Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-08-2015 01 Ran by linda (2015-08-05 12:48:56) Running from C:\Users\linda\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3954486152-1987511008-2705091493-500 - Administrator - Disabled) Guest (S-1-5-21-3954486152-1987511008-2705091493-501 - Limited - Enabled) => C:\Users\Guest linda (S-1-5-21-3954486152-1987511008-2705091493-1000 - Administrator - Enabled) => C:\Users\linda ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Internet Security (Disabled - Out of date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} AS: Norton Internet Security (Enabled - Out of date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 337 GAMES (HKU\S-1-5-21-3954486152-1987511008-2705091493-1000\...\337Games) (Version: 1.1.1.0 - ) <==== ATTENTION 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0.1 - Microsoft Corporation) Hidden Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.4 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2540 - Adobe Systems Incorporated) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.2 - Adobe Systems Incorporated) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Bejeweled 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden Comcast Desktop Software (v1.2.0.9) (HKLM-x32\...\{CEF7211D-CE3A-44C4-B321-D84A2099AE94}) (Version: 23 - Comcast) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2115 - CyberLink Corp.) DealCabby (HKLM-x32\...\DealCabby) (Version: 1.0703.0126 - DealCabby) DealPly (HKU\S-1-5-21-3954486152-1987511008-2705091493-1000\...\DealPly) (Version: - ) <==== ATTENTION DealPly (remove only) (HKLM-x32\...\DealPly) (Version: 4.8.6.3 - DealPly Technologies Ltd.) <==== ATTENTION DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden DMUninstaller (HKLM-x32\...\DMUninstaller) (Version: - ) <==== ATTENTION DownQuick (HKLM-x32\...\{546E6D59-032E-4D99-BF90-6646F2529F76}) (Version: 1.0.1 - Tuguu SL) <==== ATTENTION Dropbox (HKU\S-1-5-21-3954486152-1987511008-2705091493-1000\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.) e-Sword (HKLM-x32\...\{294B365B-32EF-49EE-99B3-A00558DC76E5}) (Version: 10.02.0001 - Rick Meyers) Free Download Manager 3.9.3 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.125 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6710.2136 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Hardware Diagnostic Tools (HKLM\...\PC-Doctor for Windows) (Version: 6.0.5247.34 - PC-Doctor, Inc.) Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.3.9512.3162 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.11.0 - Hewlett-Packard) HP Setup (HKLM-x32\...\{17B4760F-334B-475D-829F-1A3E94A6A4E6}) (Version: 1.2.3560.3170 - Hewlett-Packard) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard) HP Update (HKLM-x32\...\{D46D081B-F60E-467E-A7C4-117B70D76731}) (Version: 5.001.000.014 - Hewlett-Packard) Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2017 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.2017 - CyberLink Corp.) Hidden Level Quality Watcher (x32 Version: 1.0.0.0 - Adpeak, Inc.) Hidden <==== ATTENTION LightScribe System Software (HKLM-x32\...\{CC8E94A2-55C7-4460-953C-2A790180578C}) (Version: 1.18.8.1 - LightScribe) Magic ISO Maker v5.5 (build 0281) (HKLM-x32\...\Magic ISO Maker v5.5 (build 0281)) (Version: - ) MagicDisc 2.7.106 (HKLM-x32\...\MagicDisc 2.7.106) (Version: - ) Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.141.11 - McAfee, Inc.) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Live Search Toolbar (HKLM-x32\...\{DF802C05-4660-418c-970C-B988ADB1D316}) (Version: 3.0.566.0 - Microsoft Live Search Toolbar) Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (HKLM-x32\...\{90120000-00B2-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 39.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) Norton Internet Security (HKLM-x32\...\NIS) (Version: 17.9.0.12 - Symantec Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.5 - NVIDIA Corporation) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PictureMover (HKLM-x32\...\{1896E712-2B3D-45eb-BCE9-542742A51032}) (Version: 3.3.1.19 - Hewlett-Packard Company) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3304 - CyberLink Corp.) Power2Go (x32 Version: 6.0.3304 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3503 - CyberLink Corp.) PowerDirector (x32 Version: 7.0.3503 - CyberLink Corp.