Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-06-2016 01 Ran by [removed] (2016-06-23 13:39:44) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1511 (X64) (2016-02-16 02:28:40) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-578200233-972976924-3727881056-500 - Administrator - Disabled) => C:\Users\Administrator barry (S-1-5-21-578200233-972976924-3727881056-1001 - Administrator - Enabled) => C:\Users\barry DefaultAccount (S-1-5-21-578200233-972976924-3727881056-503 - Limited - Disabled) Guest (S-1-5-21-578200233-972976924-3727881056-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-578200233-972976924-3727881056-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 Premier (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton 360 Premier (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton 360 Premier (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 4500_G510nz_Help (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden 64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20045 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.8.800.168 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Apple Application Support (32-bit) (HKLM-x32\...\{3540ADD5-822B-47FB-B1C2-CD7B2C8E9FEC}) (Version: 4.0.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{C9C0FE2C-602E-49D7-8C42-5B9E8FF04798}) (Version: 4.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) ARO 2011 (HKLM-x32\...\ARO 2011_is1) (Version: 7.0 - Support.com) AT&T Troubleshoot & Resolve Tool (HKLM-x32\...\ATT-SST) (Version: - ) ATT Management Agent (HKLM-x32\...\ATT-ATT Management Agent) (Version: 8.2.1.6 - ATT) Backup Manager Advance (x32 Version: 2.0.2.19 - NewTech Infosystems) Hidden BitTorrent (HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\BitTorrent) (Version: 7.9.4.40912 - BitTorrent Inc.) BlackBerry Desktop Software 5.0.1 (HKLM-x32\...\BlackBerry_{F5BDF2BB-C990-4351-A05B-B2243D4037D4}) (Version: 5.0.1.18 - Research In Motion Ltd.) BlackBerry Desktop Software 5.0.1 (x32 Version: 5.0.1.18 - Research In Motion Ltd.) Hidden BlackBerry® Media Sync (HKLM-x32\...\{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}) (Version: 2.0.28 - Research In Motion) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden CameraHelperMsi (x32 Version: 13.30.1395.0 - Logitech) Hidden Canon DIGITAL CAMERA Solution Disk Software Guide (HKLM-x32\...\Software Guide) (Version: 1.1.0.2 - Canon Inc.) CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.7.2.11 - Canon Inc.) Canon Internet Library for ZoomBrowser EX (HKLM-x32\...\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.3.9 - Canon Inc.) Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 3.4.0.8 - Canon Inc.) Canon Personal Printing Guide (HKLM-x32\...\Personal Printing Guide) (Version: 1.1.0.2 - Canon Inc.) Canon PowerShot SD1300 IS_IXUS 105 Camera User Guide (HKLM-x32\...\CameraUserGuide-PSSD1300IS_IXUS105) (Version: 1.0.0.2 - Canon Inc.) Canon Utilities CameraWindow (HKLM-x32\...\CameraWindowLauncher) (Version: 7.4.0.7 - Canon Inc.) Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC8) (Version: 8.1.0.11 - Canon Inc.) Canon Utilities Movie Uploader for YouTube (HKLM-x32\...\MovieUploaderForYouTube) (Version: 1.0.0.11 - Canon Inc.) Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 7.3.0.5 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.22.46 - Canon Inc.) Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.5.0.14 - Canon Inc.) Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\...\ZoomBrowser EX Memory Card Utility) (Version: 1.3.0.4 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform) Cisco Connect (HKLM-x32\...\Cisco Connect) (Version: 1.4.11222.0 - Cisco Consumer Products LLC) Cisco WebEx Meetings (HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC) Citrix Online Launcher (HKLM-x32\...\{75B8A55E-0762-4676-AAC0-6FDF025B034B}) (Version: 1.0.220 - Citrix) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Content Transfer (HKLM-x32\...\{CFADE4AF-C0CF-4A04-A776-741318F1658F}) (Version: 1.3.0.23190 - Sony Corporation) ContentManager (HKLM-x32\...\{B64BC516-2406-43AE-A21A-1E387A2343B1}) (Version: 0.5 - Magellan) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Desktop Doctor (HKLM-x32\...\{D87149B3-7A1D-4548-9CBF-032B791E5908}) (Version: 2.5.5 - Comcast) Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Dropbox (HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\Dropbox) (Version: 4.4.29 - Dropbox, Inc.) eBay Worldwide (HKLM-x32\...\{AAF89271-2594-468D-B578-96B2E30C41C4}) (Version: 2.1.0703 - OEM) Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION) Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.80.0000 - Seiko Epson Corporation) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.62.00 - SEIKO EPSON CORPORATION) Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 2.20.0000 - SEIKO EPSON Corp.) EPSON Scan PDF EXtensions (HKLM-x32\...\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.03.0000 - SEIKO EPSON Corp.) EPSON WF-2660 Series Printer Uninstall (HKLM\...\EPSON WF-2660 Series) (Version: - SEIKO EPSON Corporation) Epson WF-2660 User’s Guide version 1.0 (HKLM-x32\...\UsersGuideEpson WF-2660 User’s Guide_is1) (Version: 1.0 - ) EpsonNet Print (HKLM\...\{F983229B-587E-4322-BCB9-D7A49734E5CD}) (Version: 3.0.0.0 - SEIKO EPSON CORPORATION) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden Gateway Games (HKLM-x32\...\WildTangent gateway Master Uninstall) (Version: 1.0.0.71 - WildTangent) Gateway InfoCentre (HKLM-x32\...\Gateway InfoCentre) (Version: 3.02.3000 - Gateway Incorporated) Gateway MyBackup (HKLM-x32\...\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems) Gateway Photo Frame 4.2.3.10 (HKLM-x32\...\Gateway Photo Frame) (Version: 4.2.3.10 - I/O Interconnect) Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3002 - Acer Incorporated) Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.02.3004 - Gateway Incorporated) Gateway ScreenSaver (HKLM-x32\...