Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-02-2017 Ran by [removed] (19-02-2017 20:07:04) Running from C:\Users\[removed]\Desktop\Registry Repair Spora Windows 7 Professional Service Pack 1 (X64) (2011-06-03 14:31:38) Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1307699844-331912778-3280394059-500 - Administrator - Enabled) => C:\Users\Administrator.jwilson-PC Guest (S-1-5-21-1307699844-331912778-3280394059-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-1307699844-331912778-3280394059-1010 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Symantec Endpoint Protection.cloud (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189} AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Spybot - Search and Destroy (Enabled - Up to date) {A16C3F68-9280-E053-1818-342707FECF4D} AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} AS: Symantec Endpoint Protection.cloud (Disabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Symantec Endpoint Protection.cloud (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 2013 National Building Cost Estimator (HKLM-x32\...\{008468E1-EEAD-4BE2-B140-18CB319ADCC4}) (Version: 1.02.0000 - Craftsman Book Company) a la mode Vault (HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\InstallShield_{BF36BCF3-FA5C-402B-AA20-3909B813142A}) (Version: 3.30 - a la mode, inc.) a la mode Vault (x32 Version: 3.30 - a la mode, inc.) Hidden ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.0.503.216 - ABBYY) ABBYY FineReader 9.0 Sprint (x32 Version: 9.00.216.58250 - ABBYY) Hidden AccelerometerP11 (HKLM-x32\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 2.00.11.17 - STMicroelectronics) Adobe Acrobat 9 Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}) (Version: 9.3.0 - Adobe Systems) Adobe Acrobat 9.3.0 - CPSID_52073 (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}_930) (Version: - Adobe Systems Incorporated) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.) Adobe Creative Suite 5 Web Premium (HKLM-x32\...\{CDC08463-9303-4BF1-BF8C-E1A2ECEE3248}) (Version: 5.0 - Adobe Systems Incorporated) Adobe Flash Player 10 ActiveX (HKLM-x32\...\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}) (Version: 10.1.52.14 - Adobe Systems, Inc.) Adobe Flash Player 10 Plugin (HKLM-x32\...\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}) (Version: 10.1.52.14 - Adobe Systems, Inc.) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.108 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.108 - Adobe Systems Incorporated) Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Apple Application Support (64-bit) (HKLM\...\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Appraiser Genie Cloud version 1.0 (HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\{B9E7126C-A1CD-442C-8807-C6EBD39AFB1C}_is1) (Version: 1.0 - Appraiser Genie, LLC) Avaya one-X® Communicator (HKLM-x32\...\{32FCAA01-AA2A-4412-9F68-8DFB641006C0}) (Version: 6.1.100 - Avaya) AVG (HKLM\...\AvgZen) (Version: 1.151.2.59606 - AVG Technologies) AVG Protection (HKLM-x32\...\AVG Antivirus) (Version: 17.1.3006 - AVG Technologies) AVG Zen (Version: 1.151.26 - AVG Technologies) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform) Citrix Online Launcher (HKLM-x32\...\{48947098-A67C-46D4-90C5-9F2F6F0F96FE}) (Version: 1.0.449 - Citrix) Configuration Manager Client (Version: 5.00.7958.1000 - Microsoft Corporation) Hidden Craftsman Software Update (HKLM-x32\...\{ED9686AC-D463-4511-8A1E-C5811B410B2D}) (Version: 3.03.0000 - Craftsman Book Company) CutePDF Writer 3.1 (HKLM\...\CutePDF Writer Installation) (Version: 3.1 - Acro Software Inc.) CyberLink PowerDVD 9.5 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.5.1.3225 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery Manager (HKLM\...\{975DFE7C-8E56-45BC-A329-401E6B1F8102}) (Version: 1.3 - Dell Inc.) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.0.5621.01 - Dell Inc.) Dell Support Center (Version: 3.0.5621.01 - PC-Doctor, Inc.) Hidden Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1207.101.218 - ALPS ELECTRIC CO., LTD.) Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.35 - Creative Technology Ltd) DigitalPersona Fingerprint Software 5.20 (HKLM\...\{C0C2D40A-1231-46FA-8F02-B45E6BF2036A}) (Version: 5.20.230 - DigitalPersona, Inc.) DIRECTV Player (HKLM-x32\...\{4a5ad61d-1fe9-48b9-87a8-9235f71120f3}) (Version: 12.1 - DIRECTV) DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden Download Navigator (HKLM-x32\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION) Download Updater (AOL Inc.) (HKLM-x32\...\SoftwareUpdUtility) (Version: - AOL Inc.) <==== ATTENTION Dream Aquarium (HKLM-x32\...\DreamAqua) (Version: - ) DriverUpdate (HKLM-x32\...\{B2B04F8B-6444-4364-89C8-F3088D4E8D02}) (Version: 2.2.43335 - SlimWare Utilities, Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 19.4.13 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden EPSON Connect version 1.0 (HKLM-x32\...