Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-11-2017 02 Ran by [removed] (09-11-2017 16:02:53) Running from C:\Users\[removed]\Desktop Microsoft Windows 10 Pro Version 1703 15063.674 (X86) (2017-07-16 18:26:53) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1409049169-3834728507-3598825175-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1409049169-3834728507-3598825175-503 - Limited - Disabled) Guest (S-1-5-21-1409049169-3834728507-3598825175-501 - Limited - Disabled) Pamela (S-1-5-21-1409049169-3834728507-3598825175-1000 - Administrator - Enabled) => C:\Users\Pamela ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated) Adobe Flash Player 27 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated) Adobe Flash Player 27 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated) Adobe Flash Player ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 9.0.45.0 - Adobe Systems Incorporated) Aimersoft Helper Compact 2.5.1 (HKLM\...\{405147F7-FCC5-499B-A27E-EA6BD4A80435}_is1) (Version: 2.5.1 - Aimersoft) Allavsoft 3.13.9.6261 (HKLM\...\{6EBED4D8-13D9-4270-8D44-B57DDB7A787C}_is1) (Version: - Allavsoft Corporation) Ashampoo Burning Studio FREE v.1.14.5 (HKLM\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) AVG (HKLM\...\{18B25CA1-A325-4ED8-A494-C764D914D57E}) (Version: 1.211.3 - AVG Technologies) Hidden AVG AntiVirus FREE (HKLM\...\AVG Antivirus) (Version: 17.7.3032 - AVG Technologies) AVG Driver Updater (HKLM\...\{BAAB946F-7E00-41F4-BEC7-B8CCF758E012}) (Version: 2.3.0 - AVG Netherlands B.V) Hidden AVG Driver Updater (HKLM\...\AVG Driver Updater) (Version: 2.3.0 - AVG Netherlands B.V) AVG PC TuneUp (HKLM\...\{C0A95EFE-B876-4922-9AE1-21C53D2DDB42}) (Version: 16.75.1 - AVG Technologies) Hidden AVG PC TuneUp (HKLM\...\AVG PC TuneUp) (Version: 16.75.3.10304 - AVG Technologies) Canon Easy-WebPrint EX (HKLM\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.) Canon IJ Scan Utility (HKLM\...\Canon_IJ_Scan_Utility) (Version: - ‪Canon Inc.‬) Canon MG2200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2200_series) (Version: 1.00 - Canon Inc.) Canon MG2200 series On-screen Manual (HKLM\...\Canon MG2200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.) Canon MG2200 series User Registration (HKLM\...\Canon MG2200 series User Registration) (Version: - Canon Inc.‎) Canon My Image Garden (HKLM\...\Canon My Image Garden) (Version: 1.0.0 - Canon Inc.) Canon My Image Garden Design Files (HKLM\...\Canon My Image Garden Design Files) (Version: 1.0.0 - Canon Inc.) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.) Canon Quick Menu (HKLM\...\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6623 - CDBurnerXP) Cisco WebEx Meetings (HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\...\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC) Corel Paint Shop Pro Photo XI (HKLM\...\{E1C7EF5E-3A7B-4ED4-A48B-F70F1B36EAB4}) (Version: 11.20.0000 - Corel Corporation) Deal Info (HKLM\...\{3284FB04-8EEA-49D5-ACC2-2AB7B8845EE0}) (Version: 2008.1.22.0 - EarthLink, Inc) Hidden EarthLink Common Authentication (HKLM\...\{C057F6D0-0E4C-4B18-B645-9D0804FCFAFD}) (Version: 1.0.86.0 - ) Hidden EarthLink FastLane (HKLM\...\{BD33CD92-3A42-4CE1-ADDE-A9B64CFFF24D}) (Version: 5.8.0.13 - EarthLink, Inc) EarthLink Software (HKLM\...\EarthLink TotalAccess 2004) (Version: 2008.1.22.0 - ) EarthLink Toolbar (HKLM\...\{B8C2A83F-20B0-49D9-BA2B-6495DD8639ED}) (Version: - EarthLink, Inc.) Emby Server (HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\...\Emby Server) (Version: 3.0 - Emby Team) Filters Unlimited 2.0 (HKLM\...\Filters Unlimited_is1) (Version: - ) FinalBurner Free v2.24.0.195 (HKLM\...\{1A3E23D7-7A1E-43EC-B35D-EB8A31BED943}) (Version: - ) FMW 1 (HKLM\...\{B9B474D5-8B52-4A05-8DA0-CFECB057E523}) (Version: 1.226.3 - AVG Technologies) Hidden Google Chrome (HKLM\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.) Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden Gramblr (HKLM\...\Gramblr) (Version: 2.9.88 - Gramblr Team) Java 8 Update 66 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation) K-Lite Codec Pack 5.2.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 5.2.0 - ) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Mozilla Firefox 56.0.2 (x86 en-US) (HKLM\...\Mozilla Firefox 56.0.2 (x86 en-US)) (Version: 56.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.2.6506 - Mozilla) Nero Info (HKLM\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 18.0.0011 - Nero AG) Pidgin (HKLM\...\Pidgin) (Version: 2.10.12 - ) PlayOn (HKLM\...\{4dc9bf99-657b-42e6-bd9d-0e411b3a5fbe}) (Version: 4.2.110.18106 - MediaMall Technologies, Inc.) PlayOn (HKLM\...\{78F2AF4B-1A60-4852-ADA5-24CD4435A819}) (Version: 4.2.110 - MediaMall Technologies, Inc.) Hidden PlayOn Dependencies (HKLM\...\{0E100B2E-D56C-4BFB-9FD6-894FDEDC10E6}) (Version: 1.0.0.0 - MediaMall Technologies, Inc.) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Redistributed Files (HKLM\...\{40939C6D-8F27-40B8-9CBC-72701624185D}) (Version: 2.0.46.0 - EarthLink, Inc.) Hidden ShopTracker 1.1.23 (HKLM\...\AmazonMeter) (Version: 1.1.23 - Nielsen) Smart Installer (HKLM\...\SmartInstaller) (Version: - EarthLink, Inc.) Spark 2.5.8 (HKLM\...\Spark 2.5.8) (Version: - Jive Software) Spotify (HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\...\Spotify) (Version: 1.0.62.508.g2c497f24 - Spotify AB) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.8.1 - Synaptics Incorporated) TotalAccess Core Applications (HKLM\...\{29B2D505-8E7F-42E6-B497-6CC525E06871}) (Version: 2008.1.22.0 - EarthLink, Inc.) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows 10 Update and Privacy Settings (HKLM\...\{542CC2C2-ABAF-4604-8723-DA296AF74540}) (Version: 1.0.14.0 - Microsoft Corporation) Windows 7 Games for Windows 10 and 8 (HKLM\...\Win7Games) (Version: 2.0 - hxxp://winaero.com) WordPerfect Office IFilter 32-bit (HKLM\...\{1DF03ECE-6AF4-414E-B118-C316F151A9A2}) (Version: 1.4 - Corel Corporation) WordPerfect Office X6 - Common Files (HKLM\...\{315FE707-7A15-4B1B-8C5A-955428AAA01D}) (Version: 16.2.1 - Corel Corporation) Hidden WordPerfect Office X6 - Common Files English (HKLM\...\{E1AF3785-AA77-471E-ABC5-4C2B459B877A}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - IPM (HKLM\...\{230100D9-27B4-49A3-A30F-D44B51EF56AA}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Lightning Files (HKLM\...\{440F51A9-8CA3-41D7-AFD5-F47820895949}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Lightning Files English (HKLM\...\{C4D92146-95DE-415A-99CC-51FBFF7C10CF}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Oxford (HKLM\...\{8959569B-D9BA-43A9-972A-D509EE7D4BA9}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Presentations Files (HKLM\...\{EAA5C699-6DB5-4508-BD64-B79EB9409C9D}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Presentations Files English (HKLM\...\{86ACFB25-0FA5-4A01-96B5-EE8F229D456E}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Quattro Pro Files (HKLM\...\{069793F3-E123-47B9-88DB-5DE76FF32ADB}) (Version: 16.2.1 - Corel Corporation) Hidden WordPerfect Office X6 - Quattro Pro Files English (HKLM\...\{10FFE1D7-6A72-4483-9856-1A2FBBC5A425}) (Version: 16.2 - Corel Corporation) Hidden WordPerfect Office X6 - Setup Files (HKLM\...\{26D6D2A4-F08A-4212-86E7-7F1F75033610}) (Version: 16.2.1 - Corel Corporation) Hidden WordPerfect Office X6 - System Files (HKLM\...\{8270ABE3-53A5-4046-BF84-EB5FBB0F5B10}) (Version: 16.1 - Corel Corporation) Hidden WordPerfect Office X6 - WordPerfect Files (HKLM\...\{CCADD122-70A5-47A6-8722-1BD5267B85F5}) (Version: 16.2.1 - Corel Corporation) Hidden WordPerfect Office X6 - WordPerfect Files English (HKLM\...\{CD29C36F-2C6D-4ED3-BC21-B20C8038E9A5}) (Version: 16.2.1 - Corel Corporation) Hidden WordPerfect Office X6 - WT (HKLM\...