Ran by [removed] (2015-09-21 14:53:26)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (X64) (2013-12-13 23:25:29)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1679494073-3026066304-2182815410-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1679494073-3026066304-2182815410-501 - Administrator - Disabled)
HomeGroupUser$ (S-1-5-21-1679494073-3026066304-2182815410-1089 - Limited - Enabled)
Patti (S-1-5-21-1679494073-3026066304-2182815410-1001 - Administrator - Enabled) => C:\Users\Patti
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.6 - Atheros Communications Inc.)
Auslogics Duplicate File Finder (HKLM-x32\…\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 3.4.2.0 - Auslogics Labs Pty Ltd)
CCleaner (HKLM\…\CCleaner) (Version: 4.19 - Piriform)
Chromium (HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Chromium) (Version: 46.0.2480.0 - Chromium)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Duplicate File Finder (HKLM-x32\…\{1041487C-12E6-47FE-B83A-E9891782C8FE}}_is1) (Version: 6.1.0.0 - Ashisoft)
GIMP 2.6.10 (HKLM-x32\…\WinGimp-2.0_is1) (Version: 2.6.10 - The GIMP Team)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 45.0.2454.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\…\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Hallmark Card Studio 2013 (HKLM-x32\…\{A6E08FBC-FC99-4CEE-B645-83A42107BE89}) (Version: 14.0.0.28 - Creative Home)
Hallmark Card Studio 2013 Bonus Pack (HKLM-x32\…\{2339C775-C7EA-4103-9A82-E12EB67FA2A3}) (Version: 1.0.0.1 - Creative Home)
HP Photosmart 6520 series Basic Device Software (HKLM\…\{1151BCF8-3246-4E34-9C17-22E66318C41C}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3345 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{EDBA2433-0910-4C72-8C5B-8FEDAE3EF18E}) (Version: 3.5.34.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{8e41467d-297e-496d-8b0f-e771b6c87c06}) (Version: 16.11.0 - Intel Corporation)
Java 7 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Macrium Reflect Free Edition (HKLM\…\MacriumReflect) (Version: 5.2 - Paramount Software (UK) Ltd.)
Macrium Reflect Free Edition (Version: 5.2.6474 - Paramount Software (UK) Ltd.) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microfast PC (HKLM-x32\…\Microfast PC 1.0.14) (Version: 1.0.14 - Microfast PC)
Microfast PC (x32 Version: 1.0.14 - Microfast PC) Hidden
Microsoft Baseline Security Analyzer 2.3 (HKLM\…\{D8D25854-D7F0-45C5-8702-D650A5A23E21}) (Version: 2.3.2208 - Microsoft Corporation)
Microsoft Office (HKLM-x32\…\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Mozilla Firefox 40.0.3 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
NETGEAR Genie (HKLM-x32\…\NETGEAR Genie) (Version: 2.3.1.13 - NETGEAR Inc.)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6794 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Kies3 (HKLM-x32\…\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.9 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14083.9 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Search Provided by Yahoo (HKLM-x32\…\Wincy) (Version: - Wincy)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
ShieldSoft (HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\ShieldSoft) (Version: 1.0 - ShieldSoft)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SpywareBlaster 5.0 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
SUABnR (HKLM-x32\…\InstallShield_{2485354C-6B65-4978-BB91-CCE61442377B}) (Version: 1.1.0.13103_1 - Samsung Electronics Co., Ltd.)
SUABnR (x32 Version: 1.1.0.13103_1 - Samsung Electronics Co., Ltd.) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.21 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
TOSHIBA Application Installer (HKLM-x32\…\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.4 - TOSHIBA)
Toshiba Book Place (HKLM-x32\…\{24B45620-22B6-4E4A-B836-FF30A0B0404E}) (Version: 3.1.9534 - K-NFB Reading Technology, Inc.)
