Additional scan result of Farbar Recovery Scan Tool (x64) Version:09-01-2015 Ran by Ruth (2016-01-10 00:25:35) Running from C:\Users\Ruth\Desktop Windows 7 Ultimate Service Pack 1 (X64) (2015-08-12 02:39:58) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3438633565-1124592229-3206170717-500 - Administrator - Disabled) Guest (S-1-5-21-3438633565-1124592229-3206170717-501 - Limited - Disabled) Ruth (S-1-5-21-3438633565-1124592229-3206170717-1001 - Administrator - Enabled) => C:\Users\Ruth ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton AntiVirus Online (Enabled - Out of date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton AntiVirus Online (Enabled - Out of date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AbiWord 2.8.6 (HKLM-x32\...\AbiWord2) (Version: 2.8.6 - AbiSource Developers) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) Adobe Flash Player 20 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies) AVG 2016 (Version: 16.0.4460 - AVG Technologies) Hidden AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden CenturyLink Installer (HKLM-x32\...\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Easy Photo Scan (HKLM-x32\...\{1A6DED1E-A024-455D-AA82-203D6B3B0CBC}) (Version: 1.00.0006 - Seiko Epson Corporation) Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION) Epson Customer Participation (HKLM\...\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.6.0.0 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM-x32\...\{4B22C430-7EA8-4534-8358-376FD900B953}) (Version: 3.10.0042 - Seiko Epson Corporation) Epson E-Web Print (HKLM-x32\...\{6BF9F374-EC67-4808-A90C-F127DE6D989D}) (Version: 1.23.0000 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-400 Series Printer Uninstall (HKLM\...\EPSON XP-400 Series) (Version: - SEIKO EPSON Corporation) FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.2.2.929 - Foxit Software Inc.) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Norton AntiVirus Online (HKLM-x32\...\NAV) (Version: 22.5.2.15 - Symantec Corporation) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 3.0 - Krzysztof Kowalczyk) VS10Runtimex64 (Version: 1.0.0 - sourcefire) Hidden WebCam SCB-0340N (HKLM-x32\...\{71A51BED-E7D3-11DB-A386-005056C00008}) (Version: 1.00.0000 - Vimicro Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0E28D8C7-9E8E-4DF0-BB57-79F1DA6D0077} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe Task: {147E9A40-684F-4E5D-9822-252792CD64FF} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_20_0_0_228_pepper.exe Task: {17BA8FDA-0DFF-465B-BF5C-FA7B1ED1C49F} - System32\Tasks\{D3D33174-C588-4259-BBD3-9DEEBF9F0DDF} => pcalua.exe -a C:\Users\Ruth\AppData\Local\Temp\Temp1_Samsung_X128_Camera_XP_345200140043.zip\setup.exe Task: {225D6741-A4AA-402F-AF42-3084238DD6A5} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe Task: {3621B44F-DA81-4BEE-810D-B90D21A9C2EF} - System32\Tasks\{608C713B-55F8-40DD-A0D7-AF17ECFD492B} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{71A51BED-E7D3-11DB-A386-005056C00008}\setup.exe" -c -runfromtemp -l0x0009 -removeonly Task: {3D1A73A9-1E69-4163-A143-FBD1608D625A} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe Task: {3E0566C5-1A4E-46DC-BED2-194DF1C884BD} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe Task: {52B876A8-6222-49F3-B7A9-30FDFD1837B7} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\22.5.2.15\WSCStub.exe [2015-07-16] (Symantec Corporation) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {5CC8E2AE-1233-42E3-9E13-98BB6F409EF2} - System32\Tasks\Adobe Flash Player Updater Task: {6A12470E-E6E3-4329-AAF5-F875AAC8ADB8} - System32\Tasks\Opera scheduled Autoupdate 1439350364 => C:\Program Files (x86)\Opera\launcher.exe Task: {BAF7D4B5-8BB6-4840-8DD7-4D5E144816A1} - System32\Tasks\Opera scheduled Autoupdate 1447174457 => C:\Program Files (x86)\Opera\launcher.exe Task: {CC8B3BA8-D4DB-4D92-8A6E-5FA6DFC7E089} - System32\Tasks\UpdaterEX => C:\Users\Ruth\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc Task: {E550D7E0-573E-41F0-98D1-AABE92A41DD0} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_20_0_0_228_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Ruth\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Ruth\Desktop\centurylink.net.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.centurylink.net ==================== Loaded Modules (Whitelisted) ============== 2010-01-30 02:40 - 2010-01-30 02:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-03-24 21:38 - 2010-03-24 21:38 - 08794976 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-03-24 21:17 - 2010-03-24 21:17 - 08794464 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\install.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\DevManagerCore.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\escsvc64.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\LogiDPP.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\LogiDPPApp.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\lvco13311044.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\lvcod64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\LVUI64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\LVUIRC64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wdfcoinstaller01007.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\DevManagerCore.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\LogiDPP.