SearchScopes: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.co…q={searchTerms}
2015-07-18 10:36 - 2015-07-18 10:36 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\One System Care
2015-07-18 10:32 - 2015-07-20 11:00 - 00000266 _____ C:\Windows\Tasks\One System CarePeriod.job
2015-07-18 10:32 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\gmsd_us_021010034
2015-07-18 10:32 - 2015-07-18 10:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\gmsd_us_021010034
2015-07-18 10:32 - 2014-08-18 11:51 - 00660792 _____ (VoiceFive, Inc.) C:\Windows\system32\pmls.dll
2015-07-18 10:31 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\OneSystemCare
2015-07-18 10:31 - 2015-07-18 10:32 - 00000000 ____D C:\Program Files\PremierOpinion
2015-07-18 10:31 - 2015-07-18 10:31 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-18 10:31 - 2015-07-18 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
[3936] C:\Program Files\user extensions\Client.exe => process closed successfully.
"HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully.
"HKCR\PROTOCOLS\Handler\linkscanner" => key removed successfully.
blbdrive => Service removed successfully.
IpInIp => Service removed successfully.
NwlnkFlt => Service removed successfully.
NwlnkFwd => Service removed successfully.
taphss6 => Service removed successfully.
C:\Users\Sharon\AppData\Roaming\One System Care => moved successfully.
C:\Windows\Tasks\One System CarePeriod.job => moved successfully.
C:\Program Files\gmsd_us_021010034 => moved successfully.
C:\Users\Sharon\AppData\Local\gmsd_us_021010034 => moved successfully.
C:\Windows\system32\pmls.dll => moved successfully.
C:\Program Files\OneSystemCare => moved successfully.
C:\Program Files\PremierOpinion => moved successfully.
C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47 => moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care => moved successfully.
"C:\Users\Sharon\AppData\Roaming\One System Care" => File/Folder not found.
"C:\Windows\Tasks\One System CarePeriod.job" => File/Folder not found.
"C:\Program Files\gmsd_us_021010034" => File/Folder not found.
"C:\Users\Sharon\AppData\Local\gmsd_us_021010034" => File/Folder not found.
"C:\Windows\system32\pmls.dll" => File/Folder not found.
"C:\Program Files\OneSystemCare" => File/Folder not found.
"C:\Program Files\PremierOpinion" => File/Folder not found.
"C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47" => File/Folder not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care" => File/Folder not found.
C:\Program Files\user extensions\Client.exe => moved successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
Successfully flushed the DNS Resolver Cache.
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
Unable to cancel {4052307A-21EF-413B-99B8-20FB701DBE51}.
{542BF183-F808-4ACA-A712-8004FF3CE4EE} canceled.
1 out of 2 jobs canceled.
EmptyTemp: => 1008.2 MB temporary data Removed.
The system needed a reboot.
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by [removed] at 2015-07-21 04:03:24
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1992874582-3349113656-4066416677-500 - Administrator - Disabled)
Guest (S-1-5-21-1992874582-3349113656-4066416677-501 - Limited - Disabled)
Sharon (S-1-5-21-1992874582-3349113656-4066416677-1001 - Administrator - Enabled) => C:\Users\Sharon
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\…\7-Zip) (Version: - )
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (HKLM\…\ShockwaveFlash) (Version: 9 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Atheros Driver Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros)
Audacity 2.0.3 (HKLM\…\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AVG PC TuneUp 2014 (en-US) (Version: 14.0.1001.519 - AVG) Hidden
AVG PC TuneUp 2014 (HKLM\…\AVG PC TuneUp) (Version: 14.0.1001.519 - AVG)
AVG PC TuneUp 2014 (Version: 14.0.1001.519 - AVG) Hidden
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.07 - Piriform)
Citrix Online Launcher (HKLM\…\{C57F6C71-C365-4AFF-9108-397BBAD6127F}) (Version: 1.0.204 - Citrix)
Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Elementary Education: Content Knowledge Practice Test (HKLM\…\{0AED2370-A4CD-4D5A-A6FA-32DE353DAE4C}) (Version: 2.0 - Educational Testing Service)
Emsisoft Anti-Malware (HKLM\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.)
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version: - )
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Freemake Video Converter version 4.0.1 (HKLM\…\Freemake Video Converter_is1) (Version: 4.0.1 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM\…\Freemake Video Downloader_is1) (Version: 3.5.0 - Ellora Assets Corporation)
FreeScreenSharing (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\FreeScreenSharing) (Version: 0.56.21.0 - Free Conferencing Corporation)
GamesDesktop 025.021010034 (HKLM\…\gmsd_us_021010034_is1) (Version: - GAMESDESKTOP) <==== ATTENTION
GeniusBox 2.0 (HKLM\…\GeniusBox) (Version: 2.0 - GeniusBox 2.0)
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.3.3019 (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\GoToMeeting) (Version: 7.2.3.3019 - CitrixOnline)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2264 - Hewlett-Packard)
HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2269 - Hewlett-Packard)
HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
HP OFFICEJET 6210 Driver Utility (HKLM\…\HP OFFICEJET 6210 Driver Utility_is1) (Version: - Lavians Inc.)
