Additional scan result of Farbar Recovery Scan Tool (x64) Version:25-12-2015 Ran by [removed] (2015-12-26 13:35:34) Running from C:\Users\[removed]\Downloads Windows 10 Home (X64) (2015-12-16 08:27:29) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3901721066-3880018567-3824620293-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3901721066-3880018567-3824620293-503 - Limited - Disabled) Guest (S-1-5-21-3901721066-3880018567-3824620293-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3901721066-3880018567-3824620293-1002 - Limited - Enabled) Owner (S-1-5-21-3901721066-3880018567-3824620293-1000 - Administrator - Enabled) => C:\Users\Owner ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 20.0.0.204 - Adobe Systems Incorporated) Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apple Application Support (32-bit) (HKLM-x32\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) ArcSoft Panorama Maker 5 (HKLM-x32\...\{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}) (Version: 5.0.1.25 - ArcSoft) ArcSoft Print Creations - Album Page (HKLM-x32\...\{E6B4117F-AC59-4B13-9274-EB136E8897EE}) (Version: - ArcSoft) ArcSoft Print Creations - Funhouse (HKLM-x32\...\{9591C049-5CAE-4E89-A8D9-191F1899628B}) (Version: - ArcSoft) ArcSoft Print Creations - Greeting Card (HKLM-x32\...\{F04F9557-81A9-4293-BC49-2C216FA325A7}) (Version: - ArcSoft) ArcSoft Print Creations - Photo Book (HKLM-x32\...\{56589DFE-0C29-4DFE-8E42-887B771ECD23}) (Version: - ArcSoft) ArcSoft Print Creations - Photo Calendar (HKLM-x32\...\{CA9ED5E4-1548-485B-A293-417840060158}) (Version: - ArcSoft) ArcSoft Print Creations - Scrapbook (HKLM-x32\...\{B0D83FCD-9D42-43ED-8315-250326AADA02}) (Version: - ArcSoft) ArcSoft Print Creations - Slimline Card (HKLM-x32\...\{007B37D9-0C45-4202-834B-DD5FAAE99D63}) (Version: - ArcSoft) ArcSoft Print Creations (HKLM-x32\...\{CAE8A0F1-B498-4C23-95FA-55047E730C8F}) (Version: 2.8.255.384 - ArcSoft) ATI Catalyst Install Manager (HKLM\...\{1F9241E8-87C1-FB9C-5D76-3FF7D0318A87}) (Version: 3.0.732.0 - ATI Technologies, Inc.) Avast Internet Security (HKLM-x32\...\Avast) (Version: 11.1.2245 - AVAST Software) Best Buy Software Installer (HKLM-x32\...\Best Buy Software Installer) (Version: 2.1.0.30 - Best Buy) Best Buy Software Installer (Version: 2.1.0.30 - Best Buy) Hidden Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation) Bing Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.470.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CameraHelperMsi (x32 Version: 13.10.1217.0 - Logitech) Hidden ccc-core-static (x32 Version: 2009.0702.1239.20840 - ATI) Hidden CCScore (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Coupon Printer for Windows (HKLM-x32\...\Coupon Printer for Windows5.0.0.8) (Version: 5.0.0.8 - Coupons.com Incorporated) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKU\S-1-5-21-3901721066-3880018567-3824620293-1000\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.) Eddy Current Level 1 (HKLM-x32\...\Eddy Current Level 1) (Version: - ) Elevated Installer (x32 Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden EMET (HKLM-x32\...\{90CD53EC-488B-4B1A-8C6B-3C36E82A84CA}) (Version: 2.1.0 - Microsoft) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden ESSBrwr (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ESSCDBK (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ESScore (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ESSgui (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ESSini (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ESSPCD (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ESSPDock (x32 Version: 6.03.0001.0004 - EASTMAN KODAK Company) Hidden ESSTOOLS (x32 Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden essvatgt (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{b292f4e5-60ca-4bb8-8810-e5f908c3c1ff}) (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden Gateway InfoCentre (HKLM-x32\...\Gateway InfoCentre) (Version: 3.02.3000 - Gateway Incorporated) Gateway Photo Frame 4.2.3.10 (HKLM-x32\...\Gateway Photo Frame) (Version: 4.2.3.10 - I/O Interconnect) Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Gateway Incorporated) Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.02.3006 - Gateway Incorporated) Gateway ScreenSaver (HKLM-x32\...\Gateway Screensaver) (Version: 1.1.0812 - Gateway Incorporated) Gateway Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3017 - Gateway Incorporated) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Greetings Workshop (HKLM-x32\...\Greetings Workshop) (Version: - ) HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Photosmart 6520 series Basic Device Software (HKLM\...\{9BB919AA-7F13-4003-BC37-AD2F8294DEBC}) (Version: 28.0.989.0 - Hewlett-Packard Co.) HP Photosmart 6520 series Help (HKLM-x32\...