\EPSON Connect_is1) (Version: 1.0 - Epson America Inc.) Epson Customer Participation (HKLM\...\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.4.0.0 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM-x32\...\{44F72193-F59C-4303-BAE8-E3E4BC1C122C}) (Version: 3.01.0003 - Seiko Epson Corporation) Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.30.00 - SEIKO EPSON CORPORATION) Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON WF-2530 Series Printer Uninstall (HKLM\...\EPSON WF-2530 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION) FMW 1 (Version: 1.162.3 - AVG Technologies) Hidden Global VPN Client (HKLM\...\{88C972E7-D7FC-40F3-9FE5-180957F37B45}) (Version: 4.9.0 - Dell SonicWALL) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden GoToMeeting 8.0.0.6441 (HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\GoToMeeting) (Version: 8.0.0.6441 - CitrixOnline) iCloud (HKLM\...\{4BB313CE-D3D1-424C-8823-15CF85B00B05}) (Version: 6.1.0.30 - Apple Inc.) ICQ7.5 (HKLM-x32\...\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}) (Version: 7.5 - ICQ) Infinite HD™ App (HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\Octoshape Streaming Services) (Version: - Octoshape ApS) InstallVC90Support (x32 Version: 1.01.0000 - Novatel Wireless) Hidden Intel Security True Key (HKLM\...\TrueKey) (Version: 4.3.145.1 - Intel Security) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2253 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{5A80B0BA-79AF-4B11-B851-CCB9F7977AC0}) (Version: 1.0.1.0489 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel(R) Wireless Display (HKLM-x32\...\{F84906ED-BB54-4889-B131-FED9C9056FC8}) (Version: 2.0.27.0 - Intel Corporation) Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) join.me (HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\JoinMe) (Version: 3.1.0.4343 - LogMeIn, Inc.) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) MANDIANT Intelligent Response Agent (HKLM-x32\...\{8A594DE0-1674-4A6A-AF33-BCD131524123}) (Version: 2.3.3100 - MANDIANT) McAfee SiteAdvisor Enterprise Plus (x32 Version: 3.0.0.638 - McAfee, Inc.) Hidden Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft IntelliPoint 8.1 (HKLM\...\Microsoft IntelliPoint 8.1) (Version: 8.15.406.0 - Microsoft) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation) Mileage Estimator (HKLM-x32\...\{9EA518AA-3B30-4CE5-8E93-77BA715E8917}) (Version: 1.00.0036 - a la mode, inc.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NVIDIA 3D Vision Driver 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation) NVIDIA GeForce Experience 2.11.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.4.0 - NVIDIA Corporation) NVIDIA Graphics Driver 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden PhotoShowExpress (x32 Version: 2.0.028 - Sonic Solutions) Hidden Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.0.10 - Dell Inc.) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden RegCure Pro (HKLM-x32\...\{C547F361-5750-4CD1-9FB6-BC93827CB6C1}) (Version: 3.3.22.0 - ParetoLogic, Inc.) <==== ATTENTION Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.40.0 - Roxio) Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.) SecureDoc Privacy Protection (HKLM-x32\...\SecureDoc Privacy Protection) (Version: 8.6 - KangoExtensions) <==== ATTENTION SereneScreen Marine Aquarium 3 (HKLM-x32\...\SereneScreen Marine Aquarium 3_is1) (Version: 3.3 - Prolific Publishing, Inc.) ShadowExplorer 0.9 (HKLM-x32\...\ShadowExplorer_is1) (Version: 0.9.462.0 - ShadowExplorer.com) SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.11.4.0 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.4 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.4.102 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16052.2 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16052.2 - Samsung Electronics Co., Ltd.) Hidden Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Symantec Endpoint Protection.cloud (x32 Version: 22.5.4.24 - Symantec Corporation) Hidden Symantec.cloud - Cloud Agent (Version: 3.00.10.2737 - Symantec Corporation) Hidden Symantec.cloud - Endpoint Protection (Version: 5.10.11.690 - Symantec Corporation) Hidden Symantec.cloud (HKLM\...\Symantec Hosted Services ARP) (Version: 3.00.10.2737 - Symantec Corporation) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer) TOTAL (HKLM-x32\...\InstallShield_{07BC20F3-F40F-4BFD-9005-7FB5605C9538}) (Version: 6.100.0140 - a la mode, inc.) TOTAL (x32 Version: 6.100.0140 - a la mode, inc.) Hidden TOTAL Connect (HKLM-x32\...\{ED2432D3-1214-4F30-9DAB-5BC767143A31}) (Version: 3.00.0023 - a la mode, inc.) TOTAL Mobile Sync (HKLM-x32\...\{9A676B2C-0705-464D-97A3-6EA1A8DC9504}) (Version: 1.00.0088 - a la mode, inc.) TOTAL Sketch (HKLM-x32\...\{B156E9B8-A6E8-4A08-9E85-82831DAE4BD5}) (Version: 1.00.0053 - a la mode, inc.) Validity Sensors DDK (HKLM\...\{10AAF056-7792-497A-ACAF-3BF002196574}) (Version: 4.3.33.0 - Validity Sensors, Inc.) Vault Files Downloader (HKLM-x32\...