\{0F7A0D0F-6576-489E-B20B-B7C8F95BBCC3}) (Version: 16.1 - Corel Corporation) Hidden WordPerfect Office X6 (HKLM\...\_{26D6D2A4-F08A-4212-86E7-7F1F75033610}) (Version: 16.0.0.428 - Corel Corporation) WordPerfect Office X6 (HKLM\...\{F6582F6F-6CD1-4B62-8BC6-EACF98AF410F}) (Version: 16.2 - Corel Corporation) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{2B656800-DADC-4237-9CDD-AA4CA2ED9890}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{32E26FD9-F435-4A20-A561-35D4B987CFDC}\InprocServer32 -> C:\ProgramData\WebEx\WebEx\1526\atucfobj.dll (Cisco WebEx LLC) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{4AA18B3D-EA61-400E-9643-6454B7A0FA89}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{B03EE1EA-8BEB-40DA-A1B0-699BCBB79CCA}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{B3158DBC-3C85-4CA4-8BE9-C5DDDAC363B2}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{C966DA3A-462D-43F7-9060-43CA186D3167}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{D6A65470-14B1-496E-B220-9321D7AE80BF}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{E16E7E5D-F84F-4380-A3EB-0DE53A249479}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) CustomCLSID: HKU\S-1-5-21-1409049169-3834728507-3598825175-1000_Classes\CLSID\{FDB9FF81-EB8F-46EC-A4E7-1E5CDF5F771F}\InprocServer32 -> C:\Users\Pamela\AppData\Roaming\Five9\Softphone8.0.8\CounterPathSDK.dll (CounterPath Corporation) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2017-10-20] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers1: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files\AVG\AVG PC TuneUp\SDShelEx-win32.dll [2017-07-26] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers2: [QuickFinderMenu] -> {45dfc9aa-83c4-4ded-bc9d-f0442b4b02ea} => c:\Program Files\Corel\WordPerfect Office X6\Programs\PFSE160.DLL [2012-10-31] (Corel Corporation) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers4: [AVG Disk Space Explorer Shell Extension] -> {4838CD50-7E5D-4811-9B17-C47A85539F28} => C:\Program Files\AVG\AVG PC TuneUp\DseShExt-x86.dll [2017-07-26] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers4: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files\AVG\AVG PC TuneUp\SDShelEx-win32.dll [2017-07-26] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers4: [QuickFinderMenu] -> {45dfc9aa-83c4-4ded-bc9d-f0442b4b02ea} => c:\Program Files\Corel\WordPerfect Office X6\Programs\PFSE160.DLL [2012-10-31] (Corel Corporation) ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2017-10-20] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04C7A7DB-0E12-4761-872A-EAB7CFAC0587} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {065C3054-63BE-4177-A175-95534951D831} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {0A5A5710-3CD0-48CC-BC1E-020D2939A5C6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {0B94467F-B17E-4954-A652-5DB82B192C23} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {0F7455E2-5869-4825-9F67-2D0C2C11575C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {10E84112-A401-47AA-98C4-4AB4895D03A9} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {110F5691-893E-4292-94D3-FC8BB75B3119} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {2AC1FCD3-3E12-4B69-830B-EE08DFD32BAC} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {2F6F311E-FCB5-41D2-9382-2869EEC3CC6A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {32A48ECF-4361-41FA-8C5A-AB1E4E9F55EF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {3787AF9C-86B9-4D64-AC58-B942B5729E3F} - System32\Tasks\AVG Driver Updater Scan => C:\Program Files\AVG Driver Updater\AVG Driver Updater.exe [2017-01-30] (AVG Netherlands B.V) Task: {38884D52-1BE7-4327-9452-D6C5ECF22F68} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {3BBF0FC3-0A54-4E30-B2F6-1891BCE91E77} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {450ADF20-699B-4C4C-930D-BA2AA327E640} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-10-11] (Microsoft Corporation) Task: {46F332C0-B680-4D2F-B7CA-FA961292F766} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {49497D1F-C5F5-44E6-8D87-9791DB9F17F6} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {494F5E91-B419-4B19-857A-4E81366770F9} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {4BE76527-18C1-4B97-A721-0F5045A45257} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe Task: {5010A2AF-765E-41C4-8B59-08D9CBF4FE97} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {5AA1F050-40F0-4F17-9177-E4241CFD5DCE} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [2017-10-20] (AVG Technologies CZ, s.r.o.) Task: {5BA00EFC-C96D-4062-BD7B-3CB0FD008938} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {5BDC0903-B813-414C-90EB-C83DBF619900} - System32\Tasks\Nero\Nero Info => C:\Program Files\Common Files\Nero\Nero Info\NeroInfo.exe [2016-09-26] (Nero AG) Task: {5C04D629-BF9A-495B-A926-F0DCF6E6F4E6} - System32\Tasks\{3419CADB-365D-4B04-ACE6-FACA907AA584} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files\MediaMall\drivers\i386\DPInstall.exe" -d C:\WINDOWS\Installer\MSI56C6.tmp- -c /i "C:\Program Files\MediaMall\drivers\i386\povrtdev.inf" Task: {5DEA6A87-A410-4E25-BC1E-C33C4908EE30} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated) Task: {5FC2D175-584E-4CA2-8FC7-B4D5D02D93D8} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {7958B754-8E74-439D-A230-2612E75FF946} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {7AB9F29D-79DD-45FB-A651-1D13341EC9B9} - System32\Tasks\AVG_SYS_TASK_0215av => C:\ProgramData\Avg_Update_0215av\AVG-Secure-Search-Update_0215av.exe Task: {7BFB8CDF-B037-4A53-8258-AE82612ECAF3} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {8AEE4359-C7E3-4B3A-BDCB-581D1693E8EB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {8BC6711B-76A4-4C54-9E14-8A3BC9403581} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {8E06F6BD-6F5E-46EA-B902-0F4038606D3D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {9166C508-6BD9-4112-AC39-76B2362A008B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files\AVG\AVG PC TuneUp\tuscanx.exe [2017-07-26] (AVG Technologies CZ, s.r.o.) Task: {957A7317-FFA7-4350-8948-FA3FF0ECA9CB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {9B1BF274-20DF-4FB3-9FB0-021CEC51BA0F} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9B7C9692-DF51-4E10-9FD2-029BD3D7E57D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {A2CF756D-B56E-4440-A22E-CEDA465899D6} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {A30FDB92-4B77-46CC-BF08-4A2F8DE846B2} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-11-09] (Oracle Corporation) Task: {AE4D1028-5970-429D-B130-AADBD52B556F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {B1C50BB7-5209-4628-9CEC-9DDC5B46F321} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {BA2F0F4D-4A43-43CB-943B-FBDB1540B088} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {BEB30A5C-F78B-44FA-91A5-2016E780C404} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {C53E8216-D3A4-4895-A439-04C1453802A7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C870F9DA-9CB4-414D-9FBB-2654CFDB42B3} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {C8784842-FFE0-4576-B136-EE1816148439} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_27_0_0_183_pepper.exe [2017-10-25] (Adobe Systems Incorporated) Task: {C9D9F064-85B5-408B-85B6-10C2077736D4} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {CA480A39-7E78-465C-BF87-D3DE509695B1} - System32\Tasks\AVG Driver Updater Startup => C:\Program Files\AVG Driver Updater\AVG Driver Updater.exe [2017-01-30] (AVG Netherlands B.V) Task: {CB090992-2571-4D52-B85E-F673CF00534F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {D199E2F5-A2AE-41B4-9FDF-B731BC51949D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {D8268DC0-21E9-4069-A88C-6FC9A102B2FF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {D8352C3C-8A40-4740-B31F-41D3F9D87394} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D939950D-DFA1-4BE8-862B-38B77B5A4A09} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E163940D-1E23-4F6A-9C81-3A95FDE0A8D5} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E31BE7D1-6F87-45B6-9CD3-21D9E788E580} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated) Task: {E762AB79-FA39-466E-8297-0D2C2E0A21C8} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {FB243BF4-979E-48B8-9319-52BEEDCB8A5F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\AVG Driver Updater Scan.job => C:\Program Files\AVG Driver Updater\AVG Driver Updater.exe Task: C:\WINDOWS\Tasks\AVG Driver Updater Startup.job => C:\Program Files\AVG Driver Updater\AVG Driver Updater.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2006-11-02 19:40 - 2006-11-02 19:40 - 000174656 _____ () C:\WINDOWS\system32\PSIService.exe 2016-11-21 21:29 - 2016-11-21 21:29 - 052992000 _____ () C:\Program Files\Common Files\ffdshowEx\libcef.DLL 2017-03-18 10:19 - 2017-03-18 10:19 - 000116824 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-09-12 20:42 - 2017-09-12 20:42 - 000060160 _____ () C:\Program Files\AVG\Antivirus\module_lifetime.dll 2017-03-18 10:19 - 2017-03-18 12:23 - 001456128 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-11-07 03:53 - 2017-11-07 03:54 - 000075264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x86__kzf8qxf38zg5c\SkypeHost.exe 2017-11-07 03:53 - 2017-11-07 03:54 - 000173568 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x86__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-11-07 03:53 - 2017-11-07 03:54 - 018178560 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x86__kzf8qxf38zg5c\SkyWrap.dll 2017-11-07 03:53 - 2017-11-07 03:54 - 001793536 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x86__kzf8qxf38zg5c\skypert.dll 2016-12-02 10:45 - 2016-12-02 10:45 - 048920064 _____ () C:\Program Files\AVG\UiDll\2623\libcef.dll 2016-08-12 20:13 - 2016-07-14 14:05 - 001506304 _____ () C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\DAQExp.dll 2016-08-12 20:13 - 2014-05-19 16:19 - 000137728 _____ () C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\CBSCreateVC.dll 2017-10-20 07:37 - 2017-10-20 07:37 - 000168216 _____ () C:\Program Files\AVG\Antivirus\JsonRpcServer.dll 2017-07-03 20:45 - 2017-07-03 20:45 - 067109376 _____ () C:\Program Files\AVG\Antivirus\libcef.dll 2017-10-20 07:37 - 2017-10-20 07:37 - 000218208 _____ () C:\Program Files\AVG\Antivirus\event_routing_rpc.dll 2017-10-20 07:37 - 2017-10-20 07:37 - 000245704 _____ () C:\Program Files\AVG\Antivirus\tasks_core.dll 2017-10-25 07:38 - 2017-10-25 07:38 - 000704456 _____ () C:\Program Files\AVG\Antivirus\ffl2.dll 2017-01-31 07:43 - 2017-11-09 07:28 - 008218192 _____ () C:\Program Files\Gramblr\gramblr.exe 2017-10-10 04:25 - 2017-10-10 04:25 - 021005824 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\Music.UI.exe 2017-10-10 04:25 - 2017-10-10 04:25 - 006517760 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\EntCommon.dll 2017-08-22 23:00 - 2017-08-22 23:00 - 000758784 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\Microsoft.Membership.MeControl.UI.Xaml.dll 2017-09-26 14:59 - 2017-09-26 14:59 - 002890664 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-10-10 04:25 - 2017-10-10 04:25 - 012088320 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\Music.Visuals.dll 2017-10-10 04:25 - 2017-10-10 04:25 - 008046080 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\EntPlat.dll 2017-06-01 00:53 - 2017-06-01 00:53 - 000100512 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18421.0_x86__8wekyb3d8bbwe\GNSDK_FP.DLL 2017-10-18 11:04 - 2017-10-18 11:05 - 015201792 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17092.13511.0_x86__8wekyb3d8bbwe\Video.UI.exe 2017-10-18 11:04 - 2017-10-18 11:05 - 006486528 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17092.13511.0_x86__8wekyb3d8bbwe\EntCommon.dll 2017-09-26 14:59 - 