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\…\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\…\{8C6027FD-53DC-446D-BB75-CACD7028A134}) (Version: 4.000.005.005 - Hewlett-Packard)
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
Image Resizer for Windows (HKLM\…\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Image Resizer for Windows (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Itibiti RTC (Version: 0.0.1 - Itibiti Inc) Hidden
LightScribe 1.4.142.1 (Version: 1.4.142.1 - http://www.lightscribe.com)Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{6AF49698-949A-4C89-9B31-041D2CCB5FBD}) (Version: 6.00.050 - muvee Technologies)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: - )
OLYMPUS Master 2 (HKLM\…\{45FCADDB-0B29-457E-83A1-D245C62A716C}) (Version: 1.0.6 - OLYMPUS IMAGING CORP.)
OLYMPUS muvee theaterPack (HKLM\…\{B3282FB8-874B-4054-8356-9EB391A826F9}) (Version: 1.0.4 - OLYMPUS IMAGING CORP.)
OpenOffice.org 3.4.1 (HKLM\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
Python 2.4.3 (HKLM\…\{75E71ADD-042C-4F30-BFAC-A9EC42351313}) (Version: 2.4.3150 - Martin v. Löwis)
QuickTime (HKLM\…\{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}) (Version: 7.1.3.100 - Apple Computer, Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5377 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{938B1CD7-7C60-491E-AA90-1F1888168240}) (Version: 9.0.559 - Roxio)
Skype Click to Call (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 7.1 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Snapfish Media Detector (HKLM\…\{4EF6FDB0-3B11-4820-9860-8E08E9965195}) (Version: 1.7.0.15 - HP Snapfish)
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Status (Version: 82.0.173.000 - Hewlett-Packard) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
TrojanHunter 6.0 (HKLM\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 1.1.9 (HKLM\…\VLC media player) (Version: 1.1.9 - VideoLAN)
WebEx Event Manager for Firefox or Chrome (HKLM\…\{06B5988F-EBA6-4802-9F7B-4FB471291321}) (Version: 28.7.0.15458 - Cisco WebEx LLC)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM\…\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
Youtube Downloader HD v. 2.9.6 (HKLM\…\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)
Zoom (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
==================== Restore Points =========================
05-07-2015 16:42:42 Scheduled Checkpoint
08-07-2015 22:24:40 Scheduled Checkpoint
13-07-2015 03:04:14 Scheduled Checkpoint
16-07-2015 03:01:38 Windows Update
16-07-2015 19:55:08 Scheduled Checkpoint
16-07-2015 20:40:45 zoek.exe restore point
18-07-2015 07:26:24 Scheduled Checkpoint
18-07-2015 13:17:38 Revo Uninstaller's restore point - Knctr
19-07-2015 19:14:19 Scheduled Checkpoint
20-07-2015 19:24:57 Removed AVG 2015
20-07-2015 19:32:23 Removed AVG 2015
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {02B1C58A-086C-4ED9-B993-C6450A1DBC27} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {09F713C9-DD9B-446B-A2F3-0C4F27A5D403} - System32\Tasks\Validate Installation => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {1B6DBECF-3A87-479C-9AEE-97A6A053F36F} - System32\Tasks\HP online update program => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {2406BCAB-604C-46CC-8541-B7A1BE9F6CF2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {2A42CD5F-56F8-4BF2-9DCB-4539B8A920A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {5DCB035D-4B45-4509-A148-84B06314AD4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {63C8F07F-D02D-4EBD-8DBE-2194C65FAA96} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {70150072-3745-4970-92F2-319F581F5B89} - System32\Tasks\One System Care Monitor => C:\Program Files\OneSystemCare\CleanupConsole.exe
Task: {76748A9F-364C-4BA3-A180-A8A9E65E30AC} - System32\Tasks\Real Player online update program => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-10-12] (RealNetworks, Inc.)
