Additional scan result of Farbar Recovery Scan Tool (x64) Version:18-04-2016 Ran by Jason (2016-04-22 18:05:47) Running from C:\Users\Jason\Desktop Windows Vista (TM) Home Premium Service Pack 2 (X64) (2009-05-14 10:21:02) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-797596941-2681491629-3159916735-500 - Administrator - Disabled) Guest (S-1-5-21-797596941-2681491629-3159916735-501 - Limited - Enabled) Jason (S-1-5-21-797596941-2681491629-3159916735-1000 - Administrator - Enabled) => C:\Users\Jason ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB} FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - LSI Corporation) Apple Application Support (HKLM-x32\...\{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}) (Version: 1.5.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{8F473675-D702-45F9-8EBC-342B40C17BF5}) (Version: 3.4.0.25 - Apple Inc.) Apple Software Update (HKLM-x32\...\{C41300B9-185D-475E-BFEC-39EF732F19B1}) (Version: 2.1.2.120 - Apple Inc.) ATI Catalyst Install Manager (HKLM\...\{3975CE71-3544-9FBA-56E5-2E9709E348C5}) (Version: 3.0.704.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}) (Version: 2.0.4.0 - Apple Inc.) Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.30.20.0 - Broadcom Corporation) Brother MFC-7840W (HKLM-x32\...\{F7B94AE7-EDB3-43C9-A969-69698F353072}) (Version: 1.00 - Brother) Brother MFL-Pro Suite (HKLM-x32\...\{46E1B1F2-A279-4356-9B17-029F9CC72EAE}) (Version: 1.00 - Brother Industries, Ltd.) Business Contact Manager for Outlook 2007 SP2 (HKLM-x32\...\Business Contact Manager) (Version: 3.0.8619.1 - Microsoft Corporation) Business Contact Manager for Outlook 2007 SP2 (x32 Version: 3.0.8619.1 - Microsoft Corporation) Hidden ccc-core-static (x32 Version: 2008.1231.1149.21141 - ATI) Hidden Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 13.4.500.4 - Citrix Systems, Inc.) Civilization: Call To Power (HKLM-x32\...\Activision_CivCTPUninstallKey) (Version: - ) Command & Conquer 3 (HKLM-x32\...\{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}) (Version: 1.00.0000 - Electronic Arts Inc.) Command & Conquer Tiberian Sun (HKLM-x32\...\Tiberian Sun) (Version: - ) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2326 - CyberLink Corp.) ESU for Microsoft Vista (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Full Tilt Poker.Net (HKLM-x32\...\{E07B7A31-E160-466D-A003-3BB7B8989D52}) (Version: 4.34.4.WIN.FullTilt.NET - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden HotDocs 2008 Professional Edition (HKLM-x32\...\{453EE94F-FC9F-4BFB-A6C7-42969C7423A5}) (Version: 6.60.109 - LexisNexis) HotDocs Player 10.2 (64bit) (HKLM\...\{4C9B8D0E-DF65-4BEF-A564-7E7FA8E31BD7}) (Version: 10.23.4099 - HotDocs Corporation) Hoyle Casino Games 2011 (remove only) (HKLM-x32\...\Hoyle Casino Games 2011) (Version: - ) HP Active Support Library (HKLM-x32\...\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard) HP Customer Experience Enhancements (HKLM-x32\...\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}) (Version: 5.7.0.2664 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.71 - WildTangent) HP Help and Support (HKLM-x32\...\{0054A0F6-00C9-4498-B821-B5C9578F433E}) (Version: 2.1.3.0 - Hewlett-Packard Company) HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 2.1.2328 - Hewlett-Packard) HP MediaSmart Music/Photo/Video (HKLM-x32\...\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 2.1.2425 - Hewlett-Packard) HP MediaSmart SlingPlayer (HKLM-x32\...\HP.MediaSmartSlingPlayer_is1) (Version: 2.1 - Sling Media, Inc.) HP MediaSmart SmartMenu (HKLM\...\{F1568AA6-5982-4AFB-A871-C68E4328BC3B}) (Version: 2.1.7 - Hewlett-Packard) HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.1.1124 - Hewlett-Packard) HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.12.1 - Hewlett-Packard) HP Total Care Advisor (HKLM-x32\...\{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}) (Version: 2.4.5991.2847 - Hewlett-Packard) HP Total Care Setup (HKLM-x32\...\{95A747E0-DF19-46CB-A622-20A0107201BD}) (Version: 1.1.2413.2876 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{787D1A33-A97B-4245-87C0-7174609A540C}) (Version: 5.002.005.003 - Hewlett-Packard) HP User Guides 0126 (HKLM-x32\...\{36E90C09-EB23-4EAC-8B47-12C0CA5DBD3A}) (Version: 1.04.0000 - Hewlett-Packard) HP Wireless Assistant (HKLM-x32\...