Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-01-2017 Ran by [removed] (18-01-2017 20:14:09) Running from C:\Users\[removed]\Desktop Windows 10 Home Version 1607 (X64) (2016-10-02 02:29:41) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3193119406-1769082486-1526078369-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3193119406-1769082486-1526078369-503 - Limited - Disabled) Family (S-1-5-21-3193119406-1769082486-1526078369-1000 - Administrator - Enabled) => C:\Users\Family Guest (S-1-5-21-3193119406-1769082486-1526078369-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3193119406-1769082486-1526078369-1008 - Limited - Enabled) Sandy (S-1-5-21-3193119406-1769082486-1526078369-1007 - Limited - Enabled) => C:\Users\Sandy ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501} FW: McAfee Firewall (Enabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-zip v9.20 (HKLM-x32\...\7-zip) (Version: v9.20 - TUGUU SL) <==== ATTENTION ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY) ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe Connect Add-in (HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\Adobe Connect Add-in) (Version: - ) Adobe Connect Add-in (HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\...\Adobe Connect Add-in) (Version: - ) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden Amazon Assistant (HKLM-x32\...\{AA11FD16-297F-452D-9015-F9014303CDD3}) (Version: 10.16.1216 - Amazon) <==== ATTENTION AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Applian FLV and Media Player 3.1.1.12 (HKLM-x32\...\Applian FLV and Media Player) (Version: 3.1.1.12 - Applian Technologies) Ask Toolbar Updater (HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.0.20007 - Ask.com) <==== ATTENTION BeeThink MusicHandle 3.2 (HKLM-x32\...\BeeThink MusicHandle 3.2 (MP3,WMA,OGG,WAV Converter)_is1) (Version: - BeeThink SoftWare, Inc.) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden Bonjour (HKLM\...\{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}) (Version: 2.0.4.0 - Apple Inc.) Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC) (Version: 8.10.4.24 - Canon Inc.) Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.5.1.7 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.) ccc-core-static (x32 Version: 2010.0511.2153.37435 - ATI) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Cisco Connect (HKLM-x32\...\Cisco Connect) (Version: 1.4.11299.0 - Cisco Consumer Products LLC) Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited) Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.45 - Creative Technology Limited) Creative Audio Control Panel (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited) Creative Diagnostics (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited) Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited) Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs) Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited) Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited) Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited) Creative System Information (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited) Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited) CutePDF Writer 2.8 (HKLM\...\CutePDF Writer Installation) (Version: - ) CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3210 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited) Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited) DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.2.4412 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.2.4412 - Hewlett-Packard) Hidden EaseUS Partition Master 10.5 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS) EaseUS Todo Backup Free 8.6 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 8.6 - CHENGDU YIWO Tech Development Co., Ltd) Elevated Installer (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.81.0000 - Seiko Epson Corporation) Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation) Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.63.00 - SEIKO EPSON CORPORATION) Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 2.30.00 - SEIKO EPSON Corp.) EPSON Scan PDF Extensions (HKLM-x32\...\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.03.0001 - SEIKO EPSON Corp.) Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION) EPSON WF-3640 Series Printer Uninstall (HKLM\...\EPSON WF-3640 Series) (Version: - SEIKO EPSON Corporation) Epson WF-3640 User’s Guide version 1.0 (HKLM-x32\...\UsersGuideEpson WF-3640 User’s Guide_is1) (Version: 1.0 - ) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Escape Rosecliff Island (x32 Version: 2.2.0.95 - WildTangent) Hidden Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG) Garmin City Navigator North America NT 2013.10 Update (HKLM-x32\...\{DE2E1909-12C2-4249-8003-7978BEA3A14F}) (Version: 16.10.0.0 - Garmin Ltd or its subsidiaries) Garmin City Navigator North America NT 2013.40 Update (HKLM-x32\...\{CB9E92AF-55F4-46A7-BC7A-16005E4BF39D}) (Version: 16.40.0.0 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM-x32\...\{17079027-EB8A-42C6-9BF8-825B78889F6A}) (Version: 4.0.1 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin x64 (HKLM\...\{EB418DDD-5365-4381-87F6-D8BBB21CC1CA}) (Version: 4.0.1 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{9fbf4745-0038-4ed3-aee1-87af9b9ef8f1}) (Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden H&R Block Deluxe + Efile + State 2011 (HKLM-x32\...\{C6006AED-E5A7-4F77-BAD5-95AC43DE04F3}) (Version: 11.05.7102 - HRB Technology, LLC.) H&R Block Deluxe + Efile + State 2012 (HKLM-x32\...\{89D20029-0578-4D8D-979A-695C8D868868}) (Version: 12.05.7803 - HRB Technology, LLC.) H&R Block Deluxe + Efile + State 2013 (HKLM-x32\...\{EDE796DE-0A72-464D-9D21-F04BC41A092B}) (Version: 13.05.6502 - HRB Technology, LLC.) H&R Block Deluxe + Efile + State 2015 (HKLM-x32\...\{E7BFC29A-9459-4534-9E35-BF1D66A18BAA}) (Version: 15.05.7401 - HRB Technology, LLC.) H&R Block Deluxe + Efile 2010 (HKLM-x32\...\{81FB87B4-AEA6-49A8-9110-BED4AEFC20E8}) (Version: 10.03.6402 - HRB Technology, LLC.) H&R Block Maryland 2011 (HKLM-x32\...\{7E959791-CC56-4278-87D7-B7C89F794491}) (Version: 1.11.6301 - HRB Technology, LLC.) H&R Block Maryland 2012 (HKLM-x32\...