\{2EC5B55F-5458-43D3-BCFA-E14957082B89}) (Version: 1.00.0007 - a la mode, inc.) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Resource Kit Tools - SubInAcl.exe (HKLM-x32\...\{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}) (Version: 5.2.3790.1164 - Microsoft Corporation) Xobni Core (x32 Version: 1.0.0 - Xobni, Inc.) Hidden Ziften 4.2 (HKLM-x32\...\{1434173C-0B4B-4F05-91C4-2CD78EE49F03}) (Version: 4.2.0.1 - Ziften Technologies, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1307699844-331912778-3280394059-500_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Administrator.jwilson-PC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll () CustomCLSID: HKU\S-1-5-21-1307699844-331912778-3280394059-500_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\6140\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02CAF6E4-09B9-4052-8D0B-05E97220C608} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-03-31] (McAfee, Inc.) Task: {05C26526-37F9-4174-9650-FA36EC34B4C7} - System32\Tasks\{F16CD415-77CE-4F78-9C15-F9658BA06946} => C:\Users\jwilson\AppData\Local\AOL\AIM\aim.exe Task: {12E27DA5-0A78-4BA5-8652-E79757AAA67D} - System32\Tasks\G2MUpdateTask-S-1-5-21-1307699844-331912778-3280394059-500 => C:\Program Files (x86)\Citrix\GoToMeeting\6441\g2mupdate.exe [2017-02-18] (Citrix Online, a division of Citrix Systems, Inc.) Task: {19EC3E77-4EA3-400F-8D2B-E92200501D32} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-07-01] (Dropbox, Inc.) Task: {24D7F821-2986-46F7-AC86-92EAFA81D5E0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-28] (Microsoft Corporation) Task: {2524BB74-1557-4E99-9CCB-DC27BA7646A6} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {2B859273-91F6-41E5-A4DA-20E3286B6246} - System32\Tasks\{42B592DC-0A48-44DE-9B4D-6CB771EB1D1B} => C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE Task: {2D37B091-70EB-4B43-960F-82F2C66D5DBB} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-07-01] (Dropbox, Inc.) Task: {2D6A3D73-E15A-4861-8307-386DB607002F} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {316C5E71-EB60-4ABC-A21B-DBACC768D463} - System32\Tasks\Norton WSC Integration => C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\WSCStub.exe [2015-09-23] (Symantec Corporation) Task: {31C81B40-0052-4864-BE9C-265FFDA1457D} - System32\Tasks\Microsoft\Configuration Manager\Configuration Manager Health Evaluation => C:\Windows\CCM\ccmeval.exe [2013-09-11] (Microsoft Corporation) Task: {323BA262-7FD8-4A9B-B132-F7E40F268724} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-07] (Adobe Systems Incorporated) Task: {33B73949-EDE8-4F89-ABDC-C3CFD7DAE525} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {3C280DC3-34EA-4186-B745-CEA425448890} - System32\Tasks\a la mode Vault Backup => C:\Program Files (x86)\a la mode\Vault\eVault.exe [2009-06-09] (a la mode, inc.) Task: {437FB839-0E86-4751-AD00-6405F6917591} - System32\Tasks\AdobeAAMUpdater-1.0-IAM-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {43F23581-9B40-4876-9F16-03507CB8B38B} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-04-13] (Microsoft Corporation) Task: {50DCF78A-A729-45E7-A3A7-76CF4E6CFA21} - System32\Tasks\Endpoint Protection.cloud\Norton Error Processor => C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\SymErr.exe [2015-09-08] (Symantec Corporation) Task: {598CEE2D-E37B-420C-8E8A-268BF41D92FE} - System32\Tasks\{E0674841-2CE4-4416-899C-E186F6B6E116} => C:\Program Files (x86)\Trillian\trillian.exe Task: {61A7ECC8-7261-4499-8698-0E31FB5A2CA1} - System32\Tasks\{C00B4797-C71F-4844-9AC4-755680FE2BA7} => pcalua.exe -a "C:\Program Files (x86)\Mp3Tube Toolbar\uninstall.exe" -c bho /S Task: {643A676F-D1BD-4F78-8158-A8CF7517B691} - System32\Tasks\{B6E796DE-CFE7-4039-8836-6D277D1C67AF} => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe Task: {68A80416-80F8-4ACB-82C7-D325C0A789BF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {6970C88A-367B-4151-B5F9-87CC257ECDA5} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation) Task: {6BF61836-CAC9-445C-80F1-8480B3FD5E17} - System32\Tasks\SoftUpdateLogon => C:\Users\jlwilson2.US\AppData\Local\SoftUpdate\SoftUpdate.exe Task: {705D4838-FB38-489B-B3A9-A54F4EE2476A} - System32\Tasks\At2 => \\ent-mocsmsccm01\ConfigMgr07SP2\SMSSETUP\CLIENT\ccmsetup.exe <==== ATTENTION Task: {79C70CAA-7140-436E-B849-A4A2B69D1691} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-02-13] (AVG Technologies CZ, s.r.o.) Task: {89F9C5D2-E6F9-48E0-8AD2-A50EB07659BA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.) Task: {8CE2C97A-F308-43C4-B741-E36CA1DC6117} - System32\Tasks\{5D076A2C-C56C-4639-8ACD-5B4448915057} => C:\Users\jlwilson2\GoToAssistDownloadHelper.exe [2011-06-28] () Task: {8EB7AC92-14F0-4ED3-AFBE-AE2A7ED1A1D7} - System32\Tasks\{52540A96-B54B-4DC0-9D44-575B2F831C53} => C:\Program Files (x86)\Trillian\trillian.exe Task: {9CE32093-7607-489A-9F25-6159E0704582} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation) Task: {9EA01FA8-6FD7-463C-9779-2F6068DA3023} - System32\Tasks\{969F5D0A-4A78-4558-BEA7-49108E9FF398} => pcalua.exe -a D:\setup.exe -d D:\ Task: {A7D9E424-8F09-4CD6-A034-5C4431BE36B1} - System32\Tasks\{2E80B247-057E-4447-86C9-36F97952FC5E} => C:\Users\jwilson\AppData\Local\AOL\AIM\aim.exe Task: {A7E48415-5139-47C3-B632-4DE816F7EAAF} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-957578113-1565271767-774919444-5761844 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {B0AAF08F-B1FF-4A67-8912-55FF1C4DA5A6} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2016-11-17] (Apple Inc.) Task: {B0E92450-21E3-4EA7-A26B-14C2B9122DA4} - System32\Tasks\At1 => \\ent-mocsmsccm01\ConfigMgr07SP2\SMSSETUP\CLIENT\ccmsetup.exe <==== ATTENTION Task: {B948B706-3C27-4D5B-951A-007F86258130} - System32\Tasks\{72A3CF32-0537-4154-BE74-4CE4E76732AE} => pcalua.exe -a C:\Users\jlwilson2.US\Desktop\setup.exe -d C:\Users\jlwilson2.US\Desktop Task: {BE11F9EA-9D91-4707-A37E-1BF9BB7B8987} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.) Task: {C25A2ED3-39EB-48CD-B2A0-16477BD51BB0} - System32\Tasks\{37EC10D8-C9C8-4139-840A-DF3A3B3AD630} => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe Task: {C2878995-5D6A-4610-8F2E-39A1BF9585C0} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-12-28] (Microsoft Corporation) Task: {C90FF1D4-F587-4CC6-92D8-CE314296FCAE} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {C9A9BCE9-4A38-4311-9351-70EA69BE2521} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2010-08-05] () Task: {CDD1A30F-D03B-494E-A62B-75AB3043C34D} - System32\Tasks\Endpoint Protection.cloud\Norton Error Analyzer => C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\SymErr.exe [2015-09-08] (Symantec Corporation) Task: {D16AE1A2-E720-4E54-8209-90B43FD5BA89} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {D45F99F4-CF97-4CBB-8B94-4E54BAB6C23D} - System32\Tasks\SoftUpdateDaily => C:\Users\jlwilson2.US\AppData\Local\SoftUpdate\SoftUpdate.exe Task: {D597B6C9-7F90-473A-81BA-52361F70596F} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-957578113-1565271767-774919444-5761844 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {DE83C49F-801E-4DFA-84DB-E13A278FB776} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-28] (Microsoft Corporation) Task: {E766A147-31EC-4674-8E20-67E436946BC0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-07] (Google Inc.) Task: {E77EC843-93CB-42AF-B2A7-DC2D0968A785} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-07] (Google Inc.) Task: {EAEFFD3B-A593-4852-BC1C-E86164DAE23B} - System32\Tasks\Microsoft\Configuration Manager\Configuration Manager Idle Detection Task: {EEA44902-383D-4D89-A355-AF800C0C3B8C} - System32\Tasks\G2MUploadTask-S-1-5-21-1307699844-331912778-3280394059-500 => C:\Program Files (x86)\Citrix\GoToMeeting\6441\g2mupload.exe [2017-02-18] (Citrix Online, a division of Citrix Systems, Inc.) Task: {EFFD4FCA-E92A-40C4-B2BC-8CD77756ABBF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\At1.job => \\ent mocsmsccm01 ConfigMgr07SP2 SMSSETUP CLIENT ccmsetup exe /service SMSSITECODE AUTO SYSTEM Created by NetScheduleJobAdd Task: C:\Windows\Tasks\At2.job => \\ent mocsmsccm01 ConfigMgr07SP2 SMSSETUP CLIENT ccmsetup exe /service SMSSITECODE AUTO SYSTEM Created by NetScheduleJobAdd Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1307699844-331912778-3280394059-500.job => C:\Program Files (x86)\Citrix\GoToMeeting\6441\g2mupdate.exe Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1307699844-331912778-3280394059-500.job => C:\Program Files (x86)\Citrix\GoToMeeting\6441\g2mupload.exe Task: C:\Windows\Tasks\RegCure Pro Startup.job => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegCure Pro Update.job => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegCure Pro_sch_71174A8D-F610-11E6-85DA-14FEB5A1C695.job => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe <==== ATTENTION ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" ==================== Loaded Modules (Whitelisted) ============== 2017-02-17 12:02 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-02-17 12:02 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2016-10-21 23:21 - 2016-10-21 23:21 - 00959168 _____ () C:\Users\Administrator.jwilson-PC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-10-21 23:00 - 2016-12-28 11:03 - 08924864 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2" e" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DpHost => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sndappv2 => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\alamode.com -> alamode.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\almsr.com -> almsr.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\appraiserxsites.com -> appraiserxsites.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\bing.com -> bing.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\certmail.com -> certmail.