\{E5E29403-3D25-40C6-892B-F9FEE2A95585}) (Version: 3.50 A6 - Hewlett-Packard) HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6087.22 - IDT) iSEEK AnswerWorks English Runtime (HKLM-x32\...\{9E5A03E3-6246-4920-9630-0527D5DA9B07}) (Version: 009.000.0002 - Vantage Linguistics) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) JMicron JMB38X Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.00.20.07 - JMicron Technology Corp.) Juno Preloader (HKLM-x32\...\{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}) (Version: 1.0.0 - Juno, Inc.) LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1118 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.1118 - CyberLink Corp.) Hidden LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 7.0.6.19846 - LeapFrog) LeapFrog Connect (x32 Version: 7.0.6.19846 - LeapFrog) Hidden LeapFrog LeapPad Explorer Plugin (x32 Version: 7.0.6.19846 - LeapFrog) Hidden LightScribe System Software 1.14.17.1 (HKLM-x32\...\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe) LizardTech DjVu Control (autoinstall) (HKLM-x32\...\DjVu) (Version: - ) magicJack (HKU\S-1-5-21-797596941-2681491629-3159916735-1000\...\magicJack) (Version: 2.0.6073.4252 - magicJack L.P.) magicJack Outlook Add-In 1.0.3.521 (HKU\S-1-5-21-797596941-2681491629-3159916735-1000\...\magicJack Outlook Add-In) (Version: 1.0.3.521 - magicJack) McAfee AntiVirus Plus (HKLM-x32\...\MSC) (Version: 14.0.339 - McAfee, Inc.) McAfee SiteAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.290 - McAfee, Inc.) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft IntelliPoint 7.0 (HKLM\...\{C74A84EC-7C5F-4C36-A4A6-381E516D643B}) (Version: 7.0.260.0 - Microsoft) Microsoft Office 2003 Web Components (HKLM-x32\...\{90A40409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office 2007 Primary Interop Assemblies (HKLM-x32\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Accounting 2009 (HKLM-x32\...\Microsoft Office Accounting 2009) (Version: 4.0.3610.0 - Microsoft Corporation) Microsoft Office Accounting 2009 Equifax Addin (HKLM-x32\...\{C6C148EC-55FB-4FDF-AD4F-ECEA579D040D}) (Version: 4.0.1930.0 - Microsoft Corporation) Microsoft Office Accounting 2009 Fixed Asset Manager (HKLM-x32\...\{53276F5A-85AB-4BEF-BAA2-2490975DC006}) (Version: 4.0.1930.0 - Microsoft Corporation) Microsoft Office Accounting 2009 PayPal Addin (HKLM-x32\...\{DC0C35E4-CD3D-4F12-95BB-7C74D9467BD7}) (Version: 4.0.1930.0 - Microsoft Corporation) Microsoft Office Accounting 2009 Tax Integration Add-in (HKLM-x32\...\{D9AE6BE1-5847-4962-86B0-2A290B7E6C43}) (Version: 4.0.1930.0 - Microsoft Corporation) Microsoft Office Accounting ADP Payroll Addin (HKLM-x32\...\{5FA793A6-0071-42C1-9355-8F69A428C44F}) (Version: 0.0.0.0 - ADP) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Small Business Connectivity Components (HKLM-x32\...\{A939D341-5A04-4E0A-BB55-3E65B386432D}) (Version: 2.0.7024.0 - Microsoft Corporation) Microsoft Office Ultimate 2007 (HKLM-x32\...\ULTIMATER) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 (HKLM-x32\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation) Microsoft SQL Server Native Client (HKLM\...\{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft SQL Server Setup Support Files (English) (HKLM-x32\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{B636C9B9-A3F2-4DCE-ADCC-72E095018385}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 45.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 45.0.2 (x86 en-US)) (Version: 45.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.2 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) muvee Reveal (HKLM-x32\...\{E8020EC7-5DD8-80C9-7237-7B2E9BDA8CC6}) (Version: 7.0.35.7660 - muvee Technologies Pte Ltd) NetZero Preloader (HKLM-x32\...\{352310C3-E46B-42D3-8F32-54721FDD72D9}) (Version: 1.0.0 - NetZero, Inc.) novaPDF v7 (novaPDF 7.4 printer) (HKLM\...\novaPDF v7_is1) (Version: - Softland) Nuance PDF Converter Professional 7 (HKLM\...\{FFAE98FC-4E1A-45BB-ADED-081160A2CBD7}) (Version: 7.20.6187 - Nuance Communications, Inc.) Nuance PDF Converter Professional 7 (HKLM-x32\...\{FFAE98FC-4E1A-45BB-ADED-081160A2CBD7}) (Version: 7.20.6187 - Nuance Communications, Inc.) Online Plug-in (x32 Version: 13.4.500.4 - Citrix Systems, Inc.) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.) PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5615 - CyberLink Corp.) PhotoNow! (x32 Version: 1.1.5615 - CyberLink Corp.) Hidden Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2325 - CyberLink Corp.) Power2Go (x32 Version: 6.0.2325 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2317 - CyberLink Corp.) PowerDirector (x32 Version: 7.0.2317 - CyberLink Corp.) Hidden ProtectSmart Hard Drive Protection (HKLM\...\{2F97CE84-9C33-4631-821B-85EA371EA254}) (Version: 3.10.1.7 - Hewlett-Packard) QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) RealDownloader (x32 Version: 1.3.4 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.4 - RealNetworks) Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden ScanSoft PaperPort 11 (HKLM-x32\...\{7A8FF745-BBC5-482B-88E4-18D3178249A9}) (Version: 11.1.0000 - Nuance Communications, Inc.) Scansoft PDF Professional (x32 Version: - ) Hidden Self-service Plug-in (x32 Version: 3.4.400.49109 - Citrix Systems, Inc.) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Sid Meier's Civilization: Beyond Earth (HKLM-x32\...\Steam App 65980) (Version: - Firaxis Games) Sid Meier's Starships (HKLM-x32\...\Steam App 282210) (Version: - Firaxis Games) SimCity 4 Deluxe (HKLM-x32\...\{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}) (Version: - ) Sins of a Solar Empire (HKU\S-1-5-21-797596941-2681491629-3159916735-1000\...\Sins of a Solar Empire) (Version: - Stardock Entertainment) Sins of a Solar Empire (x32 Version: 1.00.00 - Stardock Entertainment, Inc.) Hidden Skins (x32 Version: 2008.1231.1149.21141 - ATI) Hidden Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.6.8442 - Skype Technologies S.A.) Skype™ 7.21 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.) Slingbox - Watch Your TV Anywhere (HKLM-x32\...\{7B798B31-2F33-4DC8-BDA4-D36488E86636}) (Version: 1.0.0 - Sling Media) SlingPlayer (HKLM-x32\...\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media) SlingPlayer (x32 Version: 1.04.0206 - Sling Media) Hidden SPORE Creature Creator Trial Edition (HKLM-x32\...\{ECEE0279-785F-4CB3-9F28-E69813234BF8}) (Version: 1.00.0000 - Electronic Arts) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated) TurboTax 2009 (HKLM-x32\...\TurboTax 2009) (Version: - Intuit, Inc) TurboTax 2010 (HKLM-x32\...\TurboTax 2010) (Version: - Intuit, Inc) TurboTax 2011 (HKLM-x32\...\TurboTax 2011) (Version: - Intuit, Inc) TurboTax 2012 (HKLM-x32\...\TurboTax 2012) (Version: 2012.0 - Intuit, Inc) TurboTax 2013 (HKLM-x32\...\TurboTax 2013) (Version: 2013.0 - Intuit, Inc) TurboTax 2014 (HKLM-x32\...\TurboTax 2014) (Version: 2014.0 - Intuit, Inc) TurboTax 2015 (HKLM-x32\...\TurboTax 2015) (Version: 2015.0 - Intuit, Inc) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version: - LeapFrog) WealthCounsel Toolbar (HKLM-x32\...\{52BE6460-875A-4E1B-8F3D-ABE17C8B885E}) (Version: 6.2.0 - WealthCounsel, LLC) WealthDocs 6.2 (HKLM-x32\...\WealthDocs 6.2) (Version: - ) WealthDocs Asset Transfer System (HKLM-x32\...\WealthDocs Asset Transfer System) (Version: - ) Westwood Shared Internet Components (HKLM-x32\...\WOLAPI) (Version: - ) WildTangent Games App for HP (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.11.2 - WildTangent) Windows Driver Package - ENE (enecir) HIDClass (09/04/2008 2.6.0.0) (HKLM\...\07B260955637F1FF7587ED2AA87459040DD09BF7) (Version: 09/04/2008 2.6.0.0 - ENE) Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog) Xvid 1.2.1 final uninstall (HKLM-x32\...\Xvid_is1) (Version: 1.2 - Xvid team (Koepi)) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{06B3E595-39E0-4b08-B719-8BCE64A04D70}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{1B5D8432-4AFF-44AB-BC21-656035B0B63D}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{2C2098F9-D471-4806-9759-504F65C4171B}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{4D509C2B-0223-47EB-95A5-CC8E98055F67}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{4D54CA35-5FB1-4e93-905C-84EE9B1FE69B}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{4E2481F7-DFB8-4E85-B51F-B12B1D82A377}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{503AB2B4-5D01-4EF0-9B2B-36E1B9C738A9}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{50DED91B-A330-48BA-B7F4-F48803D63D3F}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{8378295C-C9F5-4364-AA28-AB2A4CEDCD87}