2017-09-26 14:59 - 002890664 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17092.13511.0_x86__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-10-18 11:04 - 2017-10-18 11:05 - 007872000 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17092.13511.0_x86__8wekyb3d8bbwe\EntPlat.dll 2017-10-10 04:24 - 2017-10-10 04:24 - 003274240 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1709.2703.0_x86__8wekyb3d8bbwe\Calculator.exe 2017-09-26 14:59 - 2017-09-26 14:59 - 002890664 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1709.2703.0_x86__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-09-26 14:24 - 2017-09-20 20:57 - 003011928 _____ () C:\Program Files\Google\Chrome\Application\61.0.3163.100\libglesv2.dll 2017-09-26 14:24 - 2017-09-20 20:57 - 000086872 _____ () C:\Program Files\Google\Chrome\Application\61.0.3163.100\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 18:04 - 2016-08-14 04:40 - 000000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Pamela\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{dc5b74ac-9dd6-4758-a297-d9c3e21e7ccf}.jpg HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper -> DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupfolder: C:^Users^Pamela^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kasamba Messenger.lnk => C:\Windows\pss\Kasamba Messenger.lnk.Startup MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon HKLM\...\StartupApproved\Run: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run: => "GrooveMonitor" HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\...\StartupApproved\Run: => "Plex Media Server" HKU\S-1-5-21-1409049169-3834728507-3598825175-1000\...\StartupApproved\Run: => "BlueStacks Agent" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{485855FA-0D46-472D-94C0-3D727D6398C1}] => (Allow) C:\Program Files\Winamp\winamp.exe FirewallRules: [{07EA8C35-8018-4907-BC20-9546ECFE4B6D}] => (Allow) C:\Program Files\Winamp\winamp.exe FirewallRules: [{14788EB2-6FA4-421B-8F72-7C432A6AF7D5}] => (Allow) C:\Program Files\MediaMall\Surfer.exe FirewallRules: [{F854713F-70E8-4173-98D2-80184F837D46}] => (Allow) C:\Program Files\MediaMall\PlayMark.exe FirewallRules: [{8E720BB3-034F-4F84-BE2C-9353F41838EB}] => (Allow) C:\Program Files\MediaMall\PlayOn.exe FirewallRules: [{65BF8529-0B48-4337-B7C3-3BDE1F4D4FF3}] => (Allow) C:\Program Files\MediaMall\SettingsManager.exe FirewallRules: [{DEC24587-61E6-4008-9C42-BBED778F688C}] => (Allow) C:\Program Files\MediaMall\MediaMallServerLauncher.exe FirewallRules: [{956683D5-4674-4EC0-8535-D6853E24A31D}] => (Allow) C:\Program Files\MediaMall\MediaMallServer.exe FirewallRules: [UDP Query User{A973372B-B0E5-4B36-904D-CA0094404151}C:\program files\spark\spark.exe] => (Allow) C:\program files\spark\spark.exe FirewallRules: [TCP Query User{43B3EC8B-BA95-4540-B516-7E1F6B41EE53}C:\program files\spark\spark.exe] => (Allow) C:\program files\spark\spark.exe FirewallRules: [{C722BA3F-ED37-49EF-8418-1C15DBD54259}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{5FD7F97A-1938-46F2-ACCF-AC4FAB24237F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{96F869A1-AFA4-4DA6-96A5-A432F51F78F9}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{C69338A9-192C-4671-9D13-E74B31D473F6}C:\users\pamela\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\pamela\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{C5D6AFAA-C1CA-4AD2-A77C-1B147980CD11}C:\users\pamela\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\pamela\appdata\roaming\spotify\spotify.exe FirewallRules: [{B10DD371-1CC9-47FB-8456-D1BC1604C241}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{C4F4CF00-8D55-4869-AC8B-199D7A3EF1ED}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{1CE846E2-04BA-4401-8A57-AAD66F2A1B16}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{724C12FC-0548-4E19-86A3-BB90E93A6B98}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{3DC9A526-5161-4150-950D-A1F89C87B2F5}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{BE6C4631-6E96-419F-A9E8-BE1D5E9B04E5}] => (Allow) LPort=8097 