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\interflood.com -> interflood.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\sharepoint.com -> hxxps://studentsblackhawk-files.sharepoint.com IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\virtualearth.net -> virtualearth.net IE trusted site: HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\xsitesnetwork.com -> xsitesnetwork.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 20:34 - 2017-02-02 11:06 - 00000965 ____N C:\Windows\system32\Drivers\etc\hosts 10.124.7.194 devoiaaa.schedulestar.com 209.97.51.214 qa.ical.schedulestar.com 209.97.51.199 stage.ical.schedulestar.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1307699844-331912778-3280394059-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{D3539683-16C6-4304-91BB-D4FB65FC13B3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{B7846724-CDAC-4BB4-903B-6044F0270334}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{5620D84D-9175-405D-924B-C8ADF54082BA}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe FirewallRules: [{32B0B135-5DD0-4F99-A110-F363A3589087}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{4E40D2AD-DF8F-482B-B363-5B893A49894D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe FirewallRules: [{B2EF8F84-4380-42DE-8134-C7BB6F533F8C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9.EXE FirewallRules: [{98E0CCAB-D04A-4DF3-B408-CE08A14D8932}] => (Allow) C:\Program Files (x86)\ICQ7.5\ICQ.exe FirewallRules: [{49B4EA33-14F7-4DAB-8F5B-660D13365C44}] => (Allow) C:\Program Files (x86)\ICQ7.5\ICQ.exe FirewallRules: [{3C8ED61C-4807-4219-AD15-664E5B740E8F}] => (Allow) C:\Program Files (x86)\ICQ7.5\ICQ.exe FirewallRules: [{7CA83D30-78E9-4F4A-8B30-1A3C46581F7B}] => (Allow) C:\Program Files (x86)\ICQ7.5\ICQ.exe FirewallRules: [{0DE4DB4E-65F2-433B-AFF0-0B6E98F7C11C}] => (Allow) C:\Program Files (x86)\ICQ7.5\ICQ.exe FirewallRules: [{74D4A954-AD13-4706-9963-98D683DF92FC}] => (Allow) C:\Program Files (x86)\ICQ7.5\ICQ.exe FirewallRules: [TCP Query User{1D7412E4-719F-4E12-A9C1-171D2E6AD8F7}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [UDP Query User{3AEB191C-E6C7-4DFF-BA5E-C201A3454EAA}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [{E07CF685-6512-405A-B806-4C0BCC5CD235}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{3E4E8A38-B3FD-4DAC-A869-D0DFB89D8ABD}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{BBD01ED3-0313-4D12-8547-C910912CBF65}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{335B58EA-7CA4-41D5-B1C6-FE2A110101C1}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{4EFB7370-41B2-46D1-A811-6EC7E1B543D6}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{CD4426E4-5C75-4287-8F64-B724148BBA22}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{D299203F-1C57-4FA7-8F34-71DAB47AA723}] => (Allow) C:\Windows\System32\dldtcoms.exe FirewallRules: [{50719E72-FD88-4F34-BAAF-D45D839EAD07}] => (Allow) C:\Windows\System32\dldtcoms.exe FirewallRules: [TCP Query User{92A88295-EAB1-4953-BBCB-79C04CCBEC80}C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe] => (Block) C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe FirewallRules: [UDP Query User{8BA3C73D-B1FA-4B4A-9EC6-D25CD423D827}C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe] => (Block) C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe FirewallRules: [{349C625D-1AB3-4F2B-883D-48C894135B3F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{336A300A-005B-48A2-9797-872C12925C17}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A6F7725A-9490-4991-B253-B47FABF33E25}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{5DA74C32-4D06-4FD0-8ACD-B79E09C1E5BC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{A9ECD2FD-F40F-4B59-9A5F-0038BF09B2C0}C:\program files (x86)\trillian\trillian.exe] => (Block) C:\program files (x86)\trillian\trillian.exe FirewallRules: [UDP Query User{49CF5BB3-47F4-4A3E-965D-8827A8CAB8A5}C:\program files (x86)\trillian\trillian.exe] => (Block) C:\program files (x86)\trillian\trillian.exe FirewallRules: [{2D68AEC2-9F90-45F9-B3B5-DFCB3D449432}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{50047BC8-A590-4260-A658-72D8CCC1DF49}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{11B3276E-C702-4113-92FD-D47A9BFA4919}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\MfeServiceMgr.exe FirewallRules: [{7F5C1709-4548-4D6C-A17E-B077C50D815D}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\MfeServiceMgr.exe FirewallRules: [{F89AC33C-16AC-468F-96BB-2A121606C935}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\MfeServiceMgr.exe FirewallRules: [{BAF57C03-D963-4BA2-B89E-9B23873FF5D5}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\MfeServiceMgr.exe FirewallRules: [{1E6067C6-3A0E-4A5D-91E6-1E278ADE5A02}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\MfeServiceMgr.exe FirewallRules: [{2511D238-D5DF-402A-8EDB-8E642E42A7CE}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\MfeServiceMgr.exe FirewallRules: [{B3D01603-8C3F-4A86-9C94-A2D3285ACD05}] => (Allow) C:\Program Files (x86)\Products\MIRAgent\MIRAgent.exe FirewallRules: [TCP Query User{299E5CF2-0FC7-4BFC-9F87-62A150F4045F}C:\program files (x86)\avaya\avaya one-x communicator\onexcengine.exe] => (Allow) C:\program files (x86)\avaya\avaya one-x communicator\onexcengine.exe FirewallRules: [UDP Query User{78B29D68-F69E-42D0-9F41-E37FC4EDF3EC}C:\program files (x86)\avaya\avaya one-x communicator\onexcengine.exe] => (Allow) C:\program files (x86)\avaya\avaya one-x communicator\onexcengine.exe FirewallRules: [{2863F0E9-D58B-4EB5-87DD-988F8385CDCF}] => (Allow) C:\Windows\CCM\RemCtrl\CmRcService.exe FirewallRules: [{142D56DF-F035-4D29-A406-B253F4188FE5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{CE5FB38D-09A1-4BB0-B385-F0DEA6DB8780}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{463C05C6-13AC-4A64-83A1-7BA7CFB3D56A}] => (Allow) C:\Users\jwilson\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{1949518F-32E7-43CB-8A2F-1FA9CEE6713F}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{D2A5FC89-1B2D-4744-858E-7D3A0C1FB739}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe FirewallRules: [{4E034FE4-08E2-4929-B85F-90DB23120CFB}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe FirewallRules: [{C64FF2FF-4A28-4757-B93C-A75B5FB86501}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{12669B2D-B289-4C49-B913-1F863A1001AF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{2268329B-3F7F-47CA-8438-4C8590A2D1CF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{22BAE0A2-8E7D-4228-99C2-ECB47F24BF65}] => (Allow) C:\Program Files (x86)\a la mode\Sched\eSched.exe FirewallRules: [{16137275-3576-47F9-B59D-E663E922616C}] => (Allow) C:\Program Files (x86)\a la mode\Sched\eSched.exe FirewallRules: [TCP Query User{B4CC0734-515A-4537-AB82-19BC41C4DAD7}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{E4F8FEC4-D75A-4CAB-B9F0-7F1233463944}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{79CCD97F-9B72-4337-8721-DEBD7E99814D}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{741AB434-4244-4894-B42E-18D5DDF5DE38}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{90879364-F75F-4BC2-9E74-C3AE0338488F}C:\program files (x86)\a la mode\sched\esched.exe] => (Allow) C:\program files (x86)\a la mode\sched\esched.exe FirewallRules: [UDP Query User{D60770E3-1619-4330-971B-DB327D4283F8}C:\program files (x86)\a la mode\sched\esched.exe] => (Allow) C:\program files (x86)\a la mode\sched\esched.exe FirewallRules: [{3F1C71EB-35C8-4ED6-8456-2E6DE32C6BD5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{D6184808-58A5-428A-9606-9E55CFBCCB9E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{079750EB-FA93-4E90-856E-E39A1F27846C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{9DCA394F-D3F5-458E-A76E-6088DBF4C5F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{7A2C34ED-ECFE-4060-B8EB-2BA5114CA129}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{6B934664-0843-4B7B-AD49-7A023C1A0795}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{339C40DB-E2E2-4485-9899-F46F17CF83C0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6C04E1F6-7AF5-4C92-9FC4-A4F901CB63A9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{1D2C0E79-6E6E-45E3-BC61-4BE3D3A31C7F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{6A8E15DC-6831-436D-A2DE-F908F1D3F870}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{6BAA396F-571E-43E0-A600-84E7EF12A0D8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{949D3244-6E75-428E-BC6D-FABF680EF736}C:\program files (x86)\a la mode\vault\vault.exe] => (Allow) C:\program files (x86)\a la mode\vault\vault.exe FirewallRules: [UDP Query User{2083464D-F0AF-4E14-8A78-699FAC537F23}C:\program files (x86)\a la mode\vault\vault.exe] => (Allow) C:\program files (x86)\a la mode\vault\vault.exe FirewallRules: [{AAC06EFB-BD15-44B0-9B38-F36C99A3D261}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{456C4B31-E777-4E79-9C1C-0BD9D96A4A97}] => (Allow) LPort=2869 FirewallRules: [{34EFB60B-0009-4547-9E41-0A976BB8547B}] => (Allow) LPort=1900 FirewallRules: [{A107D453-3302-4EBC-A6C4-96F4443BBD70}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [TCP Query User{3FF81733-0402-4170-890B-23E145901D6F}C:\program files (x86)\a la mode\vault\vault.exe] => (Allow) C:\program files (x86)\a la mode\vault\vault.exe FirewallRules: [UDP Query User{0BD43CF8-A81F-4E83-9273-576C37963F66}C:\program files (x86)\a la mode\vault\vault.exe] => (Allow) C:\program files (x86)\a la mode\vault\vault.exe FirewallRules: [{BE36EA38-7DD1-467B-B167-FECC12120443}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{7C8B6C84-BDB5-40C8-9D83-96D317654ED5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{C9766FE7-D9A5-463C-876E-D4DE36177E19}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{5D6D64D7-2617-4532-AD6E-0FB232BF7979}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Restore Points ========================= 17-02-2017 22:05:05 AA11 18-02-2017 