TOSHIBA Desktop Assist (HKLM\…\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\…\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\…\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.00.6625.6402 - Toshiba Corporation)
TOSHIBA HDD Accelerator (HKLM\…\{DB4D9937-0B14-4EF1-BF9A-BB7E3B9DCB04}) (Version: 1.1.0001 - Toshiba Corporation)
TOSHIBA HDD Protection (HKLM\…\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.5.0002.64002 - Toshiba Corporation)
TOSHIBA Password Utility (HKLM-x32\…\{B1786E63-2127-42C9-95A3-146E5F727BF1}) (Version: v1.0.0.9 - TOSHIBA Corporation)
TOSHIBA PC Health Monitor (HKLM\…\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation)
TOSHIBA Quality Application (HKLM-x32\…\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.8 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.2.0.54043005 - Toshiba Corporation)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\…\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.2.8.0 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\…\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\…\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0032 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\…\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.00.0002.32002 - Toshiba Corporation)
TOSHIBA User's Guide (HKLM-x32\…\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA VIDEO PLAYER (HKLM\…\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102 - Toshiba Corporation)
TOSHIBARegistration (HKLM-x32\…\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA)
Verizon Wireless Software Upgrade Assistant - Samsung(ar) (HKLM-x32\…\{A3070098-A41D-42D9-B6D3-2EF15285E719}) (Version: 2.14.0605 - Samsung Electronics Co., Ltd.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\…\{B5300E76-AA13-4542-8E0E-776A280FE47E}) (Version: 2.14.0503 - Samsung Electronics Co., Ltd.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
05-09-2015 14:09:03 Scheduled Checkpoint
09-09-2015 03:37:46 Windows Update
16-09-2015 06:24:10 Scheduled Checkpoint
19-09-2015 14:30:09 Chrome Cleanup Tool
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 09:25 - 2013-08-22 09:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0C004A94-BE6C-42A7-8829-7DC8A5914C88} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {1322A334-23B8-4025-B844-79E5B7373637} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\SymErr.exe
Task: {24FF6BD8-140A-4A03-ACB5-A45AA83574CE} - System32\Tasks\UpdateTask => C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE [2015-09-16] ()
Task: {6C7E3192-0929-4723-9D7C-F60721D64F4C} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation)
Task: {6F2AE581-BBB6-4CE0-AAA1-813917B1391B} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-11] (Adobe Systems Incorporated)
Task: {782654FD-470E-4CA7-9167-1CF8B389CCCF} - System32\Tasks\Microfast_LogOn => C:\Program Files (x86)\Microfast PC\MicrofastPC.exe [2015-08-19] ()
Task: {7C815E78-14E6-4319-A63E-89BDDFC5FD5A} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\SymErr.exe
Task: {81BB484E-4339-4FBB-B68E-44CFE92F501C} - System32\Tasks\Microfast_Protect => C:\Program Files (x86)\Microfast PC\chconf.exe [2015-08-19] (Microsoft)
Task: {979026BC-23F4-4FA6-9421-3F3D7EF5B92E} - System32\Tasks\HP AR Program Upload - 7635039faa2847ceb8b980b869b48daee0ddc6a36cfb4ac79db1bdb464ef6e0f => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {9A5C215A-3337-4F37-B83D-763085D523BA} - \Optimizer Pro Schedule -> No File <==== ATTENTION
Task: {9AB7EFC1-61B5-4B0E-AC7F-FFE1481DA3A2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {AC55050F-89CA-422D-B9C4-D567D3AA93CA} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-28] (Synaptics Incorporated)
Task: {B3F91BD3-65D2-4705-95D6-8936ACF6A86A} - System32\Tasks\pcreg => C:\Program Files\pcmax\service.exe [2014-05-29] () <==== ATTENTION