FirewallRules: [{A92B030C-CE1D-4AAD-A14C-5D0169861034}] => (Allow) C:\Program Files\EarthLink TotalAccess\TaskPanl.exe FirewallRules: [{70BF5B7B-6480-4263-BAFD-64D8A33C4902}] => (Allow) C:\Program Files\EarthLink TotalAccess\TaskPanl.exe ==================== Restore Points ========================= 18-10-2017 10:17:58 Windows Update 26-10-2017 10:28:04 Scheduled Checkpoint 04-11-2017 11:24:44 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Standard PS/2 Keyboard Description: Standard PS/2 Keyboard Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard keyboards) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Lenovo Pointing Device Description: Lenovo Pointing Device Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Synaptics Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (11/09/2017 03:40:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Pamela-PC) Description: Activation of app windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel failed with error: -2147417836 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/09/2017 05:11:09 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Pamela-PC) Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/08/2017 07:48:06 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: MediaMallServer.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException at r21Z2VJiok7u9HKc4Xn.buwaSWJv9Okfgq4D7yy.WndProc(System.Windows.Forms.Message ByRef) at System.Windows.Forms.NativeWindow.DebuggableCallback(IntPtr, Int32, IntPtr, IntPtr) at System.Windows.Forms.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr) at System.Windows.Forms.NativeWindow.DefWndProc(System.Windows.Forms.Message ByRef) at System.Windows.Forms.NativeWindow.WndProc(System.Windows.Forms.Message ByRef) at System.Windows.Forms.NativeWindow.DebuggableCallback(IntPtr, Int32, IntPtr, IntPtr) at System.Windows.Forms.UnsafeNativeMethods.PeekMessage(MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32, Int32) at System.Windows.Forms.Application+ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(IntPtr, Int32, Int32) at System.Windows.Forms.Application+ThreadContext.RunMessageLoopInner(Int32, System.Windows.Forms.ApplicationContext) at System.Windows.Forms.Application+ThreadContext.RunMessageLoop(Int32, System.Windows.Forms.ApplicationContext) at System.Windows.Forms.Application.Run(System.Windows.Forms.Form) at qQ5Wjub9SyX01sBp8ON.DS3dMSbln4SApiXJtp3.qMPZu1NIJ7r(System.String[]) Error: (11/08/2017 04:17:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Pamela-PC) Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/07/2017 07:24:25 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: MediaMallServer.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException at r21Z2VJiok7u9HKc4Xn.buwaSWJv9Okfgq4D7yy.WndProc(System.Windows.Forms.Message ByRef) at System.Windows.Forms.NativeWindow.DebuggableCallback(IntPtr, Int32, IntPtr, IntPtr) at Microsoft.Win32.UnsafeNativeMethods.DefWindowProc(IntPtr, Int32, IntPtr, IntPtr) at Microsoft.Win32.SystemEvents.WindowProc(IntPtr, Int32, IntPtr, IntPtr) at System.Windows.Forms.UnsafeNativeMethods.PeekMessage(MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32, Int32) at System.Windows.Forms.Application+ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(IntPtr, Int32, Int32) at System.Windows.Forms.Application+ThreadContext.RunMessageLoopInner(Int32, System.Windows.Forms.ApplicationContext) at System.Windows.Forms.Application+ThreadContext.RunMessageLoop(Int32, System.Windows.Forms.ApplicationContext) at System.Windows.Forms.Application.Run(System.Windows.Forms.Form) at qQ5Wjub9SyX01sBp8ON.DS3dMSbln4SApiXJtp3.qMPZu1NIJ7r(System.String[]) Error: (11/07/2017 08:23:44 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Pamela-PC) Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/07/2017 04:40:27 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Pamela-PC) Description: Activation of app Microsoft.SkypeApp_kzf8qxf38zg5c!