14:00:47 Windows Update ==================== Faulty Device Manager Devices ============= Name: avgVmm Description: avgVmm Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: avgVmm Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Security Processor Loader Driver Description: Security Processor Loader Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: spldr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: SonicWALL Virtual NIC Description: SonicWALL Virtual NIC Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: SonicWALL Service: SWVNIC Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: avgRvrt Description: avgRvrt Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: avgRvrt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: wStLibG64 Description: wStLibG64 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: wStLibG64 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (02/19/2017 07:34:19 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) The system cannot find the file specified. Error: (02/19/2017 07:25:58 PM) (Source: TrueKey) (EventID: 0) (User: ) Description: Failed to process session change. System.ArgumentNullException: Value cannot be null. at System.Threading.Monitor.Enter(Object obj) at McAfee.YAP.Service.Common.UsersManager.GetWindowsUsers(Boolean async) at McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription) at System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId) Error: (02/19/2017 07:17:03 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (02/19/2017 07:17:03 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (02/19/2017 07:16:58 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat 9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (02/19/2017 07:16:57 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat 9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (02/19/2017 07:13:00 PM) (Source: VSTO 4.0) (EventID: 4096) (User: ) Description: Customization URI: file:///C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/PipelineSegments.store Exception: Exception reading manifest from file:///C:/Program%20Files%20(x86)/Common%20Files/Microsoft%20Shared/VSTA/Pipeline.v10.0/PipelineSegments.store: the manifest may not be valid or the file could not be opened. ************** Exception Text ************** System.Deployment.Application.InvalidDeploymentException: Exception reading manifest from file:///C:/Program%20Files%20(x86)/Common%20Files/Microsoft%20Shared/VSTA/Pipeline.v10.0/PipelineSegments.store: the manifest may not be valid or the file could not be opened. ---> System.Xml.XmlException: '', hexadecimal value 0x01, is an invalid character. Line 1, position 1. at System.Xml.XmlTextReaderImpl.Throw(Exception e) at System.Xml.XmlTextReaderImpl.Throw(String res, String[] args) at System.Xml.XmlTextReaderImpl.Throw(Int32 pos, String res, String[] args) at System.Xml.XmlTextReaderImpl.ThrowInvalidChar(Int32 pos, Char invChar) at System.Xml.XmlTextReaderImpl.ParseRootLevelWhitespace() at System.Xml.XmlTextReaderImpl.ParseDocumentContent() at System.Xml.XmlTextReaderImpl.Read() at System.Xml.XmlTextReader.Read() at System.Deployment.Application.ManifestValidatingReader.XmlFilteredReader.Read() at System.Xml.XsdValidatingReader.Read() at System.Deployment.Application.ManifestReader.FromDocument(String localPath, ManifestType manifestType, Uri sourceUri) --- End of inner exception stack trace --- at Microsoft.VisualStudio.Tools.Applications.Deployment.ClickOnceAddInDeploymentManager.GetManifests(TimeSpan timeout) at Microsoft.VisualStudio.Tools.Applications.Deployment.ClickOnceAddInDeploymentManager.InstallAddIn() ************** Loaded Assemblies ************** mscorlib Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.5485 (Win7SP1GDR.050727-5400) CodeBase: file:///C:/Windows/Microsoft.NET/Framework/v2.0.50727/mscorlib.dll ---------------------------------------- Microsoft.VisualStudio.Tools.Office.Runtime.v10.0 Assembly Version: 10.0.0.0 Win32 Version: 10.0.60301.0 CodeBase: file:///C:/Windows/assembly/GAC_MSIL/Microsoft.VisualStudio.Tools.Office.Runtime.v10.0/10.0.0.0__b03f5f7f11d50a3a/Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll ---------------------------------------- System Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.8686 (QFE.050727-8600) CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System/2.0.0.0__b77a5c561934e089/System.dll ---------------------------------------- System.Core Assembly Version: 3.5.0.0 Win32 Version: 3.5.30729.5420 built by: Win7SP1 CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.Core/3.5.0.0__b77a5c561934e089/System.Core.dll ---------------------------------------- Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0 Assembly Version: 10.0.0.0 Win32 Version: 10.0.60301.0 CodeBase: file:///C:/Windows/assembly/GAC_MSIL/Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0/10.0.0.0__b03f5f7f11d50a3a/Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll ---------------------------------------- System.AddIn Assembly Version: 3.5.0.0 Win32 Version: 3.5.30729.5446 built by: Win7SP1GDR CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.AddIn/3.5.0.0__b77a5c561934e089/System.AddIn.dll ---------------------------------------- Microsoft.Office.Tools.Outlook.v9.0 Assembly Version: 9.0.0.0 Win32 Version: 9.0.30729.7079 CodeBase: file:///C:/Windows/assembly/GAC_MSIL/Microsoft.Office.Tools.Outlook.v9.0/9.0.0.0__b03f5f7f11d50a3a/Microsoft.Office.Tools.Outlook.v9.0.dll ---------------------------------------- Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0 Assembly Version: 10.0.0.0 Win32 Version: 10.0.60301.0 CodeBase: file:///C:/Windows/assembly/GAC_MSIL/Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0/10.0.0.0__b03f5f7f11d50a3a/Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll ---------------------------------------- System.Windows.Forms Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.5491 (Win7SP1GDR.050727-5400) CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.Windows.Forms/2.0.0.0__b77a5c561934e089/System.Windows.Forms.dll ---------------------------------------- System.Drawing Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.5495 (Win7SP1GDR.050727-5400) CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.Drawing/2.0.0.0__b03f5f7f11d50a3a/System.Drawing.dll ---------------------------------------- System.Deployment Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.5493 (Win7SP1GDR.050727-5400) CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.Deployment/2.0.0.0__b03f5f7f11d50a3a/System.Deployment.dll ---------------------------------------- System.Configuration Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.Configuration/2.0.0.0__b03f5f7f11d50a3a/System.Configuration.dll ---------------------------------------- System.Xml Assembly Version: 2.0.0.0 Win32 Version: 2.0.50727.5494 (Win7SP1GDR.050727-5400) CodeBase: file:///C:/Windows/assembly/GAC_MSIL/System.Xml/2.0.0.0__b77a5c561934e089/System.Xml.dll ---------------------------------------- Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0 Assembly Version: 10.0.0.0 Win32 Version: 10.0.60301.0 CodeBase: file:///C:/Windows/assembly/GAC_MSIL/Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0/10.0.0.0__b03f5f7f11d50a3a/Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll ---------------------------------------- Error: (02/19/2017 07:09:15 PM) (Source: Microsoft Office 16) (EventID: 2000) (User: ) Description: Microsoft Outlook: Accepted Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode. Do you want to start in safe mode?. Accepted Safe Mode action : Microsoft Outlook. Error: (02/19/2017 07:01:22 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) The system cannot find the file specified. Error: (02/18/2017 08:40:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: BitDefenderCom.exe, version: 2.0.1.0, time stamp: 0x584ee319 Faulting module name: ntdll.dll, version: 6.1.7601.23572, time stamp: 0x57fd0651 Exception code: 0xc0000005 Fault offset: 0x000000000002b9e3 Faulting process id: 0xadc Faulting application start time: 0x01d28a1fc0e5c18c Faulting application path: C:\Program Files\BDServices\BitDefenderCom.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: d61252bf-f64c-11e6-89ec-bc7737148a6f System errors: ============= Error: (02/19/2017 08:06:45 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:06:45 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:06:45 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:06:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:06:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:06:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:04:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:04:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:04:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (02/19/2017 08:03:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. CodeIntegrity: =================================== Date: 2015-03-18 07:26:44.910 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-03-18 07:26:44.629 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-03-18 07:13:30.714 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-03-18 07:13:30.449 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz Percentage of memory in use: 28% Total physical RAM: 4010.17 MB Available physical RAM: 2880.59 MB Total Virtual: 8018.53 MB Available Virtual: 6976.25 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:275.53 GB) (Free:100.65 GB) NTFS Drive f: () (Removable) (Total:29.53 GB) (Free:12.02 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 07F2837E) Partition 1: (Not Active) - (Size=102 MB) - (Type=DE) Partition 2: (Active) - (Size=22.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=275.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 29.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================