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\LogiDPPApp.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\lvcodec2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\LVUI2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\LVUI2RC.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\lvuvc64.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\tap-tb-0901.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\USBAUDIO.sys:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\abiword-setup-2.8.6.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\abiword-setup-2.8.6.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\epson14494.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\epson14494.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\epson14801.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\epson14801.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\epson14803.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\epson14803.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\epson16912.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\epson16912.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\epson17001.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\epson17001.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\epson17065.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\epson17065.exe:$CmdZnID AlternateDataStreams: C:\Users\Ruth\Downloads\FoxitReader722.0929_enu_Setup.exe:$CmdTcID AlternateDataStreams: C:\Users\Ruth\Downloads\FoxitReader722.0929_enu_Setup.exe:$CmdZnID ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\...\100sexlinks.com -> 100sexlinks.com There are 4788 more sites. ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 19:34 - 2016-01-09 15:23 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3438633565-1124592229-3206170717-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 156.154.70.22 - 156.154.71.22 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: AvgUi => "C:\Program Files (x86)\AVG\Framework\Common\avguix.exe" /fmw.trayonly MSCONFIG\startupreg: COMODO Internet Security => MSCONFIG\startupreg: EEventManager => MSCONFIG\startupreg: EPLTarget => ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{B0CC1F71-8611-4BAF-94E8-11CBEF2F8EF5}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{2DC5783E-3698-47CF-9BFD-D2650A0535D1}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{F3F745E7-F86A-4DD6-976B-0C22F1AE2967}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{6E8FB578-E53E-49FE-9597-B28C7E51272B}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{3F129ACB-02C5-4793-B5B7-1A683D15E95D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{890EF504-970B-469E-85CA-FBE8B9BFD684}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{901C2455-D7C8-409F-B78E-12EB88E4AB4D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{04D47193-5707-4BE5-B76B-8CEA8404F423}] => (Allow) LPort=2869 FirewallRules: [{4C6A4E4E-6341-423C-A139-21F7A8FC7DE1}] => (Allow) LPort=1900 FirewallRules: [{28DA14CB-459C-4A82-A9D3-91A5F0558984}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{80554A0A-DAE5-4F5C-AE57-513D8C871CB0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Restore Points ========================= 15-11-2015 06:29:27 Windows Update 20-11-2015 16:51:25 Restore Operation 25-11-2015 16:47:29 Windows Update 25-11-2015 20:42:19 Restore Operation 25-11-2015 21:24:01 Opera Stable 32.0.1948.38 restore point 25-11-2015 21:26:02 WebCam SCB-0340N restore point 26-11-2015 00:23:33 Restore Operation 26-11-2015 23:39:04 Windows Defender Checkpoint 27-11-2015 07:05:41 Removed Playthru Player 27-11-2015 07:06:42 Removed Playthru Player 27-11-2015 09:35:29 Windows Live Essentials 27-11-2015 09:36:40 Installed DirectX 27-11-2015 09:37:13 Installed DirectX 27-11-2015 09:37:36 Installed DirectX 27-11-2015 09:40:11 WLSetup 27-11-2015 22:00:21 Windows Update 29-11-2015 18:37:49 Removed Visual Studio 2012 x64 Redistributables 29-11-2015 18:39:03 Removed Visual Studio 2012 x86 Redistributables 05-12-2015 02:16:58 Windows Update 08-12-2015 03:41:14 Installed CenturyLink Installer 09-12-2015 05:53:36 Windows Update 13-12-2015 03:31:00 Windows Update 20-12-2015 11:07:53 Scheduled Checkpoint 22-12-2015 02:44:34 Removed service pack backup files 22-12-2015 03:06:49 Restore Operation 22-12-2015 11:30:30 Windows Update 29-12-2015 20:12:24 Scheduled Checkpoint 31-12-2015 08:11:20 Windows Update 02-01-2016 06:45:32 Restore Operation 03-01-2016 23:28:11 Windows Update 04-01-2016 01:38:53 Restore Operation 04-01-2016 07:29:05 Installed CenturyLink Installer 04-01-2016 07:32:46 Installed CenturyLink Installer 04-01-2016 07:39:52 Installed CenturyLink Installer 04-01-2016 07:43:45 Installed CenturyLink Installer 04-01-2016 07:45:37 Removed CenturyLink Installer 04-01-2016 07:50:01 Installed CenturyLink Installer 05-01-2016 01:49:14 Restore Operation 05-01-2016 20:34:39 Windows Update 09-01-2016 03:40:07 Windows Live Essentials 09-01-2016 03:43:07 Installed DirectX 09-01-2016 03:43:43 Installed DirectX 09-01-2016 03:44:04 Installed DirectX 09-01-2016 03:44:57 WLSetup 09-01-2016 06:05:13 Windows Update 09-01-2016 06:27:09 Restore Operation 09-01-2016 08:08:05 Installed CenturyLink Installer 09-01-2016 10:27:42 Restore Operation 09-01-2016 10:38:41 Windows Update 09-01-2016 20:04:07 