Additional scan result of Farbar Recovery Scan Tool (x86) Version: 06-05-2017 Ran by [removed] (06-05-2017 14:31:00) Running from C:\Users\[removed]\Downloads Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2009-12-02 02:58:31) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2802963544-327318797-2809920788-500 - Administrator - Disabled) Guest (S-1-5-21-2802963544-327318797-2809920788-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2802963544-327318797-2809920788-1002 - Limited - Enabled) Pat (S-1-5-21-2802963544-327318797-2809920788-1000 - Administrator - Enabled) => C:\Users\Pat ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version: 7.1.0 - DivX, Inc.) Adobe Flash Player 25 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated) AIM 7 (HKLM\...\AIM_7) (Version: - ) AOL Messaging Toolbar (HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\AOL Messaging Toolbar) (Version: - ) Apple Application Support (HKLM\...\{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}) (Version: 1.3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}) (Version: 2.6.0.32 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - ) AVG (HKLM\...\AvgZen) (Version: 1.181.3.3057 - AVG Technologies) AVG (Version: 1.181.4 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG Antivirus) (Version: 17.3.3011 - AVG Technologies) Bonjour (HKLM\...\{07287123-B8AC-41CE-8346-3D777245C35B}) (Version: 1.0.106 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform) Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.9.1 - DivX, Inc.) DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.1.0 - DivX, Inc.) DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.1.0 - DivX, Inc.) DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.2.0 - DivX, Inc.) DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) DivX Plus Media Foundation Components (HKLM\...\{DA703982C580418795BF4001AA9D7061}) (Version: 1.0.0 - DivX, Inc.) DivX Plus Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 2.0.0 - DivX,Inc.) DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.1.0.9 - DivX, Inc.) FMW 1 (Version: 1.192.3 - AVG Technologies) Hidden Google Chrome (HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.33.5 - Google Inc.) Hidden H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version: 1.1.0 - DivX, Inc.) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1883 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}) (Version: 9.0.2.25 - Apple Inc.) Java 8 Update 121 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Label@Once 1.0 (HKLM\...\{0D795777-9D60-4692-8386-F2B3F2B5E5BF}) (Version: 1.0 - Corel) Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Publisher 2002 (HKLM\...\{90190409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation) MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version: 1.0.1 - DivX, Inc.) Mozilla Firefox 53.0.2 (x86 en-US) (HKLM\...\Mozilla Firefox 53.0.2 (x86 en-US)) (Version: 53.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.2.6333 - Mozilla) MyToshiba (HKLM\...\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}) (Version: 2.2.0.3 - Toshiba) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden Quickbooks Financial Center (HKLM\...\{3B843B38-04B1-4CE6-8888-586273E0F289}) (Version: 2.02 - TOSHIBA Corporation) QuickTime (HKLM\...\{EB900AF8-CC61-4E15-871B-98D1EA3E8025}) (Version: 7.67.75.0 - Apple Inc.) Realtek 8136 8168 8169 Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0005 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5904 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30098 - Realtek Semiconductor Corp.) Realtek WLAN Driver (HKLM\...\{0FB630AB-7BD8-40AE-B223-60397D57C3C9}) (Version: 2.00.0006 - Realtek) Skype Launcher (HKLM\...\{DA84ECBF-4B79-47F2-B34C-95C38484C058}) (Version: 2.01 - TOSHIBA Corporation) Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.6.1 - Synaptics Incorporated) The Next Tetris (HKLM\...\The Next Tetris) (Version: - ) TomTom HOME 2.8.2.2264 (HKLM\...\TomTom HOME) (Version: 2.8.2.2264 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Toshiba Application and Driver Installer (HKLM\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.0.9 - Toshiba) TOSHIBA Assist (HKLM\...