Task: {B8F976AF-A6E2-45D6-9044-4F9B576955DF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {BC9AE2BC-D19D-421C-B21E-C3A1849558D8} - System32\Tasks\HP AR Program Upload - bf1cf2500a5345929d13fd404a9b27d88489c6c3333248cfba01ff6f21f63d49 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {DD0C1FC2-90F8-4319-BA71-1A55EAF2CE54} - System32\Tasks\Microfast_Daily => C:\Program Files (x86)\Microfast PC\MicrofastPC.exe [2015-08-19] ()
Task: {E12E4098-B1EF-4011-A581-0B2E12F6BA37} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {E71AE23B-4D7C-4A65-889D-E0F83F506D42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-29] (Piriform Ltd)
Task: {F05ABC77-4238-43A5-A901-C5C7BA5908B0} - System32\Tasks\Unimioanrruo => C:\ProgramData\Unimioanrruo\1.0.5.1\mnuanvou.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microfast_Protect.job => C:\Program Files (x86)\Microfast PC\chconf.exe
Task: C:\WINDOWS\Tasks\UpdateTask.job => C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE
==================== Loaded Modules (Whitelisted) ==============
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-09-11 20:39 - 2015-09-02 15:31 - 00825344 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.dll
2015-09-11 20:39 - 2015-09-02 15:28 - 00083456 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\ShieldsoftService.exe
2015-09-11 20:39 - 2015-09-01 14:45 - 00423424 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldui.exe
2015-09-11 20:39 - 2015-09-02 15:31 - 00081408 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.exe
2013-03-24 23:35 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-09-11 20:39 - 2015-09-02 15:29 - 00472576 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
AlternateDataStreams: C:\Users\Patti\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\Patti\SkyDrive (2).old:ms-properties
AlternateDataStreams: C:\Users\Patti\SkyDrive (3).old:ms-properties
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\100sexlinks.com -> 100sexlinks.com
There are 6052 more restricted sites.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Patti\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 0) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\…\StartupApproved\StartupFolder: => "Event Planner Reminder.lnk"
HKLM\…\StartupApproved\Run: => "TecoResident"
HKLM\…\StartupApproved\Run: => "TSleepSrv"
HKLM\…\StartupApproved\Run: => "SRS Premium Sound 3D"
HKLM\…\StartupApproved\Run: => "TCrdMain"
HKLM\…\StartupApproved\Run: => "ThpSrv"
HKLM\…\StartupApproved\Run: => "TODDMain"
HKLM\…\StartupApproved\Run: => "TosWaitSrv"
HKLM\…\StartupApproved\Run32: => "HP Software Update"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\StartupApproved\StartupFolder: => "OneNote 2010 Screen Clipper and Launcher.lnk"
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\StartupApproved\Run: => "NETGEARGenie"
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\StartupApproved\Run: => "HP Photosmart 6520 series (NET)"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{9FFE2667-5136-4317-B0EC-2C6722F77EB3}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{02211E39-61A5-4178-9275-9517C6BC7B34}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{446CAFC8-EC16-452D-AAC2-3936E313AEF3}] => (Allow) LPort=1900
FirewallRules: [{20FA5F22-8B6C-452A-BBD0-FC725A27FDFF}] => (Allow) LPort=2869
FirewallRules: [{0BF184D3-F71F-4356-B609-76D3C72C47EB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [TCP Query User{1006214B-9A9C-41CE-A26C-CC103DEA4BC0}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{FB36FC0C-7FA3-409A-98F6-765AF63D9279}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{327A27A7-E181-46CF-A288-2B61ED86218C}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS55A5\HPDiagnosticCoreUI.exe
FirewallRules: [{ECB2B2AC-B85F-4141-9847-62C2A81A80C2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS55A5\HPDiagnosticCoreUI.exe
FirewallRules: [{239E6EAD-9912-4C10-9948-79149E6E0BE2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3AA6\HPDiagnosticCoreUI.exe
FirewallRules: [{D790FC45-EB95-4411-80E9-35DAD32363A0}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3AA6\HPDiagnosticCoreUI.exe