\Gateway Screensaver) (Version: 1.1.0812 - Gateway Incorporated) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.) Google Drive (HKLM-x32\...\{709316AD-161C-4D5C-9AE7-0B3A822DA271}) (Version: 1.30.2170.0459 - Google, Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM-x32\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard) HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3001 - Gateway Incorporated) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden InstallIQ Updater (HKLM-x32\...\{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}) (Version: 1.4.3.0 - W3i, LLC) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) iTunes (HKLM\...\{88509E20-3936-4D88-A1C0-B274C7BB5151}) (Version: 12.3.0.44 - Apple Inc.) Java(TM) 6 Update 16 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216016FF}) (Version: 6.0.160 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Logitech Vid HD (HKLM-x32\...\Logitech Vid) (Version: 7.2 (7240) - Logitech Inc..) Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.) LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 40.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyTurboPC (HKLM-x32\...\{A2F37CA8-53F8-4594-B701-32AE64BAED1A}) (Version: 3.2.20.0 - MyTurboPC.com) Nero 9 Essentials (HKLM-x32\...\{40a87585-3dea-47d0-8aac-c7c19689b431}) (Version: - Nero AG) Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.3 - Nikon) Norton 360 Premier (HKLM-x32\...\N360) (Version: 22.7.0.76 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.2.0.36 - Symantec) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - ) NWZ-E350 WALKMAN Guide (HKLM-x32\...\{9D7E5329-5751-435B-B585-0EFF51783A20}) (Version: 2.1.0.17210 - Sony Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.4.16 - Nikon) QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.) RealDownloader (x32 Version: 1.3.0 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.0 - RealNetworks) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.8.8855 - Skype Technologies S.A.) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden Unity Web Player (HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden V CAST Music with Rhapsody (HKLM-x32\...\V CAST Music with Rhapsody) (Version: - ) VD64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.8.3 - Nikon) WD SmartWare (HKLM\...\{07179D37-D5FE-4373-90D9-A25B992EFB3E}) (Version: 1.4.5.5 - Western Digital) WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.00.3005 - Gateway Incorporated) WildTangent Games App (Gateway Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-gateway) (Version: 4.0.5.31 - WildTangent) Windows 7 Upgrade Advisor (HKLM-x32\...\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation) Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (03/06/2009 1.0.0008.0) (HKLM\...\422991454CB076E9B856C21BBF99AF2B82317EDA) (Version: 03/06/2009 1.0.0008.0 - Western Digital Technologies) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}) (Version: 14.0.8064.206 - Microsoft Corporation) WinRAR 5.30 beta 5 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.5 - win.rar GmbH) Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\barry\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\1468\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> no filepath CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-578200233-972976924-3727881056-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\barry\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0268E5DD-23D0-4C48-B828-8C74006A6D5E} - System32\Tasks\EPSON WF-2660 Series Update {344C00C5-FF89-42A7-B4CE-885E058DDEAE} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSMAE.EXE [2013-11-22] (SEIKO EPSON CORPORATION) Task: {02F63D85-AE24-493C-8A69-740F71AD71F8} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {07FDD378-074B-47BA-8806-BA376749D6A7} - System32\Tasks\MyTurboPC_sch_2E998A8F-3963-11E6-9742-0025115B4A92 => C:\Program Files (x86)\MyTurboPC.com\MyTurboPC\mtpc.exe [2016-03-16] (MyTurboPC.com) <==== ATTENTION Task: {09A36471-E6CC-4FF8-AC00-3805A4750FC1} - System32\Tasks\PC Optimizer Pro64 startups => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION Task: {0BAED752-B7DD-49A9-9DA3-81EBACCDAD96} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {0BD6D014-7261-4E0B-B0C3-FC81783EFA82} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.7.0.76\SymErr.exe [2016-05-23] (Symantec Corporation) Task: {0CD6CF3B-F451-4C2E-A316-3D5E3BB04230} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {14D4CB46-64F7-4707-9326-329DF86E28B3} - System32\Tasks\ParetoLogic Registration => Rundll32.exe "C:\Program Files (x86)\Common Files\ParetoLogic\UUS2\UUS.dll" RunUns Task: {15C87CA0-FE67-445B-BD64-DB716C74BE7F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {1846EDD0-D0BF-4074-9A66-46CC8C049BA6} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {1C71BD98-B384-4224-ADDA-CEEFAA06F1C7} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {2A876656-5BFF-4A95-8C43-BDA23C18A454} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-578200233-972976924-3727881056-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {31CDCB9F-4611-4FDB-A65D-B23FA5DB3CE6} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {333C7AFB-A5A3-4354-B03E-C7039BF1A2D5} - System32\Tasks\MyTurboPC.com Update3_triggeronce => c:\program files (x86)\common files\myturbopc.com\uus3\Update3.exe [2016-03-16] (MyTurboPC.com) Task: {3944F181-BEE0-40B6-8CD8-7FCE25E49458} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-28] (Adobe Systems Incorporated) Task: {39A49318-358F-4E94-9727-F6E532365602} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-578200233-972976924-3727881056-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {3FD3E7A5-FE70-443C-92CA-1943A9AA7476} - System32\Tasks\{55CD1315-AC73-4F9D-BFCC-FB36D0B67414} => pcalua.exe -a "C:\Program Files (x86)\Plus-HD-7.7\Uninstall.exe" -c /fromcontrolpanel=1 Task: {44A6E8D9-0602-4642-AF54-C16C6131C8A5} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {456AF673-0710-4849-A5A5-F21CC723DF36} - \AmiUpdXp -> No File <==== ATTENTION Task: {466814BD-A3A9-48D7-952A-78B6863152F1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {4B4C8F42-F2FB-4092-8BDF-7CC6FA9E03D6} - \BrowserSafeguard Update Task -> No File <==== ATTENTION Task: {4DEEFA21-045D-41F2-A530-1B3F32AB7DAE} - System32\Tasks\{FC71A5C5-74CE-4732-B92B-98988D391DFB} => pcalua.exe -a C:\Users\barry\Downloads\OJ4500vG510n-z_Full_13_en.exe -d C:\Users\barry\Desktop Task: {4E1D3F65-0EF7-454E-9E8D-C66C318618C1} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Gateway\Gateway Recovery Management\NotificationCenter\Notification.exe [2009-07-09] (Acer) Task: {4E71931C-03DC-4320-9CA4-DD2B638F1BE9} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\22.7.0.76\WSCStub.exe [2016-06-16] (Symantec Corporation) Task: {4F4B739C-0579-469A-8E67-98B47497FE3C} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {5A636CD6-2BF8-45F0-BF15-C5C7474AC948} - System32\Tasks\Test TimeTrigger => C:\Users\barry\AppData\Local\Temp\Runner.exe <==== ATTENTION Task: {5AECD2C2-F0ED-46CB-BC4F-144CCF8B946E} - System32\Tasks\Norton 360\Norton Autofix => C:\Program Files (x86)\Norton 360\Engine\22.7.0.76\SymErr.exe [2016-05-23] (Symantec Corporation) Task: {613E7395-5B3F-4E09-B0B1-CF610D7701C9} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-578200233-972976924-3727881056-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {61436074-7FC3-4904-84AD-1AAD72CAA234} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {642701A2-3F0A-4CC5-8BA9-6ED066A8FEB1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {66D953B0-BAD6-4ED8-81DC-081063A9C51F} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.7.0.76\SymErr.exe [2016-05-23] (Symantec Corporation) Task: {6D0A0C2B-8A81-48F3-B478-F48D20C90CEB} - \ParetoLogic Registration3 -> No File <==== ATTENTION Task: {7722F0F0-C2ED-4E3B-A08A-F5104D4BC69B} - System32\Tasks\G2MUploadTask-S-1-5-21-578200233-972976924-3727881056-1001 => C:\Program Files (x86)\Citrix\GoToMeeting\5102\g2mupload.exe Task: {77C915BD-74E2-43E6-A7D7-92B495DB9D66} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {780F7D89-ABF8-48BA-ACC5-3C8273300199} - System32\Tasks\MyTurboPC Startup => C:\Program Files (x86)\MyTurboPC.com\MyTurboPC\mtpc.exe [2016-03-16] (MyTurboPC.com) Task: {7B8AF946-DD9E-4054-8266-99009C6D5087} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {80B2027C-98D1-4847-B161-D03270001F9B} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-578200233-972976924-3727881056-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {847702AF-D1FB-47AE-8716-E73BD29BC608} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {868A5297-8F36-4F68-A069-09D4D7C3D377} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-578200233-972976924-3727881056-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {8C65B035-F81B-40E4-853B-D1F95835B573} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {A0682436-7056-4B16-82D0-9B3EDE233F5E} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {A26A45E7-4062-4AF5-93A7-44506EF86106} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe Task: {A93AE0EE-6648-4364-9EF8-89A50222E3D3} - System32\Tasks\MyTurboPC.com Registration3 => Rundll32.exe "C:\Program Files (x86)\Common Files\MyTurboPC.com\UUS3\UUS3.dll" RunUns Task: {AABE5CCD-C751-4399-A400-DB3DEEE972E6} - System32\Tasks\{2236CB57-C49F-45CC-A3A5-C169F25EA834} => pcalua.exe -a "C:\Users\barry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GL8AQ708\Cm_Setup_1.98[1].exe" -d C:\Users\barry\Desktop Task: {B9881A37-5C2D-4EF2-83CC-3B1350977310} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {BBC3E865-7990-481E-8C60-8E3948FC8BC3} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {BFE12A31-9814-4BCF-80DE-1EE6E44B5AD4} - \Final Media Player Update Checker -> No File <==== ATTENTION Task: {C30DE01B-37F0-4C9E-9383-BF4C65DD4F81} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton 360 Premier\Upgrade.exe [2016-06-16] (Symantec Corporation) Task: {CC29B4FE-7805-4491-A297-2AF1164BDC1D} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {D2702BB2-BA16-454C-A4DF-8D9671D814B0} - System32\Tasks\ParetoLogic Update Version2 => C:\Program Files (x86)\Common Files\ParetoLogic\UUS2\Pareto_Update.exe Task: {D8D76A1C-7AFA-4A28-B1F3-A7D49A993C0F} - System32\Tasks\{D64E54B4-864C-4878-96EC-BA5A76C6242D} => pcalua.exe -a "C:\Users\barry\Downloads\OJ4500vG510n-z_basic_13_en (1).exe" -d C:\Users\barry\Desktop Task: {D9C6FF23-D3C6-4BA7-97E7-8006DF2F074D} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-578200233-972976924-3727881056-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {DB316BD0-BA64-4E5F-A150-9517C77F24AB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {DE601A36-25E1-4083-A06D-D71284FAA0D2} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {DEF7DD05-27C7-4158-81B1-CB288DA44A5D} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-578200233-972976924-3727881056-1001Core => C:\Users\barry\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.) Task: {E190A418-415C-4CE1-BFEF-0FC51B8738B8} - System32\Tasks\MyTurboPC.com Update3 => c:\program files (x86)\common files\myturbopc.com\uus3\Update3.exe [2016-03-16] (MyTurboPC.com) Task: {E26C218D-E3DF-48EC-8C69-059BEB524BCC} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {E68AC160-E0FD-411B-AA8D-AC7D97BFEFDD} - System32\Tasks\G2MUpdateTask-S-1-5-21-578200233-972976924-3727881056-1001 => C:\Program Files (x86)\Citrix\GoToMeeting\5102\g2mupdate.exe Task: {E74DF842-B799-4B3F-9BB3-D46114847820} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd) Task: {EACEC849-6B7E-4763-AE4E-2727B07AE629} - System32\Tasks\{8BCF1780-CD74-41FA-A817-EC6A4BDAC22F} => pcalua.exe -a "C:\Program Files (x86)\Norton Bootable Recovery Tool Wizard\Engine\6.0.0.74\Gear\GEARDIFx.exe" -d C:\Users\barry\Desktop -c INSTALL "NBRTWizard" "{A4274214-B468-482e-B2AC-24FCD2365C4B}" Task: {ECA23188-B1CB-443D-95D2-9266502C90AF} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {EFD7E345-5324-4CBF-88A1-458DC4D90645} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-578200233-972976924-3727881056-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {F2E26E93-35EF-4C85-A81E-78874D63C26C} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-578200233-972976924-3727881056-1001UA => C:\Users\barry\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.) Task: {F55D038D-6218-491D-8DDD-0D0045348D0D} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {F64D1AE6-480D-4C87-A849-9A942C10EA21} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-578200233-972976924-3727881056-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {F71F78DD-6877-4DF3-BD1D-38205ABA9A49} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {FBFFD3B1-4ED9-45FD-B168-F3BD8572DB2C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) Task: {FE73FEA9-0EF4-4AFB-B015-63467C694E3F} - System32\Tasks\{329F0E19-C54C-4CF8-A906-695E9B3DCEA7} => pcalua.exe -a "C:\Users\barry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I6U1IQ1H\wlsetup-web.exe" -d C:\Users\barry\Desktop (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-578200233-972976924-3727881056-1001Core.job => C:\Users\barry\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-578200233-972976924-3727881056-1001UA.job => C:\Users\barry\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\EPSON WF-2660 Series Update {344C00C5-FF89-42A7-B4CE-885E058DDEAE}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSMAE.EXE:/EXE:{344C00C5-FF89-42A7-B4CE-885E058DDEAE} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON WF-2660 Series Update {D5CE0E46-36B1-408F-AE59-01BC328E0670}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSMAE.EXE:/EXE:{D5CE0E46-36B1-408F-AE59-01BC328E0670} /F:UpdateWORKGROUP\BARRY-PC$ Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-578200233-972976924-3727881056-1001.job => C:\Program Files (x86)\Citrix\GoToMeeting\5102\g2mupdate.exe Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-578200233-972976924-3727881056-1001.job => C:\Program Files (x86)\Citrix\GoToMeeting\5102\g2mupload.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\MyTurboPC Startup.job => C:\Program Files (x86)\MyTurboPC.com\MyTurboPC\mtpc.exe C:\Program Files (x86)\MyTurboPC.com\MyTurboPC\mtpc.exe Task: C:\WINDOWS\Tasks\MyTurboPC.com Registration3.job => rundll32.exe C:\Program Files (x86)\Common Files\MyTurboPC.com\UUS3\UUS3.dll RunUns C:\Program Files (x86)\Common Files\MyTurboPC.com Task: C:\WINDOWS\Tasks\MyTurboPC.com Update3.job => c:\program files (x86)\common files\myturbopc.com\uus3\Update3.exe C:\program files (x86)\common files\myturbopc.com\uus3barry-PC\barryMyTurboPC.com Task: C:\WINDOWS\Tasks\MyTurboPC.com Update3_triggeronce.job => c:\program files (x86)\common files\myturbopc.com\uus3\Update3.exe C:\program files (x86)\common files\myturbopc.com\uus3barry-PC\barryMyTurboPC.com Task: C:\WINDOWS\Tasks\MyTurboPC_sch_2E998A8F-3963-11E6-9742-0025115B4A92.job => C:\Program Files (x86)\MyTurboPC.com\MyTurboPC\mtpc.exe2 /schedule:2E998A8F-3963-11E6-9742-0025115B4A92 C:\Program Files (x86)\MyTurboPC.com <==== ATTENTION Task: C:\WINDOWS\Tasks\ParetoLogic Registration.job => rundll32.exe C:\Program Files (x86)\Common Files\ParetoLogic\UUS2\UUS.dll Task: C:\WINDOWS\Tasks\ParetoLogic Update Version2.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS2\Pareto_Update.exe Task: C:\WINDOWS\Tasks\PC Optimizer Pro64 startups.job => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\barry\Desktop\Default Profile - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Default" ShortcutWithArgument: C:\Users\barry\Desktop\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.gateway.com/redirect.aspx?rid=09000002 ShortcutWithArgument: C:\Users\barry\Desktop\Petals - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" ShortcutWithArgument: C:\Users\barry\Desktop\smtmp\4\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.gateway.com/redirect.aspx?rid=09000002 ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-09-15 14:25 - 2015-09-15 14:25 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-09-15 14:25 - 2015-09-15 14:25 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-04-13 07:55 - 2016-03-29 06:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 07:55 - 2016-03-29 06:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-23 17:01 - 2016-05-23 17:01 - 00959168 _____ () C:\Users\barry\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-04-19 06:58 - 2016-04-19 06:58 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-02-16 01:30 - 2015-12-07 00:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-11 12:14 - 2016-04-23 00:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-05-11 12:15 - 2016-04-23 00:25 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll 2014-04-14 15:41 - 2014-04-14 15:41 - 00039192 _____ () C:\Program Files\CCleaner\branding.dll 2016-06-03 05:27 - 2016-06-03 05:27 - 00017920 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-06-03 05:27 - 2016-06-03 05:27 - 13105152 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-06-03 05:27 - 2016-06-03 05:27 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-03-04 08:00 - 2016-03-04 08:00 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-06-15 15:21 - 2016-05-27 23:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-06-15 15:20 - 2016-05-27 23:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-06-15 15:21 - 2016-05-27 23:54 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-06-15 15:21 - 2016-05-27 23:56 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-04-19 06:58 - 2016-04-19 06:58 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 06:58 - 2016-04-19 06:58 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-05-23 17:01 - 2016-05-23 17:01 - 00679624 _____ () C:\Users\barry\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll 2016-06-13 06:39 - 2016-05-05 06:09 - 00034768 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2016-06-13 06:39 - 2016-05-05 06:10 - 00019408 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2016-06-13 06:39 - 2016-05-05 06:09 - 00116688 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2016-06-13 06:39 - 2016-05-05 06:09 - 00093640 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2016-06-13 06:39 - 2016-05-05 06:09 - 00018376 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\select.