\{D636E311-E204-47E6-8740-E2B829F0A531}) (Version: 1.12.5201 - HRB Technology, LLC.) H&R Block Maryland 2013 (HKLM-x32\...\{8C912631-D7B4-4578-8B1A-14092E3F4408}) (Version: 1.13.4901 - HRB Technology, LLC.) Heroes of Hellas 2 - Olympia (x32 Version: 2.2.0.95 - WildTangent) Hidden Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent) HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 4.2.4521 - Hewlett-Packard) HP MediaSmart Music (HKLM-x32\...\InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}) (Version: 4.2.4517 - Hewlett-Packard) HP MediaSmart Photo (HKLM-x32\...\InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}) (Version: 4.2.4513 - Hewlett-Packard) HP MediaSmart SmartMenu (HKLM\...\{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}) (Version: 3.1.2.4 - Hewlett-Packard) HP MediaSmart Video (HKLM-x32\...\InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}) (Version: 4.2.4522 - Hewlett-Packard) HP MediaSmart/TouchSmart Netflix (HKLM-x32\...\{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}) (Version: 1.0.4.0 - Hewlett-Packard) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Setup (HKLM-x32\...\{53469506-A37E-4314-A9D9-38724EC23A75}) (Version: 8.4.4400.3525 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.0.12844.3519 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.1.6.0 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden HRBlockDirect version 1.1.2.0 (HKLM-x32\...\{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1) (Version: 1.1.2.0 - HRBlock) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) IHA_MessageCenter (HKLM-x32\...\{53C49C8D-DFB2-42B9-A7EF-0F9CA386CC13}) (Version: 1.8.17 - Verizon) Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.15 - Oracle Corporation) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation) Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Juniper Networks Network Connect 7.1.0 (HKLM-x32\...\Juniper Network Connect 7.1.0) (Version: 7.1.0.18671 - Juniper Networks) Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\Juniper_Setup_Client) (Version: 7.1.3.11013 - Juniper Networks, Inc.) Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\...\Juniper_Setup_Client) (Version: 7.1.2.10059 - Juniper Networks, Inc.) Junk Mail filter update (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) LTCM Client (HKLM-x32\...\LTCM Client) (Version: - Leader Technologies Inc.) magicJack (HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\...\magicJack) (Version: 4.1.7574.5297 - magicJack L.P.) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) McAfee All Access – Total Protection (HKLM-x32\...\MSC) (Version: 14.0.3061 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.164 - McAfee, Inc.) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft IntelliType Pro 8.2 (HKLM\...\Microsoft IntelliType Pro 8.2) (Version: 8.20.469.0 - Microsoft Corporation) Microsoft Office Language Pack 2010 - Chinese (Traditional)/中文(繁體) (HKLM-x32\...\Office14.OMUI.zh-tw) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation) Microsoft Project Professional 2010 (HKLM-x32\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 Native Client (HKLM\...\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{f45b48a7-f616-4211-b927-17cab6a96613}) (Version: 8.0.58298 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MiniTool Partition Wizard Home Edition 5.2 (HKLM-x32\...\{12FEC00C-027C-4A34-9AAB-562EDA43DC18}_is1) (Version: - MiniTool Solution Ltd.) Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.2.4412 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.2.4412 - Hewlett-Packard) Hidden Mozilla Firefox 50.1.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-US)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) Mozilla Thunderbird 45.1.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 45.1.1 (x86 en-US)) (Version: 45.1.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Mystery P.I. - The London Caper (x32 Version: 2.2.0.95 - WildTangent) Hidden NEF Codec (HKLM-x32\...\{A89768CF-CD21-44FD-A723-16D5A8557415}) (Version: 1.00.0000 - Nikon) NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.3.1.46 - NETGEAR Inc.) Nikon Message Center (HKLM-x32\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.91.000 - ) Octoshape add-in for Adobe Flash Player (HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\Octoshape add-in for Adobe Flash Player) (Version: - ) Octoshape add-in for Adobe Flash Player (HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\...\Octoshape add-in for Adobe Flash Player) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OverDrive Media Console (HKLM-x32\...\{D07205E7-F6D3-4333-AFCC-782A07685B72}) (Version: 3.2.20 - OverDrive, Inc.) Pdf995 (installed by H&R Block) (HKLM-x32\...\Pdf995) (Version: 15.0s - ) PdfEdit995 (installed by H&R Block) (HKLM-x32\...\PdfEdit995) (Version: - ) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.7717 - CyberLink Corp.) PhotoNow! (x32 Version: 1.1.7717 - CyberLink Corp.) Hidden PictureProject (HKLM-x32\...\{FF3999BE-1A7B-4738-88AA-97BF14094A4A}) (Version: 1.0 - Nikon) Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) Plex Media Server (HKLM-x32\...\{1A7638A1-E022-4F99-ADF3-F46DB04689C1}) (Version: 0.9.722 - Plex, Inc.) Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4329 - CyberLink Corp.) Power2Go (x32 Version: 6.1.4329 - CyberLink Corp.) Hidden PowerChute Personal Edition 3.0.2 (HKLM-x32\...\{8ED262EE-FC73-47A9-BB86-D92223246881}) (Version: 3.0.2 - Schneider Electric) PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3129 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.3129 - CyberLink Corp.) Hidden PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-13231864975D}) (Version: 5.10.621.0 - NewspaperDirect Inc.) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Random Generator for Microsoft Excel (HKLM-x32\...\{E6753BFA-65E6-4D63-B1F4-C7CB90387658}) (Version: 3.5.0 - Add-in Express Ltd.) Raptr (HKLM-x32\...\Raptr) (Version: 5.2.1-r113066-release - Raptr, Inc) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3219 - CyberLink Corp.) Hidden RoxioNow Player (HKLM-x32\...