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/07/2017 03:50:53 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Pamela-PC) Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/06/2017 08:45:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MediaMallServer.exe, version: 4.2.114.18341, time stamp: 0x58ef6548 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x01b6ad6c Faulting process id: 0xd58 Faulting application start time: 0x01d3571ad1b5d209 Faulting application path: C:\Program Files\MediaMall\MediaMallServer.exe Faulting module path: unknown Report Id: ca91ef80-510d-4260-80ed-bf4d608a4439 Faulting package full name: Faulting package-relative application ID: Error: (11/06/2017 08:45:00 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: MediaMallServer.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException at r21Z2VJiok7u9HKc4Xn.buwaSWJv9Okfgq4D7yy.WndProc(System.Windows.Forms.Message ByRef) at System.Windows.Forms.NativeWindow.DebuggableCallback(IntPtr, Int32, IntPtr, IntPtr) at Microsoft.Win32.UnsafeNativeMethods.DefWindowProc(IntPtr, Int32, IntPtr, IntPtr) at Microsoft.Win32.SystemEvents.WindowProc(IntPtr, Int32, IntPtr, IntPtr) at System.Windows.Forms.UnsafeNativeMethods.PeekMessage(MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32, Int32) at System.Windows.Forms.Application+ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(IntPtr, Int32, Int32) at System.Windows.Forms.Application+ThreadContext.RunMessageLoopInner(Int32, System.Windows.Forms.ApplicationContext) at System.Windows.Forms.Application+ThreadContext.RunMessageLoop(Int32, System.Windows.Forms.ApplicationContext) at System.Windows.Forms.Application.Run(System.Windows.Forms.Form) at qQ5Wjub9SyX01sBp8ON.DS3dMSbln4SApiXJtp3.qMPZu1NIJ7r(System.String[]) System errors: ============= Error: (11/02/2017 07:26:02 PM) (Source: DCOM) (EventID: 10010) (User: Pamela-PC) Description: The server microsoft.windowscommunicationsapps_17.8700.40485.0_x86__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout. Error: (11/02/2017 01:49:10 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MediaMall Server service. Error: (10/28/2017 07:27:20 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (10/28/2017 07:27:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (10/28/2017 07:25:37 AM) (Source: DCOM) (EventID: 10010) (User: Pamela-PC) Description: The server microsoft.windowscommunicationsapps_17.8600.40525.0_x86__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout. Error: (10/21/2017 03:17:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (10/21/2017 03:17:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (10/19/2017 07:17:33 PM) (Source: DCOM) (EventID: 10010) (User: Pamela-PC) Description: The server microsoft.windowscommunicationsapps_17.8600.40525.0_x86__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout. Error: (10/13/2017 10:26:29 PM) (Source: DCOM) (EventID: 10010) (User: Pamela-PC) Description: The server microsoft.windowscommunicationsapps_17.8600.40525.0_x86__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout. Error: (10/13/2017 08:46:29 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ==================== Memory info =========================== Processor: AMD Athlon(tm) II X2 B24 Processor Percentage of memory in use: 83% Total physical RAM: 3071.39 MB Available physical RAM: 519.27 MB Total Virtual: 6937.22 MB Available Virtual: 1340.54 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:927.93 GB) (Free:861.88 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 30831E8D) Partition 1: (Active) - (Size=3.1 GB) - (Type=27) Partition 2: (Not Active) - (Size=927.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================