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{84CEB33F-E30D-4d7e-9ABA-C6D6D9EDCBF3}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{8578D0FF-563A-4A7C-A3B7-08AC6448C3C8}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{8A202ADA-F14D-4F1B-86F9-8B18EE76E0C1}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{8DB78A29-8734-4d6a-8BF2-B32596905EE9}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{9EC621F9-52A8-4D9F-A8D0-474428DAE4DA}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{C5038B17-D521-4f4b-91C1-62F55A622D25}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{D1B6F1CC-C9DA-47a1-B58A-7BF32EB62CE2}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{DCDABAA3-E17D-4474-954D-E43B1D91F7EB}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{F6B3FF63-D730-4DCE-802D-0FAED25E7B72}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{F846631F-E8E8-4dba-B139-8547D5A3BBEA}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) CustomCLSID: HKU\S-1-5-21-797596941-2681491629-3159916735-1000_Classes\CLSID\{F90E67E0-4489-4546-AD04-26B9AF7DCA87}\localserver32 -> C:\Program Files (x86)\HotDocs 6\Player\HotDocs.exe (HotDocs Limited) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {003A9B84-607B-47C6-940A-D3539C28BB85} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-797596941-2681491629-3159916735-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-08-29] (RealNetworks, Inc.) Task: {03489D12-8235-4785-AF61-7B47C63F7DEB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated) Task: {0F30CE70-70F7-4EA1-A87D-B3444C6F1123} - System32\Tasks\GoogleUpdateTaskMachineUA1cf4addcc16b552 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {1242CD20-2AB5-4D7F-9099-006F7CEBD8BA} - System32\Tasks\GoogleUpdateTaskMachineUA1d0bf672e8aafd0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {36968E65-9A11-4754-9905-16B9A471C5C6} - System32\Tasks\GoogleUpdateTaskMachineUA1d042f224ae54d4 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {4ECA9B9F-0C67-42D3-8A61-0744215C2F36} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-797596941-2681491629-3159916735-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-08-29] (RealNetworks, Inc.) Task: {51A0BC6F-D4C0-40FF-B27F-570354A15A27} - System32\Tasks\Microsoft\Windows\RestartManager\{73475B54-473C-41b2-8751-DFB4CCD49539} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {52CEE8A4-F338-4914-939E-1F7E6142F33B} - System32\Tasks\GoogleUpdateTaskMachineCore1cf907b6b219576 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {67F0E291-654E-47CC-9884-4B3CF46F7E3A} - System32\Tasks\{13CA7A45-B0EB-47E4-A6FD-CB6206F4919D} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.3.0.107/en/abandoninstall?page=tsProgressBar Task: {6D21C875-C919-4406-947A-E9A43FDCEE3F} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard) Task: {99E6E818-0535-4343-8BCA-6605C7C6C82A} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-797596941-2681491629-3159916735-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-08-29] (RealNetworks, Inc.) Task: {9DCEEC5B-63D4-42CC-A33A-EA046423BD12} - System32\Tasks\GoogleUpdateTaskMachineCore1d12fa41c8ed1d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {A17AB464-5849-4934-B241-85B54166DBF3} - System32\Tasks\GoogleUpdateTaskMachineCore1d042f2236f5c94 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {B49EFB7C-56E2-442E-AE82-2267E6B9B6B1} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-797596941-2681491629-3159916735-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-08-29] (RealNetworks, Inc.) Task: {CEC43B6A-93EA-458C-9BD5-1AE8595F3BC4} - System32\Tasks\GoogleUpdateTaskMachineUA1d12fa433ca15d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {D650007F-52FF-43D2-98F8-7377939B959C} - System32\Tasks\GoogleUpdateTaskMachineCore1d0f084f4c588ab => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {DC8E0028-22CE-482D-BC00-C6C2EAB637B6} - System32\Tasks\GoogleUpdateTaskMachineCore1cfecd69afb4a30 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {DF310500-E882-4EB0-B0FA-B2E5496410CA} - System32\Tasks\{588346EC-9E54-4C72-BEF1-EBBF5BF1E552} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-03-01] (Skype Technologies S.A.) Task: {E45A8540-0C04-49C7-ACDB-03D140F2DC4C} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe [2009-06-01] (Microsoft Corporation) Task: {FC725F04-EA36-4E82-8EF9-068B17CA339A} - System32\Tasks\GoogleUpdateTaskMachineCore1cffe16a0ecf00 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf907b6b219576.