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 15.0) (Version: 15.0.4 - RealNetworks) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5938 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Recovery Manager (x32 Version: 5.5.2216 - CyberLink Corp.) Hidden Revo Uninstaller Pro 3.0.8 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.8 - VS Revo Group, Ltd.) Roxio Creator DE 10.3 (HKLM-x32\...\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.3 - Roxio) ScorpionSaver Services (HKLM\...\{6E810AB6-F34E-49A3-A93F-9E503660F718}) (Version: 1.0.0.0 - Adpeak, Inc.) <==== ATTENTION Search Protection (HKU\S-1-5-21-3954486152-1987511008-2705091493-1000\...\Search Protection) (Version: 10.9.0.3 - Spigot, Inc.) <==== ATTENTION Software Version Updater (HKLM-x32\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.3.8 - ) <==== ATTENTION SupTab (HKLM-x32\...\SupTab) (Version: 1.1.1.0 - ) <==== ATTENTION SySaver (HKU\S-1-5-21-3954486152-1987511008-2705091493-1000\...\SySaver) (Version: 2 - SySaver) theWord (HKLM-x32\...\The Word) (Version: 4.0.0.1342 - Costas Stergiou) uTorrentControl_v2 Toolbar (HKLM-x32\...\uTorrentControl_v2 Toolbar) (Version: 6.9.0.16 - uTorrentControl_v2) <==== ATTENTION Vid-Saver (HKLM-x32\...\Vid-Saver) (Version: 1.18.149.149 - 215 Apps) <==== ATTENTION WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent) Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Sign-in Assistant (HKLM-x32\...\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinZipper (HKLM-x32\...\WinZipper) (Version: 1.5.95 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION Word Whomp Underground (x32 Version: 2.2.0.95 - WildTangent) Hidden YAC(Yet Another Cleaner!) (HKLM-x32\...\iSafe) (Version: - ELEX DO BRASIL PARTICIPAÇÕES LTDA) <==== ATTENTION ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3954486152-1987511008-2705091493-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\linda\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3954486152-1987511008-2705091493-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\linda\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3954486152-1987511008-2705091493-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\linda\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3954486152-1987511008-2705091493-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\linda\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ==================== Restore Points ========================= 08-07-2015 17:16:42 Windows Update 11-07-2015 18:32:26 Windows Update 15-07-2015 07:51:49 Windows Update 16-07-2015 03:01:27 Windows Update 18-07-2015 03:00:38 Windows Update 21-07-2015 14:03:20 Windows Update 22-07-2015 03:01:00 Windows Update 25-07-2015 16:06:25 Windows Update 29-07-2015 07:39:00 Windows Update 30-07-2015 03:00:29 Windows Update 04-08-2015 13:24:03 Windows Update 05-08-2015 12:21:46 Revo Uninstaller Pro's restore point - Norton Internet Security ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0617FEF8-60FB-4F3D-9DC0-A3C0F308B4DC} - System32\Tasks\spmonitor => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\spmonitor.exe <==== ATTENTION Task: {0A044213-0408-4084-8EFA-E75B6089D272} - System32\Tasks\{A3890CCF-FD6A-4DEF-8D00-C1946C94D340} => pcalua.exe -a "C:\Program Files (x86)\ComcastUI\Desktop Software\bin\kui.exe" -d "C:\Program Files (x86)\ComcastUI\Desktop Software\bin\" Task: {12F808B8-5305-494C-97D6-A4DAF5716B79} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3954486152-1987511008-2705091493-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {1677082E-EC3D-4FF2-A2C4-0AA932392F98} - System32\Tasks\SpeedUpMyPC => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\sump.exe <==== ATTENTION Task: {26654A84-D789-4E0F-ABB1-167A4F16E14E} - System32\Tasks\DealPlyUpdate => C:\Program <==== ATTENTION Task: {35EED554-F8BC-44DB-BAF8-0FC841D57AB8} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe Task: {46ACE528-7155-4CF6-8E3A-34C43EECE5AB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {642CA808-F221-44CF-9CCE-8CFCB6B2671B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {687B475F-71A3-4785-8381-04339BF73D19} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPW10UpgradeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPW10UpgradeReminder.exe [2015-07-24] (Hewlett-Packard) Task: {79E27446-5214-45B7-8228-65B4AEB1D806} - System32\Tasks\PCDRScheduledMaintenance => C:\Program Files\PC-Doctor for Windows\pcdrcui.exe [2009-09-18] (PC-Doctor, Inc.) Task: {9B699AE3-3E9F-4C3C-BC1C-904EB34FF159} - System32\Tasks\AdobeAAMUpdater-1.0-linda-PC-linda => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {9E03F1A3-B2D0-4E42-ADA3-795C8ADD19F0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {A5A5F0F1-24F9-4282-BA10-24ED7F197AB3} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3954486152-1987511008-2705091493-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {AF81FA66-FC17-48E4-A9E6-DE7CEC98C3ED} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-07-21] (Hewlett-Packard) Task: {BCBCFE43-8435-41CA-A4A3-B24E5BBCB8F5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Critical Actions Pending => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {C0A790DB-BBED-4E6F-8336-A04E5C456D7F} - System32\Tasks\HPCeeScheduleForlinda => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard) Task: {CCCF3987-0A3F-4A6D-99CA-C1FE1270FC16} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\linda\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <==== ATTENTION Task: {CEFE10D6-691F-478B-B05E-F3A620BD309B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.) Task: {D5C8F395-6B31-4618-87A3-1E8DF0123D37} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2015-07-29] (Microsoft) Task: {E31C2480-745B-490A-A198-A7CB8724257B} - System32\Tasks\DealPly => C:\Users\linda\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe [2013-03-19] () <==== ATTENTION Task: {E3763F3B-577E-4574-AB4A-18ED8510D0CF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15] (Adobe Systems Incorporated) Task: {E75ACC32-E48D-4CE7-B3AF-9B26892BBF80} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {E851E124-13A4-4892-A0DA-E19C57E39879} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2009-10-20] () Task: {F597EE31-17BA-44A4-BB2E-7B879F73B89D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-07-02] (Avast Software s.r.o.) Task: {F6127F17-FA29-4AFA-BEA2-37EFFDE49D5E} - System32\Tasks\{D70A4945-282D-48D6-9269-FB97726A598F} => pcalua.exe -a "C:\Users\linda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9LQ0ES9Z\Comcast_Desktop_Software_activation3[1].exe" -d C:\Users\linda\Desktop (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForlinda.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\PCDRScheduledMaintenance.job => C:\Program Files\PC-Doctor for Windows\pcdrcui.exe5-fh scripts\monthly.xml Task: C:\Windows\Tasks\SpeedUpMyPC.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\sump.exe <==== ATTENTION Task: C:\Windows\Tasks\spmonitor.job => 0x000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ==================== Loaded Modules (Whitelisted) ============== 2010-01-09 20:17 - 2010-01-09 20:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 01:40 - 2010-01-21 01:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-05-05 07:56 - 2015-06-03 01:41 - 00065696 _____ () C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll 2015-05-05 07:56 - 2015-04-16 21:43 - 00176976 _____ () C:\Program Files (x86)\Elex-tech\YAC\tws\unrar.dll 2015-05-05 07:56 - 2015-04-16 21:43 - 00087744 _____ () C:\Program Files (x86)\Elex-tech\YAC\tws\unacev2.dll 2015-07-02 05:49 - 2015-07-02 05:49 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-07-02 05:49 - 2015-07-02 05:49 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-08-05 12:04 - 2015-08-05 12:04 - 02960384 _____ () C:\Program Files\AVAST Software\Avast\defs\15080501\algo.dll 2015-01-19 06:22 - 2015-01-12 03:13 - 00612528 _____ () C:\Program Files (x86)\WinZipper\sqlite3.dll 2015-05-05 07:56 - 2015-06-03 01:41 - 00179200 _____ () C:\Program Files (x86)\Elex-tech\YAC\libpng.dll 2010-01-09 20:18 - 2010-01-09 20:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 01:34 - 2010-01-21 01:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-07-02 05:49 - 2015-07-02 05:49 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-07-15 08:06 - 2015-07-15 08:06 - 17448624 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3954486152-1987511008-2705091493-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\linda\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 75.75.75.75 - 75.75.76.76 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{4B943158-42DF-45A0-89AB-4010F386E9FC}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE FirewallRules: [{D80EB754-A69D-4CFE-B9DF-5309C00F27DE}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe FirewallRules: [{37E54E3C-6D5D-4323-9CC7-1EEB459B09B8}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{A07D1A2E-C1D3-4135-8F7A-0AD55B7BBBE2}] => (Allow) svchost.exe