Norton_Power_Eraser_20160109200350928 09-01-2016 21:17:31 Installed CenturyLink Installer ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/09/2016 03:15:05 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program firefox.exe version 43.0.4.5848 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1c8 Start Time: 01d14b1517506633 Termination Time: 2886 Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Report Id: 41ee9197-b70a-11e5-91db-0013779d2629 Error: (01/09/2016 03:47:11 AM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: Ruth-PC) Description: HRESULT:0x8004FF00 Description:Cannot complete the Microsoft Security Essentials Setup Wizard. Another Windows installer is already running on your computer. Please close the other program or restart your computer, and then try running this wizard again. Error code:0x8004FF00. Error: (01/09/2016 03:41:43 AM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Ruth-PC) Description: Application or service 'Windows Search' could not be shut down. Error: (01/09/2016 03:22:37 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 43.0.4.5848, time stamp: 0x568c88bd Faulting module name: mozglue.dll, version: 43.0.4.5848, time stamp: 0x568c7b16 Exception code: 0x80000003 Fault offset: 0x0000ed44 Faulting process id: 0x2a4 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (01/08/2016 05:09:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 43.0.4.5848, time stamp: 0x568c88bd Faulting module name: mozglue.dll, version: 43.0.4.5848, time stamp: 0x568c7b16 Exception code: 0x80000003 Fault offset: 0x0000ed44 Faulting process id: 0x8e8 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (01/08/2016 05:09:14 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program firefox.exe version 43.0.4.5848 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: bbc Start Time: 01d14a0bf48b59fb Termination Time: 1189 Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Report Id: Error: (01/07/2016 11:14:38 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 43.0.4.5848, time stamp: 0x568c88bd Faulting module name: mozglue.dll, version: 43.0.4.5848, time stamp: 0x568c7b16 Exception code: 0x80000003 Fault offset: 0x0000ed44 Faulting process id: 0xb4c Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (01/07/2016 11:08:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 43.0.4.5848, time stamp: 0x568c88bd Faulting module name: mozglue.dll, version: 43.0.4.5848, time stamp: 0x568c7b16 Exception code: 0x80000003 Fault offset: 0x0000ed44 Faulting process id: 0xcbc Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (01/07/2016 02:07:09 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 43.0.4.5848, time stamp: 0x568c88bd Faulting module name: mozglue.dll, version: 43.0.4.5848, time stamp: 0x568c7b16 Exception code: 0x80000003 Fault offset: 0x0000ed44 Faulting process id: 0xe54 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (01/07/2016 02:07:07 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program firefox.exe version 43.0.4.5848 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: a00 Start Time: 01d1491bb5cceab0 Termination Time: 5263 Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Report Id: e5a971e5-b51d-11e5-b670-0013779d2629 System errors: ============= Error: (01/09/2016 10:57:44 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/09/2016 10:36:59 PM) (Source: DCOM) (EventID: 10016) (User: Ruth-PC) Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Ruth-PCRuthS-1-5-21-3438633565-1124592229-3206170717-1001LocalHost (Using LRPC) Error: (01/09/2016 08:38:25 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/09/2016 08:38:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The ByteFence Security Real-time Protection service failed to start due to the following error: %%2 Error: (01/09/2016 08:38:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The LiveUpdate service failed to start due to the following error: %%2 Error: (01/09/2016 08:38:10 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 22) (User: NT AUTHORITY) Description: The event logging service encountered an error while initializing publishing resources for channel DebugChannel. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well. Error: (01/09/2016 08:38:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The COMODO Internet Security Helper Service service failed to start due to the following error: %%2 Error: (01/09/2016 08:33:33 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: The NPEService service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error: (01/09/2016 08:12:13 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/09/2016 08:12:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The ByteFence Security Real-time Protection service failed to start due to the following error: %%2 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz Percentage of memory in use: 87% Total physical RAM: 766.11 MB Available physical RAM: 97.85 MB Total Virtual: 3587.07 MB Available Virtual: 299.5 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:98.17 GB) (Free:27.61 GB) NTFS Drive f: () (Removable) (Total:3.73 GB) (Free:2.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 44954395) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=98.2 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================