\{D3293275-1002-41F5-BC37-099B4251FF5B}) (Version: 28.0.0 - Hewlett Packard) HP Photosmart 6520 series Product Improvement Study (HKLM\...\{CE66F95C-D7EE-458E-8E08-DE5272B9CC71}) (Version: 28.0.989.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden iCloud (HKLM\...\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3002 - Gateway Incorporated) Internet TV for Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version: - Eastman Kodak Company) Logitech Vid HD (HKLM-x32\...\Logitech Vid) (Version: 7.2 (7230) - Logitech Inc..) Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.) Logitech Webcam Software Driver Package (HKLM\...\lvdrivers_12.0) (Version: 12.0.1278 - Logitech Inc.) LWS VideoEffects (Version: 13.00.1774.0 - Logitech) Hidden Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 10.70.3.3 - Marvell) Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Standard Edition 2003 (HKLM-x32\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 43.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.2 (x86 en-US)) (Version: 43.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla) Mozilla Thunderbird 38.4.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 38.4.0 (x86 en-US)) (Version: 38.4.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) netbrdg (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.3.1.25 - NETGEAR Inc.) Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.0.1 - Nikon) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - ) OfotoXMI (x32 Version: 8.02.1000.0001 - EASTMAN KODAK Company) Hidden Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.2 - Nikon) QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.) Rhapsody (HKLM-x32\...\Rhapsody) (Version: - ) SafeZone Stable 1.46.1990.139 (x32 Version: 1.46.1990.139 - Avast Software) Hidden Sansa Updater (HKU\S-1-5-21-3901721066-3880018567-3824620293-1000\...\Sansa Updater) (Version: 1.313 - SanDisk Corporation) SFR (x32 Version: 8.01.0000.0001 - Eastman Kodak Company) Hidden SHASTA (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden skin0001 (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden SKINXSDK (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden Skype Toolbars (HKLM-x32\...\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.) Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.) staticcr (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ViewNX 2 (HKLM-x32\...\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.2 - Nikon) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) VPRINTOL (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden WebIQ Technology Engine (HKLM-x32\...\{0F2F77E4-4053-4108-B153-81F0B42EDCF4}) (Version: 1.5.7100 - Usability Sciences Corporation) Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.00.3008 - Gateway Incorporated) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Scientific-Atlanta (USBCM) Net (06/10/2004 1.12.0.0000) (HKLM\...\9C6975C1801E1FD9353B8A42B5C15E8EA5E0B66E) (Version: 06/10/2004 1.12.0.0000 - Scientific-Atlanta) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Media Center Add-in for Flash (HKLM-x32\...\{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}) (Version: 4.1.2.0 - Microsoft Corporation) Windows Media Center Add-in for Silverlight (HKLM-x32\...\{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}) (Version: 4.7.3.0 - Microsoft Corporation) WIRELESS (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04FC2721-D653-4C19-A1EB-4F0B7623C94F} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {08BCFC29-7780-4B77-8AE6-B6095F259B45} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {0C661EB8-8268-4615-A419-502D524E9F11} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {0E4031AA-0E9B-453A-A177-31B4151E6EDE} - System32\Tasks\SafeZone scheduled Autoupdate 1450410503 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2015-12-01] (Avast Software) Task: {10140B52-209F-4A34-AE90-DEEB2886D013} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {1727757D-45DD-4E9A-A62B-75F35EF33C97} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {17809E23-FAF2-4DD8-ACFA-D7B357E1CD36} - System32\Tasks\{26CA5315-4A92-4C78-995E-5303EE36A136} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-12-04] (Mozilla Corporation) Task: {1A8F92DA-278B-4FF0-9492-1E27027BD645} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {27FE5FF3-52CF-43E7-9695-2823C231F8E5} - System32\Tasks\HP AR Program Upload - 53de797fdab24aec82cae13ba7d174e783ec6320dd9f4ebdbdb747d8a04a3936 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {2FDBDF17-7B91-41F3-9DE1-0627AD80E320} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {34E2C759-F022-4A23-A871-ADF71753AA1B} - System32\Tasks\HP AR Program Upload - 75cc592e3e694dfc8ac84bcff35b5ed16dd87abf9472493d9381d5d00e2afaf2 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {3A9B3EFC-C1C2-4C39-90A0-00DB74F9E527} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {3D728765-1B06-48FD-BBB0-A3EEB5FBF514} - System32\Tasks\{770BF445-099A-4FF4-A2FA-7B4D9321B43B} => pcalua.exe -a C:\Users\Owner\Downloads\Adaware_Installer.exe -d C:\Users\Owner\Downloads Task: {3E0BEE3D-AB44-4EFB-8217-F02A5B37F0C2} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {43FE7A9C-E340-4758-826B-68CFFD0A3DD7} - System32\Tasks\{4BB412E8-F56B-4EB3-A9D1-8D4412B33D87} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-12-17] (Skype Technologies S.A.) Task: {4D2A59B8-3B0F-487A-BF35-6CACD4C902DB} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {4F79E27F-5C46-4699-943E-CC333ACBBA1D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {506E8F7D-1BFA-42C1-B6AC-F0D884605B9C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {538174DB-5D2A-45F8-A9C2-12C4151E1AFF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {618B9E4D-2E6F-43C8-A7F3-45724020B7CC} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2015-10-29] () Task: {6BB340D6-5BF6-441E-9C7D-8AC50718E6DD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {74EB781C-6412-40E2-A208-91CC72E7BDE4} - System32\Tasks\{59F2B270-2CF1-44B2-86A3-66FEE7B6D90A} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CVIPMBGT\Adaware_Installer_free.exe" -d C:\Users\Owner\Desktop Task: {7A026218-049D-4DD4-8936-3641B81A2FAC} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {7EC3FBF2-14B8-4DFB-A2E9-CAE1D67EFFD0} - System32\Tasks\EasyShare Registration Task => Rundll32.exe C:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_8.2.30.1.sxt _RegistrationOffer@16 Task: {84A935DE-652F-465A-8FBD-CC668AC85414} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-14] (Adobe Systems Incorporated) Task: {851A1365-DEA0-47DE-9C83-D5C4947545AD} - System32\Tasks\{487217B0-F80F-428C-852A-1295EBAB4602} => pcalua.exe -a C:\Users\Owner\Downloads\4d9c38ed-5cb0-439b-acec-6573e3bef688_Adaware_Installer.exe -d C:\Users\Owner\Downloads Task: {87C2F15B-FE8D-4167-AF05-FA639EE1CE5D} - System32\Tasks\HP AR Program Upload - 1b48bc1923a94fda88b9582afb4a73a84d65bc9513244d12b2a5e697cf6cab36 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {8E8AF9B4-E3C9-442D-9843-EC33283B5A18} - System32\Tasks\{D5F35C68-E6FF-4CA6-8B08-E6257206ED10} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6TX421DC\install_easyshare[1].exe" -d C:\Users\Owner\Desktop Task: {912CCEF8-4FEA-4042-A7C8-3C0496E6474E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {9265F29D-7967-4F51-9B28-A02AAE8942E3} - System32\Tasks\HP AR Program Upload - 2aaca07465ed437c902607766218258a0ec1d59c254a418e84a224bf19e3f60d => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {9443C7EF-5164-46AA-A884-05ADDE23B522} - System32\Tasks\HP AR Program Upload - c3676b855b1e42b7b57f48aa8548c7c1147ef29d997144a7b3e7d75994c0c1e5 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {94B64B07-3437-42D0-B538-2C5CFA8D7D07} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {96962895-334E-4D14-8A01-D053CBE49451} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {9A0639A8-8087-4E20-B99C-394A11475884} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {9E4344F6-AB9F-4D42-A8F6-2B1AA876E8DC} - System32\Tasks\{D807633C-F175-4D5E-8BAF-4A218E7C774F} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PYRGJYBT\Adaware_Installer.exe" -d C:\Users\Owner\Desktop Task: {A1068E25-D7E3-442B-B9AF-0A0D5874F73F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {A3475048-5695-4943-99B7-3C2F8CA6CCC2} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {A6245D91-5CED-47BE-AA72-9A7059A218AA} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe Task: {A88AC861-7016-4653-AA8E-725702BEDF59} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {A8F59CCC-D90C-434D-B1FF-FC5612E09F8E} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {AB9CA01C-A4CE-4BEC-8D58-49FEBCC9DA75} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {B0416744-921F-43FE-B452-A49A205B683C} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {BB9C0D72-C04B-45A8-97A6-252DFDEB6DB6} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {C1047E5B-C100-4E31-92F1-F7DAB46FF231} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {C35C369D-93D5-4E7C-9F7F-FE0E2D677110} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {C4E23441-63F7-4FA2-8ECC-C3506742EE27} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {C7CF1502-CB0B-47A2-973B-08CDF7500E0E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-12-17] (AVAST Software) Task: {C8B7DD2D-5278-41CB-820E-56E1E9861E44} - System32\Tasks\{3585FC9C-71FC-48D1-968A-C17EE25CC19E} => pcalua.exe -a D:\Ect1\SETUP.EXE -d D:\Ect1 Task: {CA6381D6-E027-4396-88BE-3C5AEDB75F75} - System32\Tasks\{2D6133B4-5B67-41D5-B1E3-3FDB135CDC8A} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3B0GYP62\Adaware_Installer (2).exe" -d C:\Users\Owner\Desktop Task: {CF0F5E10-4F30-4C70-BC8D-46F4EC194C33} - System32\Tasks\HP AR Program Upload - dcf4dc4bbcd1424c807082dd14751fc092cd73a10b1f4877a6220f2c284f943d => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {D14152CD-5423-4680-89A9-1B5EFD93D390} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {D1C1B53B-8B31-428C-8F31-CB9AF8D61364} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {D709DB85-CFCB-409E-BA8D-D77640811B72} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {D731CEC4-42D3-4508-AF73-5F298A143923} - System32\Tasks\{E056D996-F92F-4D3A-A0D5-ACD05D0714EA} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PYRGJYBT\4d9c38ed-5cb0-439b-acec-6573e3bef688_Adaware_Installer.exe" -d C:\Users\Owner\Desktop Task: {DF6400FA-BF08-4821-8AE8-88B18F19594B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-08] (Microsoft Corporation) Task: {E6E587DB-D3B8-4760-B372-9382BCC38259} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {E89E8EA6-848D-4C14-9C3C-65516F2DE302} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {ED75FF16-F1B4-4C46-8B2D-644D8E75F225} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {F68D32E7-9DAC-4B77-AE9C-F973619CC31B} - System32\Tasks\{D4519B58-B14C-42BA-8278-A94905EC0332} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3B0GYP62\Adaware_Installer (1).exe" -d C:\Users\Owner\Desktop Task: {F6BDA360-C871-428A-A047-65C97AD906A6} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {F9856F32-0514-4364-8239-FB2D519885CD} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {F9A924D8-741D-4355-8DB9-59E94FADD499} - System32\Tasks\HP AR Program Upload - 466ca921d9e344e585631632fec594097d4f46bc26904bda93f9e6299b210eb7 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-05-08] (TODO: ) Task: {FCDEDC53-F522-4733-B8B2-4CA2653F83A0} - System32\Tasks\HPCustParticipation HP Photosmart 6520 series => C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPCustPartic.exe [2012-05-08] (Hewlett-Packard Co.) Task: {FE14F6BE-5B60-469A-9142-F1FF7ABBDB26} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\EasyShare Registration Task.job => C:\Windows\system32\rundll32.exeZC:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_8.2.30.1.sxt Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-16 05:44 - 2015-12-16 05:44 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-16 05:44 - 2015-12-16 05:44 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-12-18 05:51 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2015-12-18 05:51 - 2015-12-06 23:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-12-18 05:52 - 2015-12-06 22:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-18 05:51 - 2015-12-06 22:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-18 05:52 - 2015-12-06 22:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-12-18 05:52 - 2015-12-06 22:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-12-17 22:34 - 2015-12-17 22:34 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-17 22:41 - 2015-12-17 22:41 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-12-17 22:41 - 2015-12-17 22:41 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-12-24 16:28 - 2015-12-24 16:28 - 02806272 _____ () C:\Program Files\AVAST Software\Avast\defs\15122405\algo.dll 2015-12-17 22:41 - 2015-12-17 22:41 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-12-17 22:41 - 2015-12-17 22:41 - 00241896 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll 2015-12-17 22:37 - 2015-12-10 22:54 - 01583432 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libglesv2.dll 2015-12-17 22:37 - 2015-12-10 22:54 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libegl.dll 2015-05-15 15:27 - 2015-05-15 15:27 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 05:45 - 2015-10-13 05:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2015-10-13 05:46 - 2015-10-13 05:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2015-12-17 22:41 - 2015-12-17 22:41 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-12-17 22:34 - 2015-12-17 22:34 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2015-12-17 22:34 - 2015-12-17 22:35 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-12-04 20:05 - 2015-12-04 20:05 - 00153768 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2015-12-04 20:05 - 2015-12-04 20:05 - 00023208 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000\...\real.com -> hxxps://rhap-app-4-0.real.com IE trusted site: HKU\S-1-5-21-3901721066-3880018567-3824620293-1000\...\rhapsody.com -> hxxps://rhap-app-4-0.rhapsody.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2012-12-08 11:44 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3901721066-3880018567-3824620293-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AtHomeConnect.lnk => C:\Windows\pss\AtHomeConnect.