\{0EDEB615-1A60-425E-8306-0E10519C7B55}) (Version: 1.9.5.101 - RoxioNow) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0404-0000-0000000FF1CE}_Office14.OMUI.zh-tw_{660B00F1-F0FF-4934-83F1-68976BD14894}) (Version: - Microsoft) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited) Virtual Account Numbers (HKLM-x32\...\{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}) (Version: 4.0.0.2248 - Citi) Virtual Account Numbers (x32 Version: 1.0.1.0 - Citi) Hidden Virtual Account Numbers (x32 Version: 1.0.6.0 - Citi) Hidden Virtual Families (x32 Version: 2.2.0.95 - WildTangent) Hidden Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1-2) (Version: 1.0.3.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.3.1 (Version: 1.0.3.1 - LunarG, Inc.) Hidden Vz In-Home Agent (HKLM-x32\...\VzInHomeAgent) (Version: 9.0.93.0 - Verizon) Wheel of Fortune 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (HKLM\...\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinZip 15.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24011}) (Version: 15.5.9580 - WinZip Computing, S.L. ) Zinio Reader 4 (HKLM-x32\...\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.0.3184 - Zinio LLC) Zinio Reader 4 (x32 Version: 4.0.3184 - Zinio LLC) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Family\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => No File CustomCLSID: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000_Classes\CLSID\{092dfa86-5807-5a94-bf3b-5a53ba9e5308}\InprocServer32 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll => No File CustomCLSID: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000_Classes\CLSID\{4335840D-B73D-3D4D-B329-9FB31040F25A}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000_Classes\CLSID\{87AE33C5-C5A3-3E24-9AEC-5BDB5C426972}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000_Classes\CLSID\{CA8AA574-88C3-4600-8C59-018EB3FF97AE}\InprocServer32 -> C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader64.dll () CustomCLSID: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000_Classes\CLSID\{E83EC3E3-6453-32DF-B499-839AF001383A}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {015E7165-C9D9-4973-B7B6-84BFE147C44A} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3193119406-1769082486-1526078369-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {0614E216-9586-4DC9-9417-9663E71FFA81} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {07D83986-12F8-47F9-851F-2A2A90F33C5F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {09DD22EA-249F-4834-94E9-2F324E944E0D} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {0D71B8D1-29C0-4F23-BBF5-89FA5C462BFC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {0D9C2C17-91D5-4548-AFA9-D4AFCAA7648A} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe Task: {0E8551ED-005D-40C6-90E3-80D5843F8DBB} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {0FAF1049-BE1E-4D4C-B454-393E48321BA2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {12862875-FC19-41F2-BA20-6ECCA85C2BD4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {27C411B7-E322-486B-938E-48EF225CFC07} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {28C50382-BB24-4FE1-B5AC-37B459B1AFE6} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2016-10-20] (McAfee, Inc.) Task: {2F0B2903-9F5B-4E96-8394-51698C1980DD} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {2FC376BA-AAD8-4DD3-A0C7-48D313347053} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {30744BA7-9140-4059-B4A1-EDC2E5F5FB3E} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3193119406-1769082486-1526078369-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {3691FF85-D708-409B-BE7A-284ADA2BCFB2} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {3782F133-3394-4A8A-8E4F-26ED808EFDDC} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3193119406-1769082486-1526078369-1007 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {392AAB2B-15F7-48B1-B07E-0BE480D834F6} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {4111FB03-3E1B-4018-BFC8-73F89639A501} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {4174D0B1-D662-4442-BE05-E74FDA7AB687} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {4E39B9C5-B579-4918-923B-6ECCA71A7668} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {4F4B4018-13DF-4064-AB87-AB28D74B2DDD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-13] (Adobe Systems Incorporated) Task: {53C9E3DD-FAFC-4111-9536-C3F26726B241} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe Task: {5DA41947-0C42-4317-B484-A81C9C83FF54} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {62352700-33DA-4863-B7FC-09D4300ADDB7} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe Task: {63FFF9A0-D8C4-4DDC-8AA7-069CC6550308} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {668C8773-5629-45D6-8924-0A5FE5385BB4} - System32\Tasks\EPSON WF-3640 Series Update {B518405D-AA42-430C-A28A-80EAE82E07AB} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKDE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {66E25D6C-EFF7-4A53-B3A6-81428EDF3FF2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {71F6C50D-8701-4BF5-9AF7-E5EBD962EE4F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {72CF8FFE-44B3-41E1-96AC-044B938F1B27} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {75E207A5-0575-446A-974A-D178024369F1} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {7B0DFFF0-6088-41CF-A75A-878BA845C91F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {7C005C8E-6E34-48D7-986A-0B8451084195} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {7F37CCEE-E271-4848-992F-C44CA19ECEC4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2016-12-07] (HP Inc.) Task: {809983C0-FD09-4683-A347-76D0DE324591} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3193119406-1769082486-1526078369-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {82407A03-39B0-4CE9-8D72-EA45D98983DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe [2016-02-18] (Hewlett-Packard) Task: {8465E2C1-36AD-4EA3-8ECA-5C561635B621} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {85674EBF-CF04-4889-AE8E-86128E8FA6B9} - System32\Tasks\EPSON WF-3640 Series Invitation {B518405D-AA42-430C-A28A-80EAE82E07AB} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKDE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {915097E3-CA0E-4FDA-B09E-9D9DCC8A6531} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2016-10-12] (HP Inc.) Task: {9672DED8-490A-4C80-AE18-424D1D052E89} - System32\Tasks\HPCeeScheduleForFAMILY-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {9961AD39-3853-47EF-A6C2-7B5BE1386D58} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3193119406-1769082486-1526078369-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {99F3858A-8F6C-44F9-BD05-5FEAB968D8EB} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3193119406-1769082486-1526078369-1007 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {9D68AD1A-3850-45B6-BC03-009D74EB709E} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A0AFD6C9-A23F-4D2A-86FD-5C6A4A25FE3C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-13] (Microsoft Corporation) Task: {A1D35F98-7D4F-4EC2-9239-00601DC46FCE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A489B528-91C6-4184-A0AF-723508AC6495} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {A894259E-D7D0-41BB-AED3-1D8F66401E39} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A8FA6593-8A6C-4B70-8421-E3ED11029419} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-01-16] () Task: {A9119FA2-D99A-4B36-A29A-E978C6116B97} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3193119406-1769082486-1526078369-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {AAA02695-E986-4E78-8A95-D54A5DB6B515} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3193119406-1769082486-1526078369-1007 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {B10439E1-E185-4DB2-807B-DD6AC98B530E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {B4036C4F-A859-4F1C-B4B2-D97E30ED03BB} - System32\Tasks\HPCeeScheduleForFamily => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {B495DC14-2E65-4B39-BD9F-3621A216936B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {B4B40E10-10CD-451A-8E8A-CEC92B286609} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {B92A5C1F-2083-497F-B44F-60F380623673} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {B93D8CB7-5F10-4552-AE2D-CDCD032D9158} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2016-10-20] (McAfee, Inc.) Task: {BA0D19FD-F25E-44BB-9337-7BFFAFE95B47} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3193119406-1769082486-1526078369-1007 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {BADD0CB8-BF88-49A8-B7AA-B304FF88E7C8} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {BDAC8B8F-F5E3-4343-A02A-0B0EBAC345FD} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-03-21] (Advanced Micro Devices, Inc.) Task: {BF6BF35E-671A-4583-AE80-687A35C64B24} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION Task: {C4D5D3CC-58F8-43D2-AC4F-FA91F4439F57} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D3F9C411-49EE-4C92-B9DA-BE9875FFA017} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3193119406-1769082486-1526078369-1007 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe Task: {DAFF1AA1-FB20-41EE-B4EC-02535747558B} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3193119406-1769082486-1526078369-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {E7471891-69E8-4E37-9725-A6D106A21D09} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => c:\Program Files\Microsoft IntelliType Pro\IType.exe [2011-08-10] (Microsoft Corporation) Task: {E8D73A34-9C1E-4CF9-AF94-4FCFE680986E} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {E8FA7856-F1C0-48C9-88EE-4613503C97E8} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {EFE38090-5A2F-4BF8-B341-1E8DFFAE9EB6} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2016-12-09] (McAfee, Inc.) Task: {F809B3DB-23B7-4759-B88C-17638039582F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {FC168DBD-8327-4CC8-BEBE-28B294DC8806} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {FE23CFC7-B003-4838-A9EC-35BD07AF55C9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\EPSON WF-3640 Series Invitation {B518405D-AA42-430C-A28A-80EAE82E07AB}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKDE.EXE Task: C:\WINDOWS\Tasks\EPSON WF-3640 Series Update {B518405D-AA42-430C-A28A-80EAE82E07AB}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKDE.EXE:/EXE:{B518405D-AA42-430C-A28A-80EAE82E07AB} /F:UpdateWORKGROUP\FAMILY-HP$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\HPCeeScheduleForFAMILY-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForFamily.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-13 20:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2011-05-08 10:34 - 2009-11-05 07:40 - 00085504 _____ () C:\WINDOWS\System32\cpwmon64.dll 2014-02-16 17:17 - 2014-03-05 09:18 - 00040448 _____ () C:\WINDOWS\System32\pdf995mon64.dll 2016-12-16 14:05 - 2016-12-16 14:05 - 00099000 _____ () C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe 2016-12-13 20:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-12-30 06:17 - 2016-12-30 06:17 - 01678560 _____ () C:\Users\Family\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\ClientTelemetry.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-09-17 06:29 - 2015-06-23 00:08 - 00245800 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe 2016-10-02 00:28 - 2016-10-02 00:28 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-01-13 15:11 - 2016-12-21 02:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-01-13 15:10 - 2016-12-21 01:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-01-13 15:10 - 2016-12-21 01:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-01-13 15:10 - 2016-12-21 01:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-01-13 15:10 - 2016-12-21 01:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-01-13 15:10 - 2016-12-21 01:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-01-13 15:10 - 2016-12-21 01:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2010-09-15 12:31 - 2010-09-15 12:31 - 00611896 _____ () C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe 2015-03-18 19:46 - 2014-04-08 08:13 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe 2015-09-17 06:30 - 2014-12-15 00:04 - 00253992 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe 2015-09-17 08:31 - 2014-11-18 13:44 - 00255072 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.5\bin\TrayPopupE\TrayTipAgentE.exe 2015-11-04 15:43 - 2015-11-04 15:43 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2016-12-14 15:01 - 2016-12-14 15:01 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-12-14 15:01 - 2016-12-14 15:01 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-12-14 15:01 - 2016-12-14 15:01 - 42130432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-12-14 15:01 - 2016-12-14 15:01 - 02216448 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\roottools.