Exception code: 0xc0000005 Fault offset: 0x00000000000780cd Faulting process id: 0x3748 Faulting application start time: 0xXboxIdp.exe0 Faulting application path: XboxIdp.exe1 Faulting module path: XboxIdp.exe2 Report Id: XboxIdp.exe3 Faulting package full name: XboxIdp.exe4 Faulting package-relative application ID: XboxIdp.exe5 Error: (12/14/2015 02:24:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: coreldrw.exe, version: 9.337.0.0, time stamp: 0x3715a32b Faulting module name: coreldrw.exe, version: 9.337.0.0, time stamp: 0x3715a32b Exception code: 0xc0000005 Fault offset: 0x0058ddd5 Faulting process id: 0x1d5c Faulting application start time: 0xcoreldrw.exe0 Faulting application path: coreldrw.exe1 Faulting module path: coreldrw.exe2 Report Id: coreldrw.exe3 Faulting package full name: coreldrw.exe4 Faulting package-relative application ID: coreldrw.exe5 Error: (12/13/2015 05:33:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IncMail.exe, version: 6.6.0.5288, time stamp: 0x524abb1e Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x5654262a Exception code: 0xc0000374 Fault offset: 0x000dc089 Faulting process id: 0x2688 Faulting application start time: 0xIncMail.exe0 Faulting application path: IncMail.exe1 Faulting module path: IncMail.exe2 Report Id: IncMail.exe3 Faulting package full name: IncMail.exe4 Faulting package-relative application ID: IncMail.exe5 Error: (12/12/2015 10:47:12 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IncMail.exe, version: 6.6.0.5288, time stamp: 0x524abb1e Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x5654262a Exception code: 0xc0000374 Fault offset: 0x000dc089 Faulting process id: 0x1820 Faulting application start time: 0xIncMail.exe0 Faulting application path: IncMail.exe1 Faulting module path: IncMail.exe2 Report Id: IncMail.exe3 Faulting package full name: IncMail.exe4 Faulting package-relative application ID: IncMail.exe5 Error: (12/10/2015 06:01:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IncMail.exe, version: 6.6.0.5288, time stamp: 0x524abb1e Faulting module name: ntdll.dll, version: 10.0.10586.0, time stamp: 0x5632d9fc Exception code: 0xc0000374 Fault offset: 0x000dc18c Faulting process id: 0xa08 Faulting application start time: 0xIncMail.exe0 Faulting application path: IncMail.exe1 Faulting module path: IncMail.exe2 Report Id: IncMail.exe3 Faulting package full name: IncMail.exe4 Faulting package-relative application ID: IncMail.exe5 Error: (12/09/2015 01:30:29 PM) (Source: Perflib) (EventID: 1017) (User: ) Description: ASP.NET_2.0.50727 Error: (12/09/2015 01:30:29 PM) (Source: Perflib) (EventID: 1021) (User: ) Description: ASP.NET_2.0.507278 Error: (12/09/2015 01:08:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (12/07/2015 03:32:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: coreldrw.exe, version: 9.337.0.0, time stamp: 0x3715a32b Faulting module name: coreldrw.exe, version: 9.337.0.0, time stamp: 0x3715a32b Exception code: 0xc0000005 Fault offset: 0x0058ddd5 Faulting process id: 0x1a0 Faulting application start time: 0xcoreldrw.exe0 Faulting application path: coreldrw.exe1 Faulting module path: coreldrw.exe2 Report Id: coreldrw.exe3 Faulting package full name: coreldrw.exe4 Faulting package-relative application ID: coreldrw.exe5 System errors: ============= Error: (12/17/2015 11:35:05 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: %%1058 Error: (12/17/2015 11:33:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_3b5c5 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/17/2015 11:33:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_3b5c5 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/17/2015 11:33:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_3b5c5 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/17/2015 11:33:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_3b5c5 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/17/2015 08:07:14 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: %%1058 Error: (12/17/2015 08:05:33 AM) (Source: DCOM) (EventID: 10010) (User: RICK-PC) Description: {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E} Error: (12/17/2015 08:05:33 AM) (Source: DCOM) (EventID: 10010) (User: RICK-PC) Description: {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E} Error: (12/17/2015 08:05:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_95ceb16 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/17/2015 08:05:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_95ceb16 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2015-12-12 14:37:20.597 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-10 21:21:16.028 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-10 07:58:31.859 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-04 03:57:52.247 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-11-30 08:32:22.248 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2015-11-30 08:32:22.177 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2015-11-30 08:32:22.099 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2015-11-30 08:32:22.030 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2015-11-30 08:32:21.977 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2015-11-30 08:32:21.922 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU 530 @ 2.93GHz Percentage of memory in use: 47% Total physical RAM: 6007.09 MB Available physical RAM: 3128.94 MB Total Virtual: 12151.09 MB Available Virtual: 8799.49 MB ==================== Drives ================================ Drive c: (Gateway) (Fixed) (Total:919.41 GB) (Free:799.96 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 94462B7A) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=919.4 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================