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cfecd69afb4a30.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cffe16a0ecf00.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d042f2236f5c94.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f084f4c588ab.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12fa41c8ed1d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4addcc16b552.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d042f224ae54d4.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0bf672e8aafd0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d12fa433ca15d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2014-08-12 11:34 - 2014-08-12 11:34 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2009-01-13 11:01 - 2008-12-17 18:11 - 00365952 _____ () C:\Program Files (x86)\SMINST\BLService.exe 2009-01-13 10:52 - 2008-09-15 08:13 - 00241734 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2009-10-04 17:04 - 2005-04-22 14:36 - 00143360 ____N () C:\Windows\system32\BrSNMP64.dll 2008-12-31 06:36 - 2008-12-31 06:36 - 00118272 _____ () C:\Windows\system32\atitmm64.dll 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2009-05-14 04:26 - 2009-05-14 04:26 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll 2008-09-18 11:30 - 2008-09-18 11:30 - 01186816 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Implementation\64\wbocx.ocx 2008-10-29 18:34 - 2008-10-29 18:34 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2009-07-01 15:44 - 2009-07-01 15:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe 2009-01-13 11:01 - 2008-12-17 18:11 - 00132480 _____ () C:\Program Files (x86)\SMINST\STWmiM.dll 2009-01-13 10:52 - 2008-09-15 08:13 - 00028672 _____ () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll 2007-07-12 14:55 - 2007-07-12 14:55 - 01581056 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2007-08-14 14:59 - 2007-08-14 14:59 - 06365184 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2007-07-12 14:55 - 2007-07-12 14:55 - 00131072 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2008-11-18 12:57 - 2008-11-18 12:57 - 00057344 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll 2008-11-18 13:03 - 2008-11-18 13:03 - 00032768 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Content.XmlSerializers.dll 2008-11-18 12:56 - 2008-11-18 12:56 - 00118784 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\ECLibrary.dll 2008-11-18 12:56 - 2008-11-18 12:56 - 00040960 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingServer.dll 2008-11-18 12:56 - 2008-11-18 12:56 - 00005632 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingInterface.dll 2008-11-18 12:56 - 2008-11-18 12:56 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingMessages.dll 2010-03-27 21:26 - 2009-04-11 00:28 - 00368640 _____ () C:\Windows\SysWOW64\msjetoledb40.dll 2008-11-18 12:56 - 2008-11-18 12:56 - 00010240 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingClients.dll 2008-11-18 12:57 - 2008-11-18 12:57 - 00007168 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\RemotingClient.dll 2008-12-25 14:41 - 2008-12-25 14:41 - 00881960 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll 2014-11-24 11:46 - 2014-11-24 11:46 - 00879104 _____ () C:\Program Files (x86)\LeapFrog\LeapFrog Connect\platforms\qwindows.dll 2010-01-10 15:47 - 2010-01-10 15:47 - 00854016 _____ () C:\Windows\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll 2010-01-10 15:47 - 2010-01-10 15:47 - 00471040 _____ () C:\Windows\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll 2011-01-01 18:25 - 2011-01-01 18:25 - 00476520 _____ () C:\Windows\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 16:45 - 2010-10-20 16:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Temp:0574215C [480] AlternateDataStreams: C:\ProgramData\Temp:D95ACC7D [191] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-797596941-2681491629-3159916735-1000\...\comcast.com -> hxxps://www.comcast.