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00098856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CodeLog.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00017448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CompressFile.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00088616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 01296424 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00060968 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll 2015-09-17 06:29 - 2015-08-01 14:10 - 00022568 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CmcTbProxy.dll 2015-09-17 06:29 - 2015-08-01 14:10 - 00186920 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCPipeCenter.dll 2015-09-17 06:29 - 2015-08-01 14:10 - 00165416 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCAdapt.dll 2015-09-17 06:29 - 2015-08-01 14:10 - 00058408 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBInfo.dll 2015-09-17 06:29 - 2015-08-01 14:10 - 00015912 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCNetTokenProxy.dll 2015-09-17 06:29 - 2015-06-22 23:58 - 00108072 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActivationOnline.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\logsys.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00030248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DiskSearchImg.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00068136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\MountImg.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00158248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ImgFile.dll 2015-09-17 06:29 - 2015-03-14 10:54 - 00281128 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DsImgFile.dll 2015-09-17 06:29 - 2015-03-14 10:54 - 00072232 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckImg.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00139816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\vhdvmdk.dll 2015-09-17 06:29 - 2015-06-22 23:58 - 00037416 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\BootDriver.dll 2015-09-17 06:29 - 2015-03-14 10:54 - 00759848 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ExImage.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00193064 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBackupSize.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00407080 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidImage.dll 2015-09-17 06:29 - 2015-06-22 23:58 - 00148008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumDisk.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00076840 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FatLib.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00207912 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSLib.dll 2015-09-17 06:29 - 2015-06-22 23:58 - 00024616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\GetDriverInfo.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00020520 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CorrectMbr.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00032296 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumTapeDevice.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00034856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbTapeBrowse.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00064040 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\RegLib.dll 2015-09-17 06:29 - 2015-08-01 14:10 - 00025128 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AccountManager.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00115752 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NasOperator.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00194088 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBrowser.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudOperator.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00037928 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActiveOnline.dll 2015-09-17 06:29 - 2015-06-22 23:58 - 00136232 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\VMConfig.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00020008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00043048 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbDataSwap.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00353832 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceManager.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00027176 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceAdapter.dll 2015-09-17 06:29 - 2015-06-22 23:58 - 00137256 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Device.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00146984 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Partition.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00050216 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FileSystemAnalyser.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00061992 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FATFileSystemAnalyser.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00089640 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Common.