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00019760 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00105928 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32api.pyd 2016-06-13 06:39 - 2016-05-05 06:09 - 00392144 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2016-06-13 06:39 - 2016-05-31 14:34 - 00381752 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2016-06-13 06:39 - 2016-05-05 06:09 - 00692688 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00020816 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2016-06-13 06:39 - 2016-05-05 06:10 - 00123856 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 01682760 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00020808 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00021840 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00038696 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\fastpath.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00020936 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00024528 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32event.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00114640 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32security.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00124880 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32file.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00021832 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00024016 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00175560 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32gui.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00030160 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00043472 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32process.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00048592 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32service.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00023872 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd 2016-06-13 06:39 - 2016-05-05 06:09 - 00134088 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00026456 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00057808 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32evtlog.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00024016 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32profile.pyd 2016-06-13 06:39 - 2016-05-31 14:33 - 00246592 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00028616 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32ts.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00052024 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2016-06-13 06:39 - 2016-05-05 06:09 - 00134608 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_elementtree.pyd 2016-06-13 06:39 - 2016-05-05 06:10 - 00240584 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\jpegtran.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00020800 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00019776 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00020800 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00020280 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00023376 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00350152 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00022352 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00024392 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2016-06-13 06:39 - 2016-05-05 06:12 - 00036296 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\librsync.dll 2016-06-13 06:39 - 2016-05-31 14:34 - 00031568 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\enterprise_data.compiled._enterprise_data.pyd 2016-06-13 06:39 - 2016-03-11 20:46 - 00293392 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\EnterpriseDataAdapter.dll 2016-06-13 06:39 - 2016-05-31 14:34 - 00084280 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2016-06-13 06:39 - 2016-05-31 14:34 - 01826096 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2016-06-13 06:39 - 2016-05-05 06:10 - 00083912 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\sip.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 03928880 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 01971504 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00531248 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00132912 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00223544 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00207672 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2016-06-13 06:39 - 2016-05-05 06:11 - 00060880 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\win32print.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00025928 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\windisplaytoast.compiled._DisplayToast.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00024904 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00546096 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2016-06-13 06:39 - 2016-05-31 14:34 - 00357680 _____ () C:\Users\barry\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2016-06-18 21:02 - 2016-06-15 05:15 - 01745560 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libglesv2.dll 2016-06-18 21:02 - 2016-06-15 05:15 - 00091288 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libegl.dll 2009-02-26 13:46 - 2009-02-26 13:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 11:46 - 2011-06-22 11:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2015-11-11 04:41 - 2015-11-11 04:41 - 00756376 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 [118] AlternateDataStreams: C:\ProgramData\TEMP:D346F792 [147] AlternateDataStreams: C:\Users\barry\Desktop\KINDLE-WARRANTY-STAPLES-11-29-11.jpeg:3or4kl4x13tuuug3Byamue2s4b [87] AlternateDataStreams: C:\Users\barry\Desktop\KINDLE-WARRANTY-STAPLES-11-29-11.