\{12B3A009-A080-4619-9A2A-C6DB151D8D67}) (Version: 2.01.11 - TOSHIBA) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.1 - TOSHIBA Corporation) TOSHIBA DVD PLAYER (HKLM\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 3.01.0.07-A - TOSHIBA Corporation) TOSHIBA Extended Tiles for Windows Mobility Center (HKLM\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: 1.01.00 - TOSHIBA Corporation) TOSHIBA Flash Cards Support Utility (HKLM\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.4C - TOSHIBA CORPORATION) TOSHIBA Hardware Setup (HKLM\...\InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}) (Version: 1.63.0.11C - TOSHIBA CORPORATION) TOSHIBA HDD/SSD Alert (HKLM\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.0.2 - TOSHIBA Corporation) Toshiba Online Backup (HKLM\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.2.0.35 - Toshiba) Toshiba Quality Application (HKLM\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.001.0000 - Toshiba) TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.2 - TOSHIBA Corporation) TOSHIBA Service Station (HKLM\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.9 - TOSHIBA) TOSHIBA Speech System Applications (HKLM\...\{EE033C1F-443E-41EC-A0E2-559B539A4E4D}) (Version: 1.00.2518 - ) TOSHIBA Speech System SR Engine(U.S.) Version1.0 (HKLM\...\{008D69EB-70FF-46AB-9C75-924620DF191A}) (Version: - ) TOSHIBA Speech System TTS Engine(U.S.) Version1.0 (HKLM\...\{3FBF6F99-8EC6-41B4-8527-0A32241B5496}) (Version: - ) TOSHIBA Supervisor Password (HKLM\...\InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}) (Version: 1.63.0.6C - TOSHIBA CORPORATION) TOSHIBA Value Added Package (HKLM\...\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}) (Version: 1.2.25 - TOSHIBA Corporation) ToshibaRegistration (HKLM\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.3 - Toshiba) Unity Web Player (HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Utility Common Driver (Version: 1.0.50.26C - TOSHIBA) Hidden VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden Verizon FiOS Activation (HKLM\...\Verizon FiOS Activation_is1) (Version: - Verizon) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) WildTangent Games (HKLM\...\WildTangent toshiba Master Uninstall) (Version: 1.0.0.71 - WildTangent) Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Sync (HKLM\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\ChromeHTML: -> C:\Users\Pat\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Pat\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Pat\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.30.3\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.31.5\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.29.5\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.3\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.32.7\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.29.1\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.28.15\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2802963544-327318797-2809920788-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Pat\AppData\Local\Google\Update\1.3.33.5\psuser.dll (Google Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {18CA42D3-BE8B-4AF5-B065-E3307BE8BDC8} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\windows\TEMP\{8C9CF896-6926-4B5E-8A52-FD1E85171147}.exe <==== ATTENTION Task: {1E2C6DB9-AC36-4F0A-8752-FBAB56EEFAFC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-03] (Piriform Ltd) Task: {279ECB57-C9E8-4F6E-956C-2492B9F40A0D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {29D4410B-A934-4BE0-8E10-855553879EBE} - System32\Tasks\AVG-SSU_0716wt => C:\ProgramData\Avg_Update_0716wt\AVG-Secure-Search-Update_0716wt.exe [2016-08-03] () Task: {2B575CEA-A2BB-446A-9D4F-E59E5F223DD9} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-11] (Adobe Systems Incorporated) Task: {31CC5D87-CC0A-4392-A606-0C62BF69F259} - System32\Tasks\Driver Robot => C:\Program Files\Driver Robot\1.2.0.5\DriverRobot.exe Task: {37E8E18A-EEFF-4DA2-B28B-F8728D37D608} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [2017-05-06] (AVG Technologies CZ, s.r.o.) Task: {49062B43-C713-4DD0-BB9E-85E64211C341} - System32\Tasks\AVG-SSU_0716wt_DELETE => C:\ProgramData\Avg_Update_0716wt\AVG-Secure-Search-Update_0716wt.exe [2016-08-03] () Task: {4EC2FA75-5E25-40B7-95FF-2C871E2091ED} - System32\Tasks\AVG-SSU_0217wt_DELETE => C:\ProgramData\Avg_Update_0217wt\AVG-Secure-Search-Update_0217wt.exe [2017-02-21] () Task: {54E5E881-7106-497F-A6B5-7FEB5FFBAABE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2802963544-327318797-2809920788-1000UA => C:\Users\Pat\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {613F6F32-3F9D-4FB0-9E70-A8AF2FA94D32} - System32\Tasks\AVG-SSU_0217wt => C:\ProgramData\Avg_Update_0217wt\AVG-Secure-Search-Update_0217wt.exe [2017-02-21] () Task: {75B3830F-FC89-4CF1-8BCE-69B4E82F150B} - System32\Tasks\Arcadesafari => C:\Users\Pat\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe [2014-09-01] (Arcadesafari) Task: {79E94765-CFC0-4B06-B4F8-84A5C404EBE9} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {7E1913B0-D786-4FCB-BFEE-1E2A1557B4E6} - System32\Tasks\{7BCCAF04-FBB2-4A30-99C2-F4A7411F0AF5} => pcalua.exe -a C:\Users\Pat\AppData\Local\Temp\jre-8u101-windows-au.exe -d C:\windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION Task: {97F0EBE4-BB8A-4FB6-8965-DA5B9DD45CA6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {98BA43C3-9E42-42B0-965B-76562E410C76} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\windows\TEMP\{B62AA672-92AA-419D-A788-DFC7A9FA25D8}.exe <==== ATTENTION Task: {C5EA0FB1-851C-4639-A840-97326A4B1B6F} - System32\Tasks\{37ED5F22-D0A3-48D8-8009-A7E938DCB575} => pcalua.exe -a "C:\Users\Pat\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAGP1RYZ\Firefox%20Setup%203.5.5[1].exe" -d C:\Users\Pat\Desktop Task: {E781DC52-B58A-4F74-9A9A-99125C2BE36F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2802963544-327318797-2809920788-1000Core => C:\Users\Pat\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {F222FDF7-3C36-4C6A-A09A-16D817298ADA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\windows\Tasks\Arcadesafari.job => C:\Users\Pat\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\windows\TEMP\{B62AA672-92AA-419D-A788-DFC7A9FA25D8}.exe <==== ATTENTION Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{8C9CF896-6926-4B5E-8A52-FD1E85171147}.exe <==== ATTENTION Task: C:\windows\Tasks\AVG-SSU_0217wt.job => C:\ProgramData\Avg_Update_0217wt\AVG-Secure-Search-Update_0217wt.exe Task: C:\windows\Tasks\AVG-SSU_0217wt_DELETE.job => C:\ProgramData\Avg_Update_0217wt\AVG-Secure-Search-Update_0217wt.exe Task: C:\windows\Tasks\AVG-SSU_0716wt.job => C:\ProgramData\Avg_Update_0716wt\AVG-Secure-Search-Update_0716wt.exe Task: C:\windows\Tasks\AVG-SSU_0716wt_DELETE.job => C:\ProgramData\Avg_Update_0716wt\AVG-Secure-Search-Update_0716wt.exe Task: C:\windows\Tasks\Driver Robot.job => C:\Program Files\Driver Robot\1.2.0.5\DriverRobot.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-08-03 17:37 - 2016-08-03 17:37 - 02048584 _____ () C:\ProgramData\Avg_Update_0716wt\AVG-Secure-Search-Update_0716wt.exe 2017-02-21 10:52 - 2017-02-21 10:52 - 02048584 _____ () C:\ProgramData\Avg_Update_0217wt\AVG-Secure-Search-Update_0217wt.exe 2009-09-17 16:36 - 2009-09-17 16:36 - 00079192 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll 2017-05-06 12:43 - 2017-05-06 12:41 - 48920064 _____ () C:\Program Files\AVG\UiDll\2623\libcef.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 00171208 _____ () C:\Program Files\AVG\Antivirus\JsonRpcServer.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 00177472 _____ () C:\Program Files\AVG\Antivirus\event_routing_rpc.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 00654504 _____ () C:\Program Files\AVG\Antivirus\ffl2.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 00231616 _____ () C:\Program Files\AVG\Antivirus\streamback.dll 2017-05-06 13:12 - 2017-05-06 13:12 - 05926912 _____ () C:\Program Files\AVG\Antivirus\defs\17050600\algo.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 48936448 _____ () C:\Program Files\AVG\Antivirus\libcef.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 00135912 _____ () c:\Program Files\AVG\Antivirus\vaarclient.dll 2017-05-06 12:59 - 2017-05-06 12:59 - 00231616 _____ () c:\Program Files\AVG\Antivirus\StreamBack.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:03DBFDCF [756] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com There are 7853 more sites. IE trusted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\intuit.com -> hxxps://ttlc.intuit.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-2802963544-327318797-2809920788-1000\...\123simsen.com -> www.123simsen.com There are 7853 more sites. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 22:04 - 2011-05-31 15:55 - 00434670 ____N C:\windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com 127.0.0.1 www.123moviedownload.com There are 14949 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2802963544-327318797-2809920788-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 75.75.75.75 - 75.75.76.76 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupfolder: C:^Users^Pat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup MSCONFIG\startupreg: DW7 => "C:\Program Files\The Weather Channel\The Weather Channel App\TWCApp.exe" MSCONFIG\startupreg: Google Update => C:\Users\Pat\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe MSCONFIG\startupreg: KeNotify => C:\Program Files\TOSHIBA\Utilities\KeNotify.exe MSCONFIG\startupreg: MyTOSHIBA => "C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe" /AUTO MSCONFIG\startupreg: NortonOnlineBackupReminder => "C:\Program Files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" UNATTENDED MSCONFIG\startupreg: SpybotSD TeaTimer => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: TPwrMain => %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{DFF706D9-C438-40ED-ADD4-9080E80E1CBA}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{24088567-8F2E-423E-894B-663093BA4A18}] => (Allow) svchost.exe FirewallRules: [{7DE6C59A-BDEA-4B44-BE38-281FEFA647A3}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{1D84A04A-1B66-4271-8FD1-9C132F1E42BA}] => (Allow) C:\Program Files\AIM\aim.exe FirewallRules: [{7ACDA37A-A82B-43BB-9171-12C613797560}] => (Allow) C:\Program Files\AIM\aim.exe FirewallRules: [{D07AB82E-F067-4E95-94FF-25F3CFBC961B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7C47F32F-7367-4D10-8BF4-276A976E5184}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{09B49939-0DD4-4A86-8774-1F330F12071D}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{C7477D89-DBFA-489A-AAA9-0D3CF0555924}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{E806951D-FCDA-4B26-93AF-AA0E89918765}] => (Allow) C:\Program Files\AIM\aim.exe FirewallRules: [{F21430A5-4427-40D7-BFB6-4E90A4B6EF49}] => (Allow) C:\Program Files\AIM\aim.exe FirewallRules: [{D9BF8417-CA01-4FAD-B26E-F9F1BF190179}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe FirewallRules: [{3F5AA44F-0458-4C33-B389-CCE4EC4A1D26}] => (Allow) LPort=2869 FirewallRules: [{C06E8FA3-30CF-468B-8FF8-376DB12AEFEF}] => (Allow) LPort=1900 FirewallRules: [{81EEA77E-EC7C-459D-AD02-7A1E9B9D3A1E}] => (Allow) C:\Program Files\Windows Live\Mesh\MOE.exe FirewallRules: [{90CA8C46-51EC-4237-9CA1-AB61DF2AA8E8}] => (Allow) C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{E2C5D4D9-89B0-4F27-A725-DB9E8C5F7015}] => (Allow) C:\Program Files\AVG\AVG2015\avgmfapx.exe FirewallRules: [{94EFC6F0-55CA-42FB-BEB4-4866704A264A}] => (Allow) C:\Program Files\AVG\AVG2015\avgmfapx.exe FirewallRules: [{7C7B4F7B-D34D-4413-BC28-AD62BE5EAC30}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{6BDDA919-319E-468F-A6BB-1405D3C56D5C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{E4AE8CB8-C32F-4389-A2A2-66F983A1D212}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{3CF543D3-08F5-4E18-ACCC-27DF5FBF3478}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{C18D35BD-E86F-4C30-856B-FE8419471293}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe FirewallRules: [{6CDD3182-2B29-46C8-84DF-8BF549FBF03F}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe FirewallRules: [{1487EA1B-05F7-47B6-8ED2-385D35806F38}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe FirewallRules: [{FD091F93-2871-45E7-89CB-7BAE0218A51E}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe FirewallRules: [{F585BF5E-DA8D-492C-84A0-7C9D8DFE3CD4}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe FirewallRules: [{60BF001D-B3FF-4CF8-8FBC-75CDF4DF46C0}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe FirewallRules: [{BB18E1BC-DF04-437A-9898-342C21C16A97}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{8456A6C4-4A26-4F41-8EA7-F821B5A25FFA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{8D549D11-ECBE-4416-99FE-92F06268307C}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe FirewallRules: [{567DF070-C0C8-4B7D-9E5A-35BFE7BFE756}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe FirewallRules: [TCP Query User{06CCCDEB-CEEA-41BF-826B-BA0844BF6637}C:\users\pat\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\pat\appdata\local\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{3C551C3E-EE4F-42F9-B04A-254417255260}C:\users\pat\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\pat\appdata\local\google\chrome\application\chrome.exe ==================== Restore Points ========================= 11-04-2017 17:07:10 Scheduled Checkpoint 11-04-2017 17:31:05 Windows Update 12-04-2017 10:33:48 Windows Update 19-04-2017 16:32:49 Scheduled Checkpoint 29-04-2017 11:07:26 Scheduled Checkpoint 06-05-2017 11:26:28 Removed NetZero Launcher ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/06/2017 01:49:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 53.0.2.6333, time stamp: 0x590bd295 Faulting module name: xul.dll, version: 53.0.2.6333, time stamp: 0x590bd27e Exception code: 0x80000003 Fault offset: 0x0089d467 Faulting process id: 0x6cc Faulting application start time: 0x01d2c68eda3d508c Faulting application path: C:\Program Files\Mozilla Firefox\plugin-container.exe Faulting module path: C:\Program Files\Mozilla Firefox\xul.dll Report Id: 60c4130f-3284-11e7-8072-002622e61fc9 Error: (05/06/2017 01:49:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: firefox.exe, version: 53.0.2.6333, time stamp: 0x590bcebe Faulting module name: xul.dll, version: 53.0.2.6333, time stamp: 0x590bd27e Exception code: 0x80000003 Fault offset: 0x0089d467 Faulting process id: 0x1234 Faulting application start time: 0x01d2c68d5f3b57e7 Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla Firefox\xul.dll Report Id: 5a046023-3284-11e7-8072-002622e61fc9 Error: (05/06/2017 01:00:14 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Program Files\AVG\Antivirus\setup\iplugins\IStats.dll". Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (05/06/2017 01:00:11 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Program Files\AVG\Antivirus\setup\iplugins\IStats.dll". Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (05/06/2017 11:32:35 AM) (Source: YSearchUtilSvc) (EventID: 0) (User: ) Description: Event-ID 0 Error: (05/06/2017 11:26:28 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {0c6063ed-a715-4700-b98d-deb6e4be1263} Error: (05/06/2017 10:15:33 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\spybot - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (05/03/2017 09:42:58 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\spybot - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (05/02/2017 10:26:12 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\spybot - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (05/01/2017 10:39:39 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\spybot - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. System errors: ============= Error: (05/06/2017 12:20:52 PM) (Source: ipnathlp) (EventID: 30013) (User: ) Description: The DHCP allocator has disabled itself on IP address 10.0.0.125, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope. Error: (05/06/2017 12:20:52 PM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (05/06/2017 12:12:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AVG Antivirus service failed to start due to the following error: The system cannot find the path specified. Error: (05/06/2017 12:12:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The AVG Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (05/06/2017 11:09:54 AM) (Source: ipnathlp) (EventID: 30013) (User: ) Description: The DHCP allocator has disabled itself on IP address 10.0.0.125, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope. Error: (05/06/2017 11:09:54 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (05/06/2017 10:09:13 AM) (Source: ipnathlp) (EventID: 30013) (User: ) Description: The DHCP allocator has disabled itself on IP address 10.0.0.125, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope. Error: (05/06/2017 10:09:13 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (05/05/2017 07:54:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (05/05/2017 07:54:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz Percentage of memory in use: 48% Total physical RAM: 2908.89 MB Available physical RAM: 1496.9 MB Total Virtual: 5816.1 MB Available Virtual: 4323.8 MB ==================== Drives ================================ Drive c: (TI102605W0F) (Fixed) (Total:223.27 GB) (Free:174.46 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ==================== End of Addition.txt ============================