FirewallRules: [{BFB334DA-0FB9-40E3-93ED-5A9B0E385C7E}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [TCP Query User{B48E078B-47CC-4A82-89EF-1031F40BBA2C}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe FirewallRules: [UDP Query User{409AD874-1278-4A4E-9979-7A04E1EFF812}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe FirewallRules: [{D255AA3F-A684-4151-899C-137089DE2B5E}] => (Allow) C:\Downloads\uTorrent.exe FirewallRules: [{084917B5-4A15-4FEE-884C-D73492C7DFB7}] => (Allow) C:\Downloads\uTorrent.exe FirewallRules: [TCP Query User{0861528B-D443-4218-ADEF-DD054AD0CED7}C:\program files (x86)\free download manager\fdm.exe] => (Block) C:\program files (x86)\free download manager\fdm.exe FirewallRules: [UDP Query User{D331DA08-91F4-4E08-9458-4301DDC2B49A}C:\program files (x86)\free download manager\fdm.exe] => (Block) C:\program files (x86)\free download manager\fdm.exe FirewallRules: [{B9E80AFF-7A0E-4E96-9688-67E5A18735D9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E4F213D4-DAC1-47D4-9B8F-5DFBE99597DF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1D5C682A-5606-4466-87F8-F19FB37A68DD}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe FirewallRules: [{D028A7CE-F4A0-465B-8C92-6908D7C1F91D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/05/2015 12:21:24 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {f494359d-c2ea-4259-a074-688adb60bac3} Error: (08/04/2015 12:52:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 39.0.0.5659, time stamp: 0x55934d06 Faulting module name: mozalloc.dll, version: 39.0.0.5659, time stamp: 0x55933a83 Exception code: 0x80000003 Fault offset: 0x00001aa1 Faulting process id: 0x181c Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (08/04/2015 12:52:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 39.0.0.5659, time stamp: 0x55934d06 Faulting module name: mozalloc.dll, version: 39.0.0.5659, time stamp: 0x55933a83 Exception code: 0x80000003 Fault offset: 0x00001aa1 Faulting process id: 0x1024 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (08/04/2015 12:52:14 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program firefox.exe version 39.0.0.5659 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1150 Start Time: 01d0cc84b508c2c0 Termination Time: 240 Application Path: C:\PROGRA~2\MOZILL~1\firefox.exe Report Id: 86ed4261-3ad1-11e5-8016-7071bc5d5e70 Error: (08/01/2015 12:50:25 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17923, time stamp: 0x55945dbd Faulting module name: ntdll.dll, version: 6.1.7601.18869, time stamp: 0x556366f2 Exception code: 0xc0000005 Fault offset: 0x000000000004ada4 Faulting process id: 0x17ec Faulting application start time: 0xGWXUX.exe0 Faulting application path: GWXUX.exe1 Faulting module path: GWXUX.exe2 Report Id: GWXUX.exe3 Error: (07/31/2015 07:08:05 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 39.0.0.5659, time stamp: 0x55934d06 Faulting module name: mozalloc.dll, version: 39.0.0.5659, time stamp: 0x55933a83 Exception code: 0x80000003 Fault offset: 0x00001aa1 Faulting process id: 0x1a08 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (07/31/2015 07:07:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 39.0.0.5659, time stamp: 0x55934d06 Faulting module name: mozalloc.dll, version: 39.0.0.5659, time stamp: 0x55933a83 Exception code: 0x80000003 Fault offset: 0x00001aa1 Faulting process id: 0x1838 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (07/31/2015 07:07:39 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program firefox.exe version 39.0.0.5659 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1650 Start Time: 01d0cb1c6ff98a20 Termination Time: 282 Application Path: C:\PROGRA~2\MOZILL~1\firefox.exe Report Id: a1643701-377c-11e5-8016-7071bc5d5e70 Error: (07/25/2015 04:16:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 39.0.0.5659, time stamp: 0x55934d06 Faulting module name: mozalloc.dll, version: 39.0.0.5659, time stamp: 0x55933a83 Exception code: 0x80000003 Fault offset: 0x00001aa1 Faulting process id: 0x153c Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (07/20/2015 09:02:08 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17923, time stamp: 0x55945dbd Faulting module name: ntdll.dll, version: 6.1.7601.18869, time stamp: 0x556366f2 Exception code: 0xc0000005 Fault offset: 0x000000000004ada4 Faulting process id: 0x16c8 Faulting application start time: 0xGWXUX.exe0 