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\barry\Downloads\KINDLE-11-29-11 RECEIPT - STAPLES.jpg:3or4kl4x13tuuug3Byamue2s4b [87] AlternateDataStreams: C:\Users\barry\Downloads\KINDLE-11-29-11 RECEIPT - STAPLES.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\barry\Downloads\STAPLES -KINDLE- WARRANTY-11-29-11.jpg:3or4kl4x13tuuug3Byamue2s4b [87] AlternateDataStreams: C:\Users\barry\Downloads\STAPLES -KINDLE- WARRANTY-11-29-11.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\barry\Documents\Caden program picture 001 (2).jpg:Roxio EMC Stream [38] AlternateDataStreams: C:\Users\barry\Documents\Caden program picture 001.jpg:Roxio EMC Stream [38] AlternateDataStreams: C:\Users\barry\Documents\eric - tax- 2012 - 1.jpg:3or4kl4x13tuuug3Byamue2s4b [87] AlternateDataStreams: C:\Users\barry\Documents\eric - tax- 2012 - 1.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\barry\Documents\Hilton Garden Inn New York (2).doc:Roxio EMC Stream [38] AlternateDataStreams: C:\Users\barry\Documents\Hilton Garden Inn New York.doc:Roxio EMC Stream [38] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\$talisma_url$ -> hxxps://$talisma_url$ IE trusted site: HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\real.com -> hxxps://rhap-app-4-0.real.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2014-03-05 11:39 - 2016-04-22 12:03 - 00000054 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-578200233-972976924-3727881056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\barry\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: ATT MAHostService => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: GamesAppService => 3 MSCONFIG\Services: Greg_Service => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: IDriverT => 3 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: Maps4PC_0cService => 2 MSCONFIG\Services: Nero BackItUp Scheduler 4.0 => 3 MSCONFIG\Services: NTI IScheduleSvc => 2 MSCONFIG\Services: pcCMService => 2 MSCONFIG\Services: pcCMService64 => 2 MSCONFIG\Services: pcServiceHost => 2 MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2 MSCONFIG\Services: Roxio UPnP Renderer 9 => 3 MSCONFIG\Services: Roxio Upnp Server 9 => 2 MSCONFIG\Services: RoxLiveShare9 => 2 MSCONFIG\Services: RoxMediaDB9 => 3 MSCONFIG\Services: RoxWatch9 => 2 MSCONFIG\Services: sprtsvc_ddoctorv2 => 2 MSCONFIG\Services: UMVPFSrv => 2 MSCONFIG\Services: Updater Service => 2 MSCONFIG\Services: WDDMService => 2 MSCONFIG\Services: WDFME => 2 MSCONFIG\Services: WDSC => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk => C:\Windows\pss\Desktop Manager.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WDDMStatus.lnk => C:\Windows\pss\WDDMStatus.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^barry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk => C:\Windows\pss\Desktop Manager.lnk.Startup MSCONFIG\startupfolder: C:^Users^barry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.Startup MSCONFIG\startupreg: Ad-Aware Browsing Protection => "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ATT-SST_McciTrayApp => "C:\Program Files\ATT-SST\pcTrayApp.exe" MSCONFIG\startupreg: BackupManagerTray => "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k MSCONFIG\startupreg: BlackBerryAutoUpdate => C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background MSCONFIG\startupreg: ContentTransferWMDetector.exe => C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe MSCONFIG\startupreg: ddoctorv2 => "C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2 MSCONFIG\startupreg: Desktop Software => "C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files (x86)\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden MSCONFIG\startupreg: DisplaySwitch => "C:\Users\barry\AppData\Roaming\Microsoft\Windows\Templates\syssecurity.exe" MSCONFIG\startupreg: DW6 => "C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe" MSCONFIG\startupreg: Gateway Photo Frame => C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: InstallIQUpdater => "C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun MSCONFIG\startupreg: ISUSPM => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Logitech Vid => "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide MSCONFIG\startupreg: Magellan CmTray => C:\Program Files (x86)\Content Manager\CmTray.exe MSCONFIG\startupreg: Maps4PC_0c Browser Plugin Loader => C:\PROGRA~2\MAPS4P~2\bar\1.bin\0cbrmon.exe MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background MSCONFIG\startupreg: NortonOnlineBackupReminder => "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: PlaxoSysTray => MSCONFIG\startupreg: PlaxoUpdate => MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Retrogamer_2z Browser Plugin Loader => MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized MSCONFIG\startupreg: SugarSync => "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot MSCONFIG\startupreg: uTorrent => "J:\.active-content-data\uTorrent.exe" /MINIMIZED HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk" HKLM\...\StartupApproved\Run32: => "GrooveMonitor" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "QuickTime Task" HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\StartupApproved\Run: => "BitTorrent" HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-578200233-972976924-3727881056-1001\...