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 06:34 - 2006-09-18 15:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-797596941-2681491629-3159916735-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\img26.jpg DNS Servers: 192.168.0.1 - 205.171.3.25 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe FirewallRules: [{96FB22F8-8906-4865-82A0-8CB2007005DA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE FirewallRules: [{6EB60402-7C61-4A96-BCD4-0E475C71EFD7}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe FirewallRules: [{1ABF2154-DCC2-4954-B19A-BF5E63427097}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe FirewallRules: [{8A0EBA82-2FCA-4557-936B-7FCCE84B5928}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe FirewallRules: [{EC811F9A-9559-4E3D-B032-E1A34711E4E5}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe FirewallRules: [{58B4BC3D-CBCE-4E69-8CAF-C295FA903126}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe FirewallRules: [{1E4B8EDC-492F-4805-A06F-389CF838F2BA}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe FirewallRules: [{A46E0754-9778-4C78-913E-C6CBCA2FC1AE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe FirewallRules: [{6F4540F9-5479-4AFB-92AF-8219E2ABC3D5}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe FirewallRules: [{B8DA45B4-B972-4CA2-BA19-2DF996A6FAAE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe FirewallRules: [{94236C00-418E-40D0-8C79-9BAF13C192CF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe FirewallRules: [{7B9302C3-EF01-4BC8-8234-574C4279612C}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe FirewallRules: [TCP Query User{F951CC3C-8623-4BA5-85E1-950D522EB6A2}C:\users\jason\appdata\roaming\mjusbsp\magicjack.exe] => (Allow) C:\users\jason\appdata\roaming\mjusbsp\magicjack.exe FirewallRules: [UDP Query User{A9FEE124-4C81-4488-8B76-05F85F5F34DA}C:\users\jason\appdata\roaming\mjusbsp\magicjack.exe] => (Allow) C:\users\jason\appdata\roaming\mjusbsp\magicjack.exe FirewallRules: [{728B3833-C006-4982-A8DD-352B51F226C4}] => (Allow) C:\Program Files (x86)\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe FirewallRules: [{186203BE-CB98-42D0-A146-B03758C9C4B1}] => (Allow) C:\Program Files (x86)\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe FirewallRules: [{CB3EC452-F459-4D16-8BF4-78790FB33FFD}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QP.exe FirewallRules: [{A4B9B88B-5869-48CE-B023-401A0B432DBE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QPService.exe FirewallRules: [TCP Query User{D7A540B1-4068-4085-BB14-C69322A3768F}C:\users\jason\appdata\local\temp\electronicarts_patcher_000.exe] => (Allow) C:\users\jason\appdata\local\temp\electronicarts_patcher_000.exe FirewallRules: [UDP Query User{830E933A-81DE-49BC-B655-8880786BDD0B}C:\users\jason\appdata\local\temp\electronicarts_patcher_000.exe] => (Allow) C:\users\jason\appdata\local\temp\electronicarts_patcher_000.exe FirewallRules: [{BBF80612-3C8A-4BD6-939D-512760186C59}] => (Allow) C:\Program Files (x86)\Brother\Brmfl07b\FAXRX.exe FirewallRules: [{384F5359-102E-44A4-95A2-CDDA61EC6C6F}] => (Allow) C:\Program Files (x86)\Brother\Brmfl07b\FAXRX.exe FirewallRules: [{A77EE3B5-001C-4B61-9206-6B995CB2D7C1}] => (Allow) LPort=54925 FirewallRules: [{ED00C697-B11D-4A20-B4FD-D7F95E3ACEB2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{03CD1B7C-E6B1-4CAB-BD7D-3B94D1D0B580}C:\westwood\sun\patchget.dat] => (Allow) C:\westwood\sun\patchget.dat FirewallRules: [UDP Query User{D373C6BD-C6AC-4397-BD18-5E4FEFFA9207}C:\westwood\sun\patchget.dat] => (Allow) C:\westwood\sun\patchget.dat FirewallRules: [{E0F7C1B6-C9D1-4A9F-A77B-B5B699420C52}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MNA\McNaSvc.exe FirewallRules: [{A8E4954A-7CD8-4253-8202-8D99F6D995BD}] => (Allow) LPort=80 FirewallRules: [{D4A3EFC9-0A91-498E-B1B7-AC0FE9C7D612}] => (Allow) LPort=80 FirewallRules: [{B1097341-D9D7-409C-B955-DED1A3A4849C}] => (Allow) LPort=80 FirewallRules: [{944D0EDC-1886-460D-8552-C937CFAD39BF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{A63ED61F-86A9-463E-BA66-0C4C1D73FC19}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{427839C0-7AD3-4F1A-8BEE-527EA968BD4A}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdater.exe FirewallRules: [{D5CBF4A0-11AC-44B2-BB55-0D5242A47538}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe FirewallRules: [{FBE3B643-F3E5-44C1-9DD5-DA2A4D37C7A7}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe FirewallRules: [{54393DD4-859C-4083-8A4A-30463EC412DE}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe FirewallRules: [{B39C7E38-86D2-456A-BD1F-B25A0735410B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe FirewallRules: [{4CB4C622-1CCF-4551-B02E-CFFC639D4AE2}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe FirewallRules: [{6E40B334-88E7-4F9E-B718-20DA63F95018}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\empire total war\Empire.exe FirewallRules: [{8E124880-2A27-412E-A336-E0AA89C200A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\empire total war\Empire.exe FirewallRules: [{EB69AC3D-30F7-42EF-AA51-49893C54623E}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe FirewallRules: [{8ED113A8-17F0-45C4-B2B7-4C4DA427B30D}] => (Allow) C:\Program Files (x86)\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe FirewallRules: [{9B585661-4B01-48E3-9400-B2BF8A477A68}] => (Allow) C:\Program Files (x86)\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe FirewallRules: [{7B3701C2-434C-4F4A-B9BF-CB2A0E5251A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\empire total war\Empire.exe FirewallRules: [{8BF5AAB2-D3F0-41DA-AD95-54A3F84ABBC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\empire total war\Empire.exe FirewallRules: [{388362E2-01DD-4ADE-9687-6182A80BF688}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe FirewallRules: [{C1CB1C94-E503-4809-A618-CD2C038CEFD0}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe FirewallRules: [{0E8DE080-0691-4442-8F00-FD9B188B013E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{A01B5C70-56CB-4EC7-94E4-835BEB8AFDD2}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{B113E425-814E-42A1-BE65-E486BD764E5A}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{BD2A0F63-741A-4AEA-9D8A-20DBBAA4A226}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0D208B50-EFBC-43E3-A4A6-DBFF2ED7E5DE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe FirewallRules: [{58627F31-2F9A-454D-8912-0A4423E9E703}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe FirewallRules: [{A700E7C7-D898-4747-81DB-A89BA87E92F4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe FirewallRules: [{52A3B673-1141-418A-B4BC-13CC16ACBA30}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe FirewallRules: [{B60DEDE9-0D7B-44A9-A499-FDB619B30D9F}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{03A8DE1A-A264-4E39-8C5B-460A63E8A4EA}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{FC86EB46-C2C6-4F01-B4A7-009A36AB678F}] => (Allow) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\LeapfrogConnect.exe FirewallRules: [{F64E6700-078D-4E58-BB94-720B14EDD199}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Starships\Starships64.exe FirewallRules: [{CDCE8769-18BE-436D-8832-FACE92FB2C2F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Starships\Starships64.exe FirewallRules: [{A353CAAD-85E2-4C80-81DC-6FE3541A1974}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe FirewallRules: [{BFDB8A3E-42A0-4EC9-9F49-BE2A2200074C}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{885E6B84-CFD1-4C98-998C-C2AEA213D768}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{8B2509CE-B378-4EDD-AA29-44933B3178C3}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{BEA3161F-DB18-4B61-AD83-5859CADCBC47}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{B741F639-BEDB-4846-9C08-79574CBA286E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{330EE8D7-E2F6-4928-81D8-3DB571120812}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E6CD9B55-60E4-41E0-B93B-C845EE9EBB8B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{FAF96744-7D89-437F-A0DE-7C2AA7474E05}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 01-02-2016 08:29:28 Scheduled Checkpoint 06-02-2016 17:39:23 Installed TurboTax 2015 wrapper 06-02-2016 18:01:31 Installed TurboTax 2015 wcoiper 09-02-2016 08:40:44 Scheduled Checkpoint 10-02-2016 20:53:32 Windows Update 08-03-2016 08:42:56 Scheduled Checkpoint 09-03-2016 20:15:28 Windows Update 09-03-2016 20:53:43 Windows Update 10-03-2016 22:04:35 Windows Update 15-03-2016 03:00:32 Windows Update 16-03-2016 08:38:54 Scheduled Checkpoint 18-03-2016 09:21:42 McAfee Vulnerability Scanner 05-04-2016 11:00:33 Scheduled Checkpoint 05-04-2016 11:28:26 Device Driver Package Install: Realtek Smart card readers 06-04-2016 19:41:50 Windows Update 14-04-2016 18:13:30 