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk => C:\Windows\pss\Kodak EasyShare software.lnk.CommonStartup MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe MSCONFIG\startupreg: BingDesktop => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey MSCONFIG\startupreg: Gateway Photo Frame => C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide MSCONFIG\startupreg: Nikon Message Center 2 => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime HKLM\...\StartupApproved\Run32: => "ShopAtHomeUpdater" HKLM\...\StartupApproved\Run32: => "ShopAtHomeWatcher" HKU\S-1-5-21-3901721066-3880018567-3824620293-1000\...\StartupApproved\Run: => "GarminExpressTrayApp" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{B5C5CF02-85B1-46D9-AC60-F3EA87A1024F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{43DB7FA0-D63D-4B0E-BF6D-7770786EF38C}] => (Allow) svchost.exe FirewallRules: [{5972B3B1-0BA1-42A6-B7C1-36D84A400910}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{1EE8FDB2-440B-4CA3-B648-D6F5F57913BE}] => (Allow) C:\Windows\System32\migwiz\migwiz.exe FirewallRules: [{CB8D3D9A-B0B6-4F46-AC8A-96AA37803404}] => (Allow) C:\Windows\System32\migwiz\migwiz.exe FirewallRules: [{472E8017-73FC-4334-9282-6CAE0426D561}] => (Allow) LPort=7000 FirewallRules: [{5C820D2B-2E33-4426-8488-67DB4C973CCA}] => (Allow) LPort=7000 FirewallRules: [TCP Query User{7ECF7A0A-CBC7-4045-8269-8C9925DD390B}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{F1EB2F18-6C76-40EC-9908-E4447EA471F4}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [{EEA71C50-67AD-49DA-AFF1-BF5E667897E4}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe FirewallRules: [{A73AE3CE-65C5-4DE5-BCA6-428CE51222F7}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe FirewallRules: [{6F5F0323-D672-47FA-96C5-97616174985A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{3FE4287D-9625-41D6-80ED-A8804C84A8E3}] => (Allow) LPort=2869 FirewallRules: [{5077047A-357A-4BE6-A7AA-90D6893C383C}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{2818A8A4-00AA-4D68-9CCC-308CC9A28FB2}C:\users\owner\appdata\local\google\google earth\client\googleearth.exe] => (Block) C:\users\owner\appdata\local\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{959FE0C2-F500-42C8-AC5B-40B399194DAA}C:\users\owner\appdata\local\google\google earth\client\googleearth.exe] => (Block) C:\users\owner\appdata\local\google\google earth\client\googleearth.exe FirewallRules: [{708CA111-ACBA-42C7-AD1E-1BEAEEFB3772}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5B0B4982-F489-4DDA-86EC-67BD9B7E8F73}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3867CE77-A04A-4640-BEA1-4B9AFACEEAD4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{FC706E36-5041-4065-BC10-DA32893852AF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{CE097CE9-4114-4302-A18D-A9EAFE70FAD5}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\DeviceSetup.exe FirewallRules: [{5A2A0D81-2906-4A76-960C-268C48B0B513}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicator.exe FirewallRules: [{39992849-7006-44AB-B4A9-A1C905084321}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [TCP Query User{2906B7CB-4EC3-405B-A336-EC86EBAE04BC}C:\users\owner\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\owner\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe FirewallRules: [UDP Query User{2F601691-D332-4B2D-9513-49CB6F57A80C}C:\users\owner\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\owner\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe FirewallRules: [{22895656-0F32-4518-9053-CDB40309BC71}] => (Allow) C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{B7563457-9D81-4609-844E-A757E56E6614}] => (Allow) C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{328FA7CE-563A-44A7-8EAF-764E3E13F42A}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe FirewallRules: [UDP Query User{FA149925-DB00-4AB3-84D5-F1C9A7C9C0DA}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe FirewallRules: [{10073B37-9E90-4A79-893E-F7C8AE54767E}] => (Block) C:\program files (x86)\netgear genie\bin\netgeargenie.exe FirewallRules: [{078AF75F-C2BB-44F7-894B-233BEEEDE903}] => (Block) C:\program files (x86)\netgear genie\bin\netgeargenie.exe FirewallRules: [{B1156D57-3F19-498B-AE62-03A878A7C9EA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{49820537-6DE7-478C-84C0-95C8F9571DCF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{9173F259-33C3-457E-B607-F10A258A1885}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{449FF458-CD0D-4F9E-AC51-29B03CFD330B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{AC583BD5-855E-40F8-BA34-33C2BBC60DEA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{EFA17D7D-D583-426A-86EE-5F99DBBCDCF9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B65CC774-3E9E-4DCF-901E-3CB071E02290}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{24F87DC1-987B-48FF-B273-0879AB46A1D9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe ==================== Restore Points ========================= 18-12-2015 18:16:41 Windows Update 20-12-2015 19:16:19 Windows Backup 