Faulting application path: GWXUX.exe1 Faulting module path: GWXUX.exe2 Report Id: GWXUX.exe3 System errors: ============= Error: (08/05/2015 12:19:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Windows Update service hung on starting. Error: (08/05/2015 12:14:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect. Error: (07/30/2015 05:58:45 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service. Error: (07/30/2015 03:00:12 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service. Error: (07/24/2015 06:28:09 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service. Error: (07/22/2015 06:29:44 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service. Error: (07/21/2015 06:11:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The YAC Service service terminated unexpectedly. It has done this 3 time(s). Error: (07/21/2015 01:43:02 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service. Error: (07/20/2015 12:01:06 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service. Error: (07/20/2015 09:04:33 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The YAC Service service terminated unexpectedly. It has done this 2 time(s). Microsoft Office: ========================= Error: (08/05/2015 12:21:24 PM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Access is denied. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {f494359d-c2ea-4259-a074-688adb60bac3} Error: (08/04/2015 12:52:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe39.0.0.565955934d06mozalloc.dll39.0.0.565955933a838000000300001aa1181c01d0cc851e239f00C:\PROGRA~2\MOZILL~1\plugin-container.exeC:\PROGRA~2\MOZILL~1\mozalloc.dll8fa99660-3ad1-11e5-8016-7071bc5d5e70 Error: (08/04/2015 12:52:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe39.0.0.565955934d06mozalloc.dll39.0.0.565955933a838000000300001aa1102401d0cc850eca6430C:\PROGRA~2\MOZILL~1\plugin-container.exeC:\PROGRA~2\MOZILL~1\mozalloc.dll8b36abe0-3ad1-11e5-8016-7071bc5d5e70 Error: (08/04/2015 12:52:14 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe39.0.0.5659115001d0cc84b508c2c0240C:\PROGRA~2\MOZILL~1\firefox.exe86ed4261-3ad1-11e5-8016-7071bc5d5e70 Error: (08/01/2015 12:50:25 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: GWXUX.exe6.3.9600.1792355945dbdntdll.dll6.1.7601.18869556366f2c0000005000000000004ada417ec01d0cc8280127360C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dllc914aa60-3875-11e5-8016-7071bc5d5e70 Error: (07/31/2015 07:08:05 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe39.0.0.565955934d06mozalloc.dll39.0.0.565955933a838000000300001aa11a0801d0cb1d7b531930C:\PROGRA~2\MOZILL~1\plugin-container.exeC:\PROGRA~2\MOZILL~1\mozalloc.dllcc14b650-377c-11e5-8016-7071bc5d5e70 Error: (07/31/2015 07:07:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe39.0.0.565955934d06mozalloc.dll39.0.0.565955933a838000000300001aa1183801d0cb1d4d224cc0C:\PROGRA~2\MOZILL~1\plugin-container.exeC:\PROGRA~2\MOZILL~1\mozalloc.dllc3a5bf00-377c-11e5-8016-7071bc5d5e70 Error: (07/31/2015 07:07:39 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe39.0.0.5659165001d0cb1c6ff98a20282C:\PROGRA~2\MOZILL~1\firefox.exea1643701-377c-11e5-8016-7071bc5d5e70 Error: (07/25/2015 04:16:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe39.0.0.565955934d06mozalloc.dll39.0.0.565955933a838000000300001aa1153c01d0c66b771d2f10C:\PROGRA~2\MOZILL~1\plugin-container.exeC:\PROGRA~2\MOZILL~1\mozalloc.dll706a22e0-3312-11e5-8016-7071bc5d5e70 Error: (07/20/2015 09:02:08 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: GWXUX.exe6.3.9600.1792355945dbdntdll.dll6.1.7601.18869556366f2c0000005000000000004ada416c801d0c2f4a5b166e0C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dlle8448d70-2ee7-11e5-a08f-7071bc5d5e70 ==================== Memory info =========================== Processor: AMD Sempron(tm) 140 Processor Percentage of memory in use: 74% Total physical RAM: 1790.49 MB Available physical RAM: 463.47 MB Total Virtual: 3580.98 MB Available Virtual: 1220.64 MB ==================== Drives ================================ Drive c: (COMPAQ) (Fixed) (Total:455.77 GB) (Free:322.08 GB) NTFS Drive d: (FACTORY_IMAGE) (Fixed) (Total:9.89 GB) (Free:1.48 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive f: (OFFICE14) (CDROM) (Total:0.71 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=455.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=9.9 GB) - (Type=07 NTFS) ==================== End of log ============================