Windows Update 15-04-2016 19:22:40 Windows Modules Installer 15-04-2016 23:13:20 McAfee Vulnerability Scanner 18-04-2016 08:28:21 Scheduled Checkpoint 20-04-2016 22:25:40 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft 6to4 Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Teredo Tunneling Pseudo-Interface Description: Microsoft Tun Miniport Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunmp Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/22/2016 05:31:10 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/22/2016 05:31:10 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/22/2016 05:29:15 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2016 09:33:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 412139 Error: (04/21/2016 09:33:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 412139 Error: (04/21/2016 09:33:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/21/2016 09:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 410969 Error: (04/21/2016 09:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 410969 Error: (04/21/2016 09:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/21/2016 09:26:58 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6458 System errors: ============= Error: (04/22/2016 05:29:15 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: SRTSP SRTSPX Error: (04/22/2016 05:29:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Norton Internet Security%%3 Error: (04/21/2016 09:38:45 PM) (Source: PlugPlayManager) (EventID: 12) (User: ) Description: The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_3628103C&REV_00\4&d22e54d&0&04E4) disappeared from the system without first being prepared for removal. Error: (04/21/2016 09:38:45 PM) (Source: PlugPlayManager) (EventID: 12) (User: ) Description: The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_3628103C&REV_00\4&d22e54d&0&03E4) disappeared from the system without first being prepared for removal. Error: (04/21/2016 09:38:45 PM) (Source: PlugPlayManager) (EventID: 12) (User: ) Description: The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_3628103C&REV_00\4&d22e54d&0&02E4) disappeared from the system without first being prepared for removal. Error: (04/21/2016 09:38:45 PM) (Source: PlugPlayManager) (EventID: 12) (User: ) Description: The device 'JMB38X SD/MMC Host Controller' (PCI\VEN_197B&DEV_2382&SUBSYS_3628103C&REV_00\4&d22e54d&0&01E4) disappeared from the system without first being prepared for removal. Error: (04/21/2016 09:23:31 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000SENS Error: (04/21/2016 09:21:36 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: SRTSP SRTSPX Error: (04/21/2016 09:21:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Norton Internet Security%%3 Error: (04/21/2016 04:35:50 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {D085A4AB-CAB1-4729-9DF8-FCEEDDBD19E4} CodeIntegrity: =================================== Date: 2015-12-30 21:29:53.948 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-30 21:29:53.946 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-30 21:29:16.239 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-30 21:29:16.151 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-19 20:56:12.923 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-19 20:56:12.921 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-19 20:51:07.790 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-19 20:51:07.778 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-01 15:05:08.545 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-01 15:05:08.423 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\PROGRA~2\McAfee\SITEAD~1\x64\saHook.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU P7550 @ 2.26GHz Percentage of memory in use: 57% Total physical RAM: 4092.25 MB Available physical RAM: 1752.52 MB Total Virtual: 8359.76 MB Available Virtual: 5384.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:453.18 GB) (Free:148.17 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (RECOVERY) (Fixed) (Total:12.58 GB) (Free:1.66 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 2CF04D55) Partition 1: (Active) - (Size=453.2 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=12.6 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================