\StartupApproved\Run: => "Norton Download Manager{N360PREMEXE-SHPD-FSD5183}" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{6A53FFA7-14A3-473D-B97A-90F24A8ABF1E}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{8115F12C-7BE3-4DA5-A269-1440965B0B90}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{AEEDCB9D-2E00-4CB9-8CA6-A7F96C308F30}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{0EABA12D-6BA4-4DF8-B80F-BDCC2204C972}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{FB59EED9-2687-478F-8927-4B2879029BAD}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe FirewallRules: [{708C6D91-A101-426B-9C17-55DA3141CB0C}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe FirewallRules: [{D984C254-99B6-4986-9E9D-F2719FB04B60}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{D7F3E807-9250-4DCB-8121-5C9B9651349E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3A322DC0-2051-4B0E-905E-AA4317BF4D32}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3EE117C5-7F8A-4439-89BA-76E55D0640B7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5B5CC1BF-3294-4948-AB37-167005619B8E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5497F5A7-6FE9-49FD-8AC4-18DC7FE3D7E7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{CC7091B3-5B4E-4CA2-97A3-1084AC0F3EED}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{939AC166-B7D9-4816-B7D7-94B3A7622CA1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{7FDFE949-66B2-4DEE-A252-08AB1124BFAC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{6B605A6F-CBB0-424B-9D52-F252849818C7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8E87D886-A7B9-4F8F-827B-B47FD393C07D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1DFA5CB2-222F-41D3-BAF0-22A27A366E1B}] => (Allow) C:\Users\barry\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{88C84CC4-A248-4BB7-A14A-FB060E57EC70}] => (Allow) C:\Users\barry\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{C2C77FBA-DDA4-4B3D-BBE1-32C6C5F0FD17}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS39A5.tmp\SymNRT.exe FirewallRules: [{74C73B38-6756-4455-B8D3-8DA123B07DD5}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS39A5.tmp\SymNRT.exe FirewallRules: [{51315499-F7C9-4A2F-8D80-A85B884F4677}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS37C2.tmp\SymNRT.exe FirewallRules: [{0208CE85-8348-4D85-BA79-19D9AC3F63FB}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS37C2.tmp\SymNRT.exe FirewallRules: [{82870C51-01EA-4B95-84D7-82F90ADCA7CA}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{8590E2D5-1898-4BD3-B5AD-A410248C1465}] => (Allow) LPort=1900 FirewallRules: [{13A04846-656A-470A-A3DA-6FE51B00F971}] => (Allow) LPort=2869 FirewallRules: [{993AC441-2BA9-45E4-907C-60CAE64FD78C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{3D973D9F-8729-4FE9-91BC-3908355D1A4D}] => (Allow) C:\Users\barry\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{ADB5C9B3-9D93-4AD4-BAF4-B220BD94E8B8}] => (Allow) C:\Users\barry\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{4A013411-D66A-4BA9-8363-A2E18FF79279}] => (Allow) C:\Users\barry\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{D3C850AB-074E-428C-BBE0-FAD3CEB01907}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS3C15.tmp\SymNRT.exe FirewallRules: [{A2353080-FBC9-4E23-BF27-1A440ED29610}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS3C15.tmp\SymNRT.exe FirewallRules: [{7771B447-6A50-4368-973C-CCBE0C851110}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe FirewallRules: [{7E98AC52-DEF1-4D54-8E55-5A21F0EFE883}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe FirewallRules: [{A6FE9459-4E72-4957-89FB-6854B010EA6E}] => (Allow) %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe FirewallRules: [{6E6C94D2-DDED-43BA-8423-84B3B05A2F75}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe FirewallRules: [{F0210722-D525-4EFD-9264-EBB109D6D8CC}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe FirewallRules: [{E7F417C2-8BF6-4807-8973-87FD9CBAFA93}] => (Allow) J:\.active-content-data\uTorrent.exe FirewallRules: [{D085E219-F968-4127-B99C-F84DC23EF16C}] => (Allow) J:\.active-content-data\uTorrent.exe FirewallRules: [{A03059A7-5114-4050-AE44-200B1154D0EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{21B5A304-5771-495A-BD5E-748D8F187132}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{ED2AD793-1C6D-475E-AFE2-33F1874D27C3}] => (Allow) C:\Program Files (x86)\FinalMediaPlayer\FMPCheckForUpdates.exe FirewallRules: [UDP Query User{036F742D-4A3C-4F4A-BDAC-B69D469DAE68}C:\program files (x86)\logitech\vid hd\vid.exe] => (Block) C:\program files (x86)\logitech\vid hd\vid.exe FirewallRules: [TCP Query User{82383E79-559A-480D-A472-0ED32026AC90}C:\program files (x86)\logitech\vid hd\vid.exe] => (Block) C:\program files (x86)\logitech\vid hd\vid.exe FirewallRules: [{0D7B1F02-4DF4-4A6A-9E2C-6B47FA727440}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{985E85B9-1A96-4211-91FB-1A8A0AB9ABFA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{A32FD39E-17EF-47D5-91A3-760B8D47666D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{C90975F1-B6C8-4F38-BD9C-46A555012429}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{4669A79E-3E28-4F5C-B11E-F329D8A94C59}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9915B4FC-9055-4D51-83F1-6D79F0EB7DE2}] => (Allow) C:\Program Files (x86)\Dogpile Bundle Toolbar\ToolbarUpdate.exe FirewallRules: [{63F9F278-547D-4948-8DAB-1567DD1780AC}] => (Allow) C:\Program Files (x86)\Dogpile Bundle Toolbar\ToolbarUpdate.exe FirewallRules: [{38357F75-6061-4599-B81A-B0FD4D60BFBE}] => (Allow) C:\Program Files (x86)\Dogpile Bundle Toolbar\TroubleShooter.exe FirewallRules: [{60B8F126-F5C0-4AE3-ADC5-2ACD47CCE7DE}] => (Allow) C:\Program Files (x86)\Dogpile Bundle Toolbar\TroubleShooter.exe FirewallRules: [UDP Query User{A19D7FAD-E698-4213-92B6-97C5B3C595F7}C:\program files (x86)\v cast music with rhapsody\rhapsody.exe] => (Block) C:\program files (x86)\v cast music with rhapsody\rhapsody.exe FirewallRules: [TCP Query User{BFE693FD-A500-477C-B69F-E8F19F22DBF7}C:\program files (x86)\v cast music with rhapsody\rhapsody.exe] => (Block) C:\program files (x86)\v cast music with rhapsody\rhapsody.exe FirewallRules: [UDP Query User{EC22FF6A-44A3-4C49-B7FF-DC628829E286}D:\setup.exe] => (Allow) D:\setup.exe FirewallRules: [TCP Query User{40F8B59F-C470-4EB5-9162-818C8DD76EE5}D:\setup.exe] => (Allow) D:\setup.exe FirewallRules: [{613FA075-734C-4DCE-8D19-C1916F4EF6A7}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{B2AD120A-BFFE-4D6A-B26B-58F4A3114483}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{CEC33CE9-DAC0-41C8-AFC7-EB4EC0C3192C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{93E1CCA6-5099-4D41-B45E-CF75AFB451F0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{8340B0D4-677E-4D5D-B9E0-B9AE3FFB8616}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{47C79E4B-77BB-44F6-A04F-0ADF4F446D2A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{C7CE3AB5-C5C0-4725-99EB-4C8FB98013BF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe FirewallRules: [{2A3E5F8D-FE4A-44EE-9ECE-0247E6C5234F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe FirewallRules: [{68747840-3E32-455E-A759-096FD528859F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{F9DBFAF0-6BDA-4160-9D43-636DEA7CC7BC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{E8944629-7D5D-4DE3-A0CF-F46DC6BB8790}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe FirewallRules: [{5658EEF7-A000-4C5F-BEC8-EF6DB14CF6C1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{8E8606F1-B2A3-43CE-97DB-7B4244DA52FA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{FB76A47E-8AE3-4E8B-96F8-2D8D1193E156}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{DC2E3591-42FB-48EC-B920-816D31E9BDEF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe FirewallRules: [{E9B04437-BE2B-407D-9C7B-138FF2917403}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe FirewallRules: [{F1E1ABAC-5686-476C-9114-7BEC9F88D655}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{33882E76-C014-4EED-AA61-78C80A081074}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{3C6237AF-EA0B-4457-8AA9-0ED32DF1BC8A}] => (Allow) D:\setup\hpznui40.exe FirewallRules: [UDP Query User{A0893E83-5038-431C-8977-B259C697020D}C:\program files (x86)\v cast music with rhapsody\rhapsody.exe] => (Allow) C:\program files (x86)\v cast music with rhapsody\rhapsody.exe FirewallRules: [TCP Query User{BF6F1094-FAA1-4E3B-8BAE-AA741B9738D9}C:\program files (x86)\v cast music with rhapsody\rhapsody.exe] => (Allow) C:\program files (x86)\v cast music with rhapsody\rhapsody.exe FirewallRules: [{67C29BDB-BF68-4642-B1A8-995E89791C52}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{A6DB48C1-BB27-4915-97E6-A0A565A1F7B8}] => (Allow) svchost.exe FirewallRules: [{993B28B8-759D-4F1F-84C6-31618D2AC109}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{88220340-4C15-430F-A95A-835FD071C818}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS3404.tmp\SymNRT.exe FirewallRules: [{679ECA42-5E1E-4FF6-83E7-2FFC8D1803B5}] => (Allow) C:\Users\barry\AppData\Local\Temp\7zS3404.tmp\SymNRT.exe ==================== Restore Points ========================= 23-06-2016 11:37:58 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Microsoft PS/2 Mouse Description: Microsoft PS/2 Mouse Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (06/23/2016 01:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1531 Error: (06/23/2016 01:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1531 Error: (06/23/2016 01:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/23/2016 11:38:09 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (06/23/2016 10:59:44 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: barry-PC) Description: Activation of app Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppX9zvsr9qeth9e9a03yr0g7rpdrcrwgn5r.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/23/2016 07:06:58 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname barry-PC.local already in use; will try barry-PC-2.local instead Error: (06/23/2016 07:06:58 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 barry-PC.local. Addr 192.168.1.67 Error: (06/23/2016 07:06:58 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.1.67:5353 16 barry-PC.local. AAAA 2602:0306:C41D:AD70:05AA:35F5:B8BB:01E8 Error: (06/23/2016 06:21:22 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Ignoring response received before we even began probing: 16 barry-PC-2.local. AAAA 2602:0306:C41D:AD70:05AA:35F5:B8BB:01E8 Error: (06/23/2016 06:21:22 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Ignoring response received before we even began probing: 16 barry-PC-2.local. AAAA 2602:0306:C41D:AD70:0000:0000:0000:003B System errors: ============= Error: (06/23/2016 11:07:35 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (06/23/2016 10:59:53 AM) (Source: DCOM) (EventID: 10005) (User: barry-PC) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} CodeIntegrity: =================================== Date: 2016-06-19 13:29:15.809 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-17 12:40:31.152 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-16 04:14:36.692 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-15 07:57:25.848 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-13 06:28:13.337 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-12 10:10:29.357 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2016-05-12 10:10:29.279 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2016-05-12 10:10:29.195 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2016-05-12 10:10:29.048 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2016-05-12 10:10:28.995 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz Percentage of memory in use: 64% Total physical RAM: 6109.14 MB Available physical RAM: 2176.17 MB Total Virtual: 15272.14 MB Available Virtual: 11780.57 MB ==================== Drives ================================ Drive c: (Gateway) (Fixed) (Total:916.41 GB) (Free:499.71 GB) NTFS Drive d: (FILTER_BUILD_2) (CDROM) (Total:2.38 GB) (Free:0 GB) UDF Drive k: (My Book) (Fixed) (Total:1862.98 GB) (Free:837.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 2928213B) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=916.4 GB) - (Type=07 NTFS) ======================================================== Disk: 6 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 00021365) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================