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00056360 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSFileSystemAnalyser.dll 2015-09-17 06:29 - 2014-12-14 23:53 - 00223784 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SmartBackup.dll 2015-03-18 19:46 - 2014-04-08 08:08 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll 2013-12-26 11:33 - 2013-10-07 12:31 - 00039424 _____ () C:\Program Files (x86)\Virtual Account Numbers\VANRes.dll 2015-09-17 06:30 - 2014-12-15 00:04 - 00223272 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\traynet.dll 2015-09-17 06:30 - 2014-12-15 00:04 - 00275496 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\libcurl.dll 2015-09-17 06:30 - 2014-12-15 00:04 - 00118328 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\zlib1.dll 2015-09-17 06:30 - 2015-03-14 11:05 - 00249896 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\uexper.dll 2015-09-17 08:31 - 2014-02-13 14:27 - 00222792 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.5\bin\TrayPopupE\traynet.dll 2015-09-17 08:31 - 2014-02-13 14:27 - 00275528 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.5\bin\TrayPopupE\libcurl.dll 2015-09-17 08:31 - 2014-02-13 14:27 - 00113166 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.5\bin\TrayPopupE\zlib1.dll 2015-09-17 08:31 - 2014-02-13 14:27 - 00249928 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.5\bin\TrayPopupE\uexper.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\amazon.com -> hxxps://amazon.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2017-01-13 16:34 - 00000848 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Family\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-3193119406-1769082486-1526078369-1007\Control Panel\Desktop\\Wallpaper -> C:\Users\Sandy\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\barbara and vember_02.jpg DNS Servers: 10.0.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AtHomeConnect.lnk => C:\Windows\pss\AtHomeConnect.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HRBlockDirect.lnk => C:\Windows\pss\HRBlockDirect.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Family^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: Freecorder FLV Service => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run MSCONFIG\startupreg: FUFAXRCV => "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe" MSCONFIG\startupreg: FUFAXSTM => "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" MSCONFIG\startupreg: Garmin Lifetime Updater => C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart MSCONFIG\startupreg: HF_G_Jul => "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction HKLM\...\StartupApproved\StartupFolder: => "Image Transfer Utility.lnk" HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\StartupFolder: => "NkbMonitor.exe.lnk" HKLM\...\StartupApproved\Run: => "hpsysdrv" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "EaseUS EPM tray" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "QuickTime Task" HKLM\...\StartupApproved\Run32: => "Display" HKLM\...\StartupApproved\Run32: => "Raptr" HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\StartupApproved\Run: => "GarminExpressTrayApp" HKU\S-1-5-21-3193119406-1769082486-1526078369-1000\...\StartupApproved\Run: => "OneDrive" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [MSMQ-In-TCP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => LPort=808 FirewallRules: [{900B00D1-B043-4A27-8610-1DBF1D5FEA68}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{D6413960-5E4D-4A70-9344-712FD3FDE062}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{68AFDD4D-3588-4582-9A6E-8384D0984BF1}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{2E8AA6B9-75ED-4902-8E6C-A34C681AE28F}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{4115050A-A7D4-4BE2-A28A-4988A3345766}] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{C0A2351C-8797-487D-9C27-BA6193BC3B48}] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{914E9CB8-9615-4FF4-8359-B1DAB938AB17}] => C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{4817B4DD-B3C8-4EBE-BBA0-519CC31E32BA}] => C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{29FBECA1-4F67-4A36-9369-C92E0918AE41}] => C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{7F6A7FD0-F1DD-4EDA-96A6-508AFF2581D5}] => C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{FAA03708-BF3D-4816-BFFA-054736505775}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{15F266CE-C9D3-4D49-AD73-3D74FFE72154}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{0D6D8505-CA85-40A8-BAFD-106C01C4C50C}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{6F7B7DAE-B4A9-4377-8413-FF23D0922A7D}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{81C5D1EA-9C1C-46DA-B124-9FAF9B800B6E}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{1896CE3A-895A-40D3-941C-A07B998F3C69}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{E439D82B-96CC-4773-B593-04C9F0723428}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{FB5D29A5-BC5E-4D18-9A37-F2D23139BDA8}] => C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{BBAD11BE-9E56-4DB4-AA3C-9F27A357B80A}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{27DCDF39-39E7-49AB-8967-F7EFBA0863D1}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{34A92B37-241F-43A5-9015-8610652787E3}] => C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe FirewallRules: [{93413566-8C02-4A96-A950-81BA1BE24412}] => C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe FirewallRules: [{B5C99828-4E29-48E8-BD31-39C7164E751F}] => C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{2F7EDB04-DD0A-4848-9296-4B6E50AF883B}] => C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{1AEFA21D-841C-4C5D-B15C-8C62AC24026E}] => C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{E09AD9DB-3346-45AA-8361-6AB15E26A0FF}] => C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{A008D443-0786-4983-8A05-6EC4421B0179}] => C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe FirewallRules: [{1D33FB6E-3801-4D9E-9828-CACAF3C469B8}] => C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe FirewallRules: [{F38CDC20-635E-402F-B59B-123CD897F814}] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe FirewallRules: [{34891D58-3850-426A-B631-875F2E31A32B}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{02B3BE95-715B-4DDC-BD05-AA989A3179C6}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [UDP Query