23-12-2015 07:13:35 Windows Modules Installer ==================== Faulty Device Manager Devices ============= Name: Standard PS/2 Keyboard Description: Standard PS/2 Keyboard Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard keyboards) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2 Mouse Description: Microsoft PS/2 Mouse Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (12/24/2015 10:37:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x18d0 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 10:37:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x1a90 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 09:37:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x818 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 09:37:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x1c38 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 08:37:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x24ac Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 08:37:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x2380 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 08:34:21 PM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY) Description: Failed to begin a Windows Installer transaction ASU_MSI_TRAN. Error 1603 occurred while beginning the transaction. Error: (12/24/2015 04:37:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x1590 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 04:37:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x7f8 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 Error: (12/24/2015 03:37:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPNetworkCommunicator.exe, version: 28.0.989.0, time stamp: 0x4fa98fe9 Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b Exception code: 0xc0000005 Fault offset: 0x00000000000168d2 Faulting process id: 0x8b0 Faulting application start time: 0xHPNetworkCommunicator.exe0 Faulting application path: HPNetworkCommunicator.exe1 Faulting module path: HPNetworkCommunicator.exe2 Report Id: HPNetworkCommunicator.exe3 Faulting package full name: HPNetworkCommunicator.exe4 Faulting package-relative application ID: HPNetworkCommunicator.exe5 System errors: ============= Error: (12/25/2015 10:16:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_33947 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/25/2015 10:16:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_33947 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/25/2015 10:16:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_33947 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/25/2015 10:16:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_33947 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/24/2015 09:01:38 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the BingDesktopUpdate service to connect. Error: (12/24/2015 09:01:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Apple Mobile Device Service service failed to start due to the following error: %%1053 Error: (12/24/2015 09:01:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device Service service to connect. Error: (12/24/2015 08:59:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_52ba4e service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/24/2015 08:59:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_52ba4e service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/24/2015 08:59:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_52ba4e service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2015-12-23 08:27:46.132 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-19 03:33:21.882 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-17 19:32:57.392 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-17 19:32:57.251 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-17 19:32:54.704 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-17 19:32:54.614 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-16 20:47:01.427 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-16 20:47:01.354 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-16 20:47:01.275 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-12-16 20:47:01.200 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: AMD Phenom(tm) II X4 810 Processor Percentage of memory in use: 28% Total physical RAM: 7935.3 MB Available physical RAM: 5701.43 MB Total Virtual: 15871.3 MB Available Virtual: 13419.63 MB ==================== Drives ================================ Drive c: (Gateway) (Fixed) (Total:919.41 GB) (Free:790.93 GB) NTFS Drive j: (Elements) (Fixed) (Total:931.51 GB) (Free:23.15 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 1A6A07CA) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=919.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 00021631) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================