Task: {9047B2F4-831E-4E7F-8006-E9C122A2D247} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Sharon => C:\Program Files\Windows Calendar\WinCal.exe [2007-06-26] (Microsoft Corporation)
Task: {AFF35159-F6E9-49C8-8CA7-9669E9B18DCC} - System32\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {C37BA6B1-ADD5-4F04-A7B0-04BEB36E59A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {D19CEAE8-8D50-43AA-BE02-9BD931893253} - System32\Tasks\One System CarePeriod => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {D42CA714-CB4E-4AA5-BC29-026CAF953660} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {D5B4D35F-5815-451D-9D4A-CA951A9A7186} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd)
Task: {DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files\user extensions\client.exe" <==== ATTENTION
Task: {E29A3170-0CD7-46E7-8DD5-DAC5DB3B337A} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} - System32\Tasks\One System Care Run Delay => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {EED84F28-F38A-4C31-8D42-E093B56E74A5} - System32\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {F49EF02D-3499-4122-A306-8768A7A6322E} - System32\Tasks\Check Updates => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {F9011493-B85D-4B2F-BD39-CDF7FE8536A8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {FA63882F-4A5A-4C97-9855-5D7FA1F9709A} - System32\Tasks\{3092C782-E801-4022-8631-A592DFCCADB7} => pcalua.exe -a "C:\Program Files\QuickTime\QTSystem\QuickTime.cpl" -c @0,0x63737064
Task: {FA71853D-E21F-45D1-A4BB-7D16CF8065F6} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2015-07-21 03:54 - 2015-07-21 03:54 - 00076800 _____ () C:\Program Files\user extensions\Client.exe
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\Pictures\p.3 joy.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: emsisoft anti-malware => "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60
MSCONFIG\startupreg: FreeScreenSharing => "C:\Users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe"
MSCONFIG\startupreg: Google Update => "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: THGuard => "C:\Program Files\TrojanHunter\THGuard.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{C39C9369-DF78-4BA3-B71E-AAEBCCC33157}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{E6281A08-83AE-4E62-8A1A-2C189B8D1BE7}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{21C042E9-8F4D-4046-980E-4F45283AC8F2}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{61D8597E-437D-43DD-89CC-62F487F13081}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{CFE6DE30-FE46-4C60-B0B7-09C12C3214F0}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B82921CB-E57D-4E9E-AADF-71E261A9A6FC}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{9434D6F6-9325-449C-83A6-688A78CD132F}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{5CDBFFA3-A48D-4445-88DC-6D5364623797}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3EF2AD33-05C0-4EFB-8F08-EC2B6BBC3FE7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C160F25F-0B64-4732-8263-97D07C2E73EB}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0C16FA18-D5B1-4409-ACDA-1C3308C7BD9D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{4839C1AC-5CD7-4C77-87DF-1A41AE07EE0D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{4F4D0146-ADF9-4BA9-B769-B9BE6A194012}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
FirewallRules: [{976E81F9-33D6-45A9-905C-63E8E6B78923}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/21/2015 03:52:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/21/2015 03:52:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/19/2015 04:15:47 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/19/2015 04:15:47 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/19/2015 04:14:34 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (2592) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
Error: (07/18/2015 01:17:37 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005.
This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {b3eb9576-9865-4ecc-9a52-be690a9893e7}
Error: (07/18/2015 10:32:43 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"1".
Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/18/2015 10:32:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"1".
Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/18/2015 10:32:21 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"1".
Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/18/2015 09:28:59 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
System errors:
=============
Error: (07/21/2015 12:06:00 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 11, function 0.
Please contact your system vendor for technical assistance.
Error: (07/21/2015 12:06:00 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 9, function 0.
Please contact your system vendor for technical assistance.
Error: (07/20/2015 10:58:09 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Group Policy Client
Error: (07/20/2015 09:23:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt
Error: (07/20/2015 09:23:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
Error: (07/20/2015 09:21:32 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 11, function 0.
Please contact your system vendor for technical assistance.
Error: (07/20/2015 09:21:32 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 9, function 0.
Please contact your system vendor for technical assistance.
Error: (07/20/2015 09:17:25 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {022105BD-948A-40C9-AB42-A3300DDF097F}
Error: (07/19/2015 04:12:53 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:10:36 AM on 7/19/2015 was unexpected.
Error: (07/18/2015 09:27:58 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt
Microsoft Office:
=========================
Error: (04/19/2015 10:43:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20499 seconds with 120 seconds of active time. This session ended with a crash.
Error: (04/17/2015 10:53:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2093 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/12/2014 08:49:26 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 516 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/05/2012 11:47:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 322286 seconds with 720 seconds of active time. This session ended with a crash.
CodeIntegrity Errors:
===================================
Date: 2015-07-20 19:27:23.967
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:23.920
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:23.889
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:23.842
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:19.653
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:19.575
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:19.528
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:19.482
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:19.079
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgmfx86.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-20 19:27:19.017
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgmfx86.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+
Percentage of memory in use: 54%
Total physical RAM: 1917.94 MB
Available physical RAM: 865.2 MB
Total Virtual: 4053.84 MB
Available Virtual: 2503.35 MB
==================== Drives ================================
Drive c: (COMPAQ) (Fixed) (Total:140.67 GB) (Free:91.6 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Recovery) (Fixed) (Total:8.38 GB) (Free:1.01 GB) NTFS ==>[system with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=140.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=8.4 GB) - (Type=07 NTFS)
==================== End of log ============================