User{8949992F-64EC-47B8-B71A-19CCC1206901}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{57A2CBA6-79A2-46F6-A939-1FC7F2771D58}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{057F50BF-3F97-458D-B0EC-1BB16B85A5C5}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{CFFF1F34-204C-413A-B120-61165CDD3A38}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [{AE73F6CE-3264-4AB1-91EA-61594569DA93}] => C:\Program Files (x86)\AVG\AVG2012\avgemca.exe FirewallRules: [{D8153C76-1CC2-443D-9FF2-C839514E1F7E}] => C:\Program Files (x86)\AVG\AVG2012\avgemca.exe FirewallRules: [{CCFCE23C-178A-4F2C-9519-DC7E8513D9ED}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{BAE6BBF3-4619-4357-AD24-20459648A703}] => LPort=1900 FirewallRules: [{288EFF4B-BB50-4124-B629-3808314BB075}] => LPort=2869 FirewallRules: [{E79D7233-59BB-4EEC-9E74-FB22515AC4A8}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{A05F7739-D116-49EE-9953-EA417E28248F}] => LPort=50000 FirewallRules: [{C03E44B9-35B3-4FEA-96C1-1FAAB94F2CD6}] => LPort=50000 FirewallRules: [{8021EA96-AAFC-4C6B-9B3C-999D9B207776}] => C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [{1688ED7A-13E5-41A1-8DD5-08CB24B0FF79}] => C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [UDP Query User{F97BD500-B482-46CF-9C89-8D8C35675610}C:\program files (x86)\mozilla firefox\plugin-container.exe] => C:\program files (x86)\mozilla firefox\plugin-container.exe FirewallRules: [TCP Query User{E119D00D-BC10-42C6-952F-BFCD5EEE216D}C:\program files (x86)\mozilla firefox\plugin-container.exe] => C:\program files (x86)\mozilla firefox\plugin-container.exe FirewallRules: [{6F0816F5-98A2-498D-BFB1-60B9AFB307C7}] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [UDP Query User{AAAC6F33-D802-4D97-A638-AE8C9BAE7771}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{BACA4CC0-F9CA-47C2-B993-9B6EC50A7EFE}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{7C847989-29F3-41B4-B06E-3364C8B2293D}] => C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe FirewallRules: [{AA35E247-E1CA-4014-B3AB-057C5AEAC799}] => C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe FirewallRules: [UDP Query User{BEA478A7-9A53-4004-AD38-A5DC380A609C}C:\users\family\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe] => C:\users\family\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe FirewallRules: [TCP Query User{D709F619-1585-45E9-BCD3-F52647D2EE32}C:\users\family\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe] => C:\users\family\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe FirewallRules: [UDP Query User{F9BD5184-A554-4C9F-A4F3-295A93C0E7C1}C:\users\family\appdata\roaming\mjusbsp\magicjack.exe] => C:\users\family\appdata\roaming\mjusbsp\magicjack.exe FirewallRules: [TCP Query User{D1EE24A6-1B43-47BC-92DD-3EC70A421B1B}C:\users\family\appdata\roaming\mjusbsp\magicjack.exe] => C:\users\family\appdata\roaming\mjusbsp\magicjack.exe FirewallRules: [{239503BB-30D7-4004-BB31-D20F383D7CE7}] => C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{7BE7D993-39E1-46B1-9F45-22C173CED7E2}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{B56B0610-4F82-45F6-B2E2-D302FEE958C6}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{EA3AD6D4-C8D9-438B-835D-5672B2705B41}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{BFA89DA0-D2A1-4348-BB4E-B95E73DAB22D}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe FirewallRules: [{AD1E7339-D790-4D9C-AA75-8E65A19AFA4F}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe FirewallRules: [{CD009BC0-D8E1-49B8-9D44-DA497FEDA60A}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{BB1ABFEA-9CE5-4676-8A04-0104F1DEE4BC}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{E20D527D-3A5E-4471-A65F-316C512616F3}] => C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{161ED948-562F-4431-BCB5-3BC662234F92}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{CDCF0C27-0366-48B3-B806-F1BA9E675418}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe FirewallRules: [{F14E15BE-95E2-44A8-964A-58AFF1AAE4D0}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{DA7066D9-9A90-463A-9B04-82A3665161AF}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe FirewallRules: [{178F7186-336D-4347-AFB0-C50C959D0F27}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{46D76F54-AFCA-48A0-A423-BB82B5CC2E7C}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{CFA835B8-C754-48C6-BA40-B7265737F792}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{E728B7F2-6341-4953-ABC4-7EB0285C9BD5}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{D7A103AE-3335-4637-9C92-A63755D4CF53}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe FirewallRules: [{FA6FCEC8-F77C-4E8C-B349-9B5D823DEAB5}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe FirewallRules: [{926BF024-B5E3-4E5E-B2DC-49C3F308611D}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{73A39D72-1764-441E-BFD8-95E71029B90C}] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [UDP Query User{8CA540DA-D4D1-4FCA-BB5C-9A1639103BAD}C:\users\family\appdata\roaming\mjusbsp\magicjack.exe] => C:\users\family\appdata\roaming\mjusbsp\magicjack.exe FirewallRules: [TCP Query User{02F86038-EC2F-4500-BB05-FA72ECFA73C0}C:\users\family\appdata\roaming\mjusbsp\magicjack.exe] => C:\users\family\appdata\roaming\mjusbsp\magicjack.exe FirewallRules: [{A4EE46CD-ACF9-4C5C-AFC1-F8509ECC003E}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{087436F7-463B-455B-8AA8-81CF4E031315}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{AA1CCCC3-E787-491B-91C6-AEDD60BB1DB9}] => C:\Program Files (x86)\Roxio\RoxioNow Player\RNowShell.exe FirewallRules: [{F9E24426-6830-40CF-B7F1-06DDA8563581}] => C:\Program Files (x86)\Roxio\RoxioNow Player\RNowShell.exe FirewallRules: [{0067AA5D-F73C-45CB-AB25-1937676360A6}] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Music\HPTouchSmartMusic.exe FirewallRules: [{587ED132-141F-4935-9F1B-A9E1C0191384}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\Video\HPMediaSmartVideo.exe FirewallRules: [{F6E86A7D-1536-4406-8F34-19F97C276BE3}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\Photo\HPMediaSmartPhoto.exe FirewallRules: [{8157465E-5F4A-4A67-B746-6BA73A20A948}] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe FirewallRules: [{8D07278B-146E-42C6-A44C-FA9699D8AA7D}] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe FirewallRules: [{8ED13417-35B8-471D-B3E6-97CF7C7DEFDB}] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe FirewallRules: [{863C3C8D-9CEF-448C-BD79-5FB900AF8E4B}] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe FirewallRules: [{0A8C023B-43D1-4EE1-B288-23DD77A26861}] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe FirewallRules: [{5710F1D5-B94D-4E51-AF20-339FCB3D6CF8}] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe FirewallRules: [{E09287C3-1A9E-403B-B440-DD285E1096FA}] => c:\Program Files (x86)\CyberLink\PowerDirector\PDR8.EXE FirewallRules: [{767AFE34-0A92-46F5-9DB8-7AD50213C5C4}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{520FFA03-F4A0-4825-871E-4C40263F8880}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E7113384-99D9-4519-84BD-5D71AD654B26}] => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe FirewallRules: [{6DECCE70-80C7-4FA0-8675-CAB9C9DE1ADF}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{9E67A1AF-E091-4F1F-AE4A-91C3EE6C6D8D}] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{59A90C4D-2D5B-4986-A84F-99BA111507BA}] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe ==================== Restore Points ========================= 16-01-2017 08:03:00 Installed Epson Software Updater 16-01-2017 10:09:43 Windows Backup ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/18/2017 06:49:48 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program McUICnt.exe version 8.3.3037.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 8f4 Start Time: 01d271d19e2e0906 Termination Time: 4294967295 Application Path: C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe Report Id: caab4e1c-ddd8-11e6-8dc9-643150331188 Faulting package full name: Faulting package-relative application ID: Error: (01/18/2017 06:11:43 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program McUICnt.exe version 8.3.3037.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 8f4 Start Time: 01d271d19e2e0906 Termination Time: 4294967295 Application Path: C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe Report Id: 7863473e-ddd3-11e6-8dc9-643150331188 Faulting package full name: Faulting package-relative application ID: Error: (01/18/2017 04:59:24 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid. . Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet Error: (01/18/2017 04:58:18 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (01/17/2017 09:09:00 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest".Error in manifest or policy file "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (01/17/2017 09:03:22 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest".Error in manifest or policy file "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (01/17/2017 08:57:44 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest".Error in manifest or policy file "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (01/17/2017 08:52:07 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest".Error in manifest or policy file "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (01/17/2017 08:46:29 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest".Error in manifest or policy file "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (01/17/2017 08:40:52 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest".Error in manifest or policy file "C:\Users\Family\AppData\Roaming\Add-in Express\Random Generator for Microsoft Excel\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. System errors: ============= Error: (01/18/2017 07:49:55 PM) (Source: DCOM) (EventID: 10010) (User: Family-HP) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. Error: (01/18/2017 07:47:55 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (01/18/2017 07:27:49 PM) (Source: DCOM) (EventID: 10010) (User: Family-HP) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. Error: (01/18/2017 07:25:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (01/18/2017 07:17:44 PM) (Source: DCOM) (EventID: 10010) (User: Family-HP) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. Error: (01/18/2017 07:15:44 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (01/18/2017 07:15:26 PM) (Source: DCOM) (EventID: 10016) (User: Family-HP) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user Family-HP\Family SID (S-1-5-21-3193119406-1769082486-1526078369-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/18/2017 07:14:32 PM) (Source: DCOM) (EventID: 10016) (User: Family-HP) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user Family-HP\Family SID (S-1-5-21-3193119406-1769082486-1526078369-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/18/2017 07:12:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/18/2017 07:10:30 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error CodeIntegrity: =================================== Date: 2017-01-13 16:51:27.490 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 16:42:19.318 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 16:42:19.301 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:35.642 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:35.639 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:35.633 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:35.121 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:35.117 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:35.110 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 15:46:34.516 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: AMD Athlon(tm) II X4 640 Processor Percentage of memory in use: 31% Total physical RAM: 10239.28 MB Available physical RAM: 6975.75 MB Total Virtual: 10879.28 MB Available Virtual: 7465.58 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.71 GB) (Free:629.44 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:13.26 GB) (Free:1.58 GB) NTFS ==>[system with boot components (obtained from drive)] Drive j: (My Book) (Fixed) (Total:1862.98 GB) (Free:911.81 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 516E49C1) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) Partition 4: (Not Active) - (Size=13.3 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 00064002) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================