Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2015 02 Ran by OpheliaR at 2015-01-13 09:37:43 Running from C:\Users\OpheliaR\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AV: Norton Security (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} FW: Norton Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 1001 Nights: The Adventures Of Sindbad (HKLM-x32\...\1001 Nights: The Adventures Of Sindbad) (Version: - Alawar Entertainment Inc.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Action Ball Deluxe (HKLM-x32\...\Action Ball Deluxe) (Version: 1.0 - Alawar Entertainment Inc.) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) Alabama Smith in Escape from Pompeii (HKLM-x32\...\Alabama Smith in Escape from Pompeii) (Version: - Alawar Entertainment Inc.) Alabama Smith in the Quest of Fate (HKLM-x32\...\Alabama Smith in the Quest of Fate) (Version: - Alawar Entertainment Inc.) Alex Gordon (HKLM-x32\...\Alex Gordon) (Version: - Alawar Entertainment Inc.) Alexandra Fortune - Mystery of the Lunar Archipelago (HKLM-x32\...\Alexandra Fortune - Mystery of the Lunar Archipelago) (Version: - Alawar Entertainment Inc.) Alien Outbreak 2: Invasion (HKLM-x32\...\Alien Outbreak 2: Invasion) (Version: 1.0 - Alawar Entertainment Inc.) Amelie's Cafe: Holiday Spirit (HKLM-x32\...\Amelie's Cafe: Holiday Spirit) (Version: 1.0 - Alawar Entertainment Inc.) Amelie's Cafe: Summer Time (HKLM-x32\...\Amelie's Cafe: Summer Time) (Version: - Alawar Entertainment Inc.) Arctic Quest 2 (HKLM-x32\...\Arctic Quest 2) (Version: 1.0 - Alawar Entertainment Inc.) Aztec Tribe: New Land (HKLM-x32\...\Aztec Tribe: New Land) (Version: 1.0 - Alawar Entertainment Inc.) Beach Party Craze (HKLM-x32\...\Beach Party Craze) (Version: - Alawar Entertainment Inc.) Bilbo - The Four Corners of the World (HKLM-x32\...\Bilbo - The Four Corners of the World) (Version: - Alawar Entertainment Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform) City Magnate (HKLM-x32\...\City Magnate) (Version: 1.0 - Alawar Entertainment Inc.) Crop Busters (HKLM-x32\...\Crop Busters) (Version: 1.0 - Alawar Entertainment Inc.) Crusaders Of Space 2 (HKLM-x32\...\Crusaders Of Space 2) (Version: 1.0 - Alawar Entertainment Inc.) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.5.3606 - CyberLink Corp.) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.5.3228 - CyberLink Corp.) CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3305 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.2.3302 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden Enchanted Cavern (HKLM-x32\...\Enchanted Cavern) (Version: 1.0 - Alawar Entertainment Inc.) Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fashion Craze (HKLM-x32\...\Fashion Craze) (Version: - Alawar Entertainment Inc.) Fruit Lockers 2 - The Enchanting Islands (HKLM-x32\...\Fruit Lockers 2 - The Enchanting Islands) (Version: - Alawar Entertainment Inc.) Gourmania 3: Zoo Zoom (HKLM-x32\...\Gourmania 3: Zoo Zoom) (Version: 1.0 - Alawar Entertainment Inc.) Hamlet (HKLM-x32\...\Hamlet) (Version: - Alawar Entertainment Inc.) Haunted Domains (HKLM-x32\...\Haunted Domains) (Version: 1.0 - Alawar Entertainment Inc.) Heroes of Hellas 2: Olympia (HKLM-x32\...\Heroes of Hellas 2: Olympia) (Version: - Alawar Entertainment Inc.) Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden Hidden World (HKLM-x32\...\Hidden World) (Version: 1.0 - Alawar Entertainment Inc.) Holly 2 - Magic Land (HKLM-x32\...\Holly 2 - Magic Land) (Version: - Alawar Entertainment Inc.) HP Documentation (HKLM-x32\...\{CCE5C597-03EA-423E-BA80-6FCD280A8465}) (Version: 1.1.0.0 - Hewlett-Packard) HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard) HP Support Assistant (HKLM-x32\...\{904822F1-6C7D-4B91-B936-6A1C0810544C}) (Version: 7.7.34.34 - Hewlett-Packard Company) HP System Event Utility (HKLM-x32\...\{C78E8F51-3EAD-4F0C-83F0-EF371075E0B4}) (Version: 1.0.10 - Hewlett-Packard Company) HP Utility Center (HKLM\...\{7A75E042-0D30-43C2-BD2A-684F4BE38FF7}) (Version: 2.3.1 - Hewlett-Packard Company) HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3309 - Intel Corporation) Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1050 - Intel Corporation) Island Realms (HKLM-x32\...\Island Realms) (Version: - Alawar Entertainment Inc.) Journey of Hope (HKLM-x32\...\Journey of Hope) (Version: - Alawar Entertainment Inc.) Juliette's Fashion Empire (HKLM-x32\...\Juliette's Fashion Empire) (Version: 1.0 - Alawar Entertainment Inc.) Magic Shop (HKLM-x32\...\Magic Shop) (Version: 1.0 - Alawar Entertainment Inc.) Mahjongg Artifacts 2 (HKLM-x32\...\Mahjongg Artifacts 2) (Version: - Alawar Entertainment Inc.) Malwarebytes Anti-Exploit version 1.05.1.1016 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.05.1.1016 - Malwarebytes) McAfee LiveSafe - Internet Security (HKLM-x32\...\MSC) (Version: 12.8.992 - McAfee, Inc.) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla) My Farm Life (HKLM-x32\...\My Farm Life) (Version: 1.0 - Alawar Entertainment Inc.) Natalie Brooks - The Treasures of the Lost Kingdom (HKLM-x32\...\Natalie Brooks - The Treasures of the Lost Kingdom ) (Version: 1.0 - Alawar Entertainment Inc.) Norton Security (HKLM-x32\...\NS) (Version: 22.1.0.9 - Symantec Corporation) Oriental Dreams (HKLM-x32\...\Oriental Dreams) (Version: - Alawar Entertainment Inc.) Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.) RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.29070 - Realtek Semiconductor Corp.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 8.20.815.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7032 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.00.12.0906 - REALTEK Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Rescue Frenzy (HKLM-x32\...\Rescue Frenzy) (Version: 1.0 - Alawar Entertainment Inc.) Sea Bounty - Dead Man's Chest (HKLM-x32\...\Sea Bounty - Dead Man's Chest) (Version: - Alawar Entertainment Inc.) Ski Resort Mogul (HKLM-x32\...\Ski Resort Mogul) (Version: 1.0 - Alawar Entertainment Inc.) Sky Kingdoms (HKLM-x32\...\Sky Kingdoms) (Version: - Alawar Entertainment Inc.) Sky Taxi 4 (HKLM-x32\...\Sky Taxi 4) (Version: 1.0 - Alawar Entertainment Inc.) Snowy: Lunch Rush (HKLM-x32\...\Snowy: Lunch Rush) (Version: 1.0 - Alawar Entertainment Inc.) Sprill - The Mystery of The Bermuda Triangle (HKLM-x32\...\Sprill - The Mystery of The Bermuda Triangle) (Version: - Alawar Entertainment Inc.) Sprill and Ritchie - Adventures In Time (HKLM-x32\...\Sprill and Ritchie - Adventures In Time) (Version: - Alawar Entertainment Inc.) Stand O'Food (HKLM-x32\...\Stand O'Food) (Version: - Alawar Entertainment Inc.) Sunshine Acres (HKLM-x32\...\Sunshine Acres) (Version: 1.0 - Alawar Entertainment Inc.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1168 - SUPERAntiSpyware.com) Supermarket Mania (HKLM-x32\...\Supermarket Mania) (Version: - Alawar Entertainment Inc.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.15.0 - Synaptics Incorporated) The Curse Of Montezuma (HKLM-x32\...\The Curse Of Montezuma) (Version: - Alawar Entertainment Inc.) The Enchanting Islands (HKLM-x32\...\The Enchanting Islands) (Version: - Alawar Entertainment Inc.) The Joy of Farming (HKLM-x32\...\The Joy of Farming) (Version: 1.0 - Alawar Entertainment Inc.) The Sims™ 4 Create A Sim Demo (HKLM-x32\...\{6908ED99-F02B-4E99-A202-3FAC99C510ED}) (Version: 1.0.237.100 - Electronic Arts Inc.) The Treasures Of Montezuma 2 (HKLM-x32\...\The Treasures Of Montezuma 2) (Version: - Alawar Entertainment Inc.) Treasure Masters, Inc. (HKLM-x32\...\Treasure Masters, Inc.) (Version: - Alawar Entertainment Inc.) Tropical Farm (HKLM-x32\...\Tropical Farm ) (Version: 1.0 - Alawar Entertainment Inc.) Unity Web Player (HKU\S-1-5-21-895169118-4131550430-1158068055-1001\...\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS) UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden Virtual Farm (HKLM-x32\...\Virtual Farm ) (Version: 1.0 - Alawar Entertainment Inc.) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Zak & Jack in Showdown at Monstertown (HKLM-x32\...\Zak & Jack in Showdown at Monstertown) (Version: 1.0 - Alawar Entertainment Inc.) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 01-01-2015 16:53:29 Installed DirectX 05-01-2015 21:50:05 Windows Update 07-01-2015 11:08:59 Removed HP SimplePass ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1F7F1E1B-CEAF-4381-AC88-059558D23D6E} - System32\Tasks\Norton Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\SymErr.exe [2014-12-03] (Symantec Corporation) Task: {271ADC88-024A-4B1D-8440-E8B68B82EEFD} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink) Task: {3D37F3D5-AD2F-47D5-87F0-96215F7DAFC0} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-09-20] (Synaptics Incorporated) Task: {3FC11419-955C-43DA-AEB7-E2AC3F176FEF} - System32\Tasks\Games\UpdateCheck_S-1-5-21-895169118-4131550430-1158068055-1001 Task: {43B0C974-A5BF-4E7C-A380-F7BAC0823E47} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-27] (Adobe Systems Incorporated) Task: {4F218A11-1A55-4901-8547-C0D3DAA8D005} - System32\Tasks\HPCeeScheduleForOpheliaR => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard) Task: {5C478B66-7807-4573-B101-FE0540BFC586} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] () Task: {64A73D35-DB48-4FDA-95C8-010DF31036DE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd) Task: {661A9AB5-3896-4CB5-811B-330A44DF16FC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-10-21] (Hewlett-Packard) Task: {83926AD2-B76F-4FE3-A726-A0E014893298} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-10-21] (Hewlett-Packard) Task: {8C04BE85-ACF8-47FA-8E9B-153F105C54F7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-08-21] (Hewlett-Packard Company) Task: {8C26F880-76EF-4D26-A7DC-08B8EB644826} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-11-27] (Microsoft Corporation) Task: {91994455-D0D4-47A2-BE4D-F4A9689FDB24} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {AD6B99B0-12B1-4F86-BD38-A26BF4EC4D17} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-08-21] (Hewlett-Packard Company) Task: {B184F58F-EFB7-4354-A5AD-F7A204F7FD70} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-08-21] (Hewlett-Packard Company) Task: {C4B1C4C5-7ACC-4441-BDB9-AC269716CFC4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\WSCStub.exe [2014-12-10] (Symantec Corporation) Task: {C6BC2875-7DF6-42B9-92B8-7EF90B401FCE} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-895169118-4131550430-1158068055-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-10-26] (RealNetworks, Inc.) Task: {D1BDFEB8-6E4F-45D7-8DAC-0C28C92FF169} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-895169118-4131550430-1158068055-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-26] (RealNetworks, Inc.) Task: {D2397B84-C296-414C-99DA-52D126245FFF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Restart => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-08-21] (Hewlett-Packard Company) Task: {D6E58D99-3D69-45C4-A654-6CA31B7AF7E7} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-895169118-4131550430-1158068055-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-26] (RealNetworks, Inc.) Task: {E09AE52F-8394-42A8-919C-74BA51540880} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.) Task: {F38FBB0F-8868-4B93-891D-65E82D390885} - System32\Tasks\Norton Security\Norton Error Processor => C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\SymErr.exe [2014-12-03] (Symantec Corporation) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForOpheliaR.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2014-10-26 22:59 - 2014-10-26 22:59 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2014-10-30 05:41 - 2014-10-30 05:41 - 00031856 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe 2014-10-29 19:06 - 2014-10-29 19:06 - 00560192 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe 2015-01-06 21:39 - 2015-01-06 21:39 - 00865880 _____ () C:\Program Files (x86)\Real\RealPlayer\RPDS\Plugins\cldplin.dll 2014-10-30 05:41 - 2014-10-30 05:41 - 00035976 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll 2014-10-30 05:41 - 2014-10-30 05:41 - 00039560 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll 2014-10-30 05:41 - 2014-10-30 05:41 - 00032888 _____ () C:\Program Files (x86)\Real\UpdateService\RPDSUpdatePlugin.dll 2014-01-16 06:21 - 2013-08-05 02:49 - 00627672 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-08-05 18:48 - 2013-08-05 18:48 - 00016856 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2014-10-29 19:01 - 2014-10-29 19:01 - 01382048 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\cpprest100_1_2.dll 2014-10-26 23:03 - 2014-10-26 23:03 - 00052296 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\OpenPref.dll 2015-01-06 21:39 - 2015-01-06 21:39 - 00052808 _____ () C:\Program Files (x86)\Real\RealPlayer\openrpc.dll 2014-12-23 16:01 - 2014-11-26 11:40 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2015-01-06 21:39 - 2015-01-06 21:39 - 00573528 _____ () C:\Program Files (x86)\Real\RealPlayer\RPDS\Lib\r1api.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\Myreah\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Myreah\SkyDrive.old:ms-properties AlternateDataStreams: C:\Users\Myreah\Downloads\RE Resume.eml:OECustomProperty AlternateDataStreams: C:\Users\OpheliaR\SkyDrive:ms-properties AlternateDataStreams: C:\Users\OpheliaR\SkyDrive (2).old:ms-properties AlternateDataStreams: C:\Users\OpheliaR\SkyDrive (3).old:ms-properties AlternateDataStreams: C:\Users\OpheliaR\SkyDrive.old:ms-properties ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk" HKLM\...\StartupApproved\Run32: => "RealDownloader" HKU\S-1-5-21-895169118-4131550430-1158068055-1001\...\StartupApproved\Run: => "CCleaner Monitoring" ========================= Accounts: ========================== Administrator (S-1-5-21-895169118-4131550430-1158068055-500 - Administrator - Disabled) => C:\Users\Administrator Computer (S-1-5-21-895169118-4131550430-1158068055-1005 - Limited - Enabled) => C:\Users\Computer Guest (S-1-5-21-895169118-4131550430-1158068055-501 - Limited - Disabled) Myreah (S-1-5-21-895169118-4131550430-1158068055-1002 - Limited - Enabled) => C:\Users\Myreah OpheliaR (S-1-5-21-895169118-4131550430-1158068055-1001 - Administrator - Enabled) => C:\Users\OpheliaR ==================== Faulty Device Manager Devices ============= Name: F:\ Description: SD/MMC/MS PRO Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a} Manufacturer: Generic- Service: WUDFWpdFs Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ========================= Application errors: ================== Error: (01/13/2015 09:27:12 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program LiveComm.exe version 17.5.9600.20689 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 658c Start Time: 01d02f3c5544d433 Termination Time: 4294967295 Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe Report Id: 3fc2bca8-9b30-11e4-8271-fc15b400ef6c Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1 Error: (01/13/2015 09:23:00 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.5.5443, time stamp: 0x5475dd5d Faulting module name: mozalloc.dll, version: 34.0.5.5443, time stamp: 0x5475d664 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x1ce8 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Faulting package full name: plugin-container.exe4 Faulting package-relative application ID: plugin-container.exe5 Error: (01/13/2015 06:12:42 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (01/11/2015 10:56:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2194781 Error: (01/11/2015 10:56:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2194781 Error: (01/11/2015 10:56:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/11/2015 10:56:04 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2179359 Error: (01/11/2015 10:56:04 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2179359 Error: (01/11/2015 10:56:04 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/11/2015 10:55:49 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2163953 System errors: ============= Error: (01/13/2015 09:22:19 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HP Support Assistant Service service. Error: (01/11/2015 10:56:28 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the RealPlayerUpdateSvc service. Error: (01/11/2015 10:55:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the RealPlayerUpdateSvc service. Error: (01/11/2015 10:55:22 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the FDResPub service. Error: (01/11/2015 10:55:11 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HPWMISVC service. Error: (01/11/2015 10:18:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s). Error: (01/10/2015 08:59:29 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Background Intelligent Transfer Service service hung on starting. Error: (01/10/2015 08:59:10 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: {209500FC-6B45-4693-8871-6296C4843751} Error: (01/10/2015 08:54:47 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY) Description: WLAN Extensibility Module has failed to start. Module Path: C:\WINDOWS\system32\Rtlihvs.dll Error Code: 126 Error: (01/10/2015 08:52:21 PM) (Source: DCOM) (EventID: 10010) (User: GODSPROPERTY2) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Microsoft Office Sessions: ========================= Error: (01/13/2015 09:27:12 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: LiveComm.exe17.5.9600.20689658c01d02f3c5544d4334294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe3fc2bca8-9b30-11e4-8271-fc15b400ef6cmicrosoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 Error: (01/13/2015 09:23:00 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.5.54435475dd5dmozalloc.dll34.0.5.54435475d66480000003000014251ce801d02d578ce2c950C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllacdb0e30-9b2f-11e4-8271-fc15b400ef6c Error: (01/13/2015 06:12:42 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{6FCD4D5A-20B9-4D79-ABA5-4E7048944025}\recordingmanager.exe Error: (01/11/2015 10:56:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2194781 Error: (01/11/2015 10:56:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2194781 Error: (01/11/2015 10:56:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/11/2015 10:56:04 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2179359 Error: (01/11/2015 10:56:04 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2179359 Error: (01/11/2015 10:56:04 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/11/2015 10:55:49 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2163953 ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU N3520 @ 2.16GHz Percentage of memory in use: 47% Total physical RAM: 3992.55 MB Available physical RAM: 2085.59 MB Total Pagefile: 7671 MB Available Pagefile: 3723.34 MB Total Virtual: 131072 MB Available Virtual: 131071.78 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:679.28 GB) (Free:576.65 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:18.58 GB) (Free:1.86 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: () (Removable) (Total:0.95 GB) (Free:0.07 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 1E2AB9DB) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 970.5 MB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================