FirewallRules: [{02825BE2-0AD8-4996-99C5-8D620AD779D4}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS51A1\HPDiagnosticCoreUI.exe
FirewallRules: [{4F1DB23F-66D8-4C2C-A930-02C28177224D}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS51A1\HPDiagnosticCoreUI.exe
FirewallRules: [{E3B706F5-490F-4E9D-BB42-C49B908C194E}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0E79\HPDiagnosticCoreUI.exe
FirewallRules: [{C6060188-A7F3-453F-8794-4949AEE237B0}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0E79\HPDiagnosticCoreUI.exe
FirewallRules: [{CD657239-4B1D-4856-8198-DF0FE68F65A7}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6367\HPDiagnosticCoreUI.exe
FirewallRules: [{001C58D6-C527-4B7B-9BB4-ED35F572DB9C}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6367\HPDiagnosticCoreUI.exe
FirewallRules: [{61D25BF1-C1B9-41DD-B5A0-B163E21D5255}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4D48\HPDiagnosticCoreUI.exe
FirewallRules: [{240839EE-E376-4421-B79E-0048E0827A56}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4D48\HPDiagnosticCoreUI.exe
FirewallRules: [{09052382-D613-40D2-BAD3-0A933AACB434}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS606D\hppiw.exe
FirewallRules: [{D6514A71-15C7-4129-8645-99A3958DD4F2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS606D\hppiw.exe
FirewallRules: [{7BE6601A-D077-470A-AEBD-55E9CAC97730}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\DeviceSetup.exe
FirewallRules: [{D68E4DD4-4F9C-42ED-9CE0-B4FFCBF45907}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{A1CA6C84-93FF-4AAF-B674-33AE08051CC2}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{B6E9BD0B-7E1C-4F93-B4F1-D81F5EEB7B53}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS741C\HPDiagnosticCoreUI.exe
FirewallRules: [{12821D79-548F-4FDC-81A9-AA4F2E3D5F41}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS741C\HPDiagnosticCoreUI.exe
FirewallRules: [{AFBC6597-504C-4559-B562-189C3713AB08}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS251A\HPDiagnosticCoreUI.exe
FirewallRules: [{31B7196C-7D82-4CFB-BD8F-AFF68DA0316A}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS251A\HPDiagnosticCoreUI.exe
FirewallRules: [{4989B835-BBCA-48D2-A026-C9A9E4B0248C}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3406\HPDiagnosticCoreUI.exe
FirewallRules: [{C3B3F610-EEE2-429E-A6CC-30D48259DC68}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3406\HPDiagnosticCoreUI.exe
FirewallRules: [{2DA94F4D-F2A3-456D-B292-C1772D01207B}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4800\HPDiagnosticCoreUI.exe
FirewallRules: [{D50FA04B-F6A8-4697-A5D0-40535B627D98}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4800\HPDiagnosticCoreUI.exe
FirewallRules: [{C04183A0-4CD9-47D1-84F4-D7298B60CA0A}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS483E\HPDiagnosticCoreUI.exe
FirewallRules: [{85BECF09-DA39-4737-8CDC-9967F8C21512}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS483E\HPDiagnosticCoreUI.exe
FirewallRules: [{278182CD-4DC9-4F38-AFD7-76CC9C5F9CDE}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5009\HPDiagnosticCoreUI.exe
FirewallRules: [{82BEB5DE-47E1-4359-8FB9-93CB65E3BD4F}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5009\HPDiagnosticCoreUI.exe
FirewallRules: [{ABA33D4F-C44D-4B37-9D34-BFBDB00F8630}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6A79\HPDiagnosticCoreUI.exe
FirewallRules: [{9DF081B0-5A8D-4078-BAEA-793AF2AEF2EB}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6A79\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{0A5F966C-CC94-41E6-B407-C8058FBA67FF}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{46BB4DA2-0113-40BE-9A48-A2D61E697BDB}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{A75B6F88-F1BB-4241-B1D2-C6FE8DB30008}] => (Allow) C:\Users\Patti\AppData\Local\Temp\n5270\speedmaxZS_1605-d640b376.exe
FirewallRules: [{B5805387-0A36-440D-B96C-A7956A4249EE}] => (Allow) C:\Users\Patti\AppData\Local\Temp\speedmax_15374.exe
FirewallRules: [{61C113E4-7600-4E84-9CC4-6A30627A09B3}] => (Allow) C:\Users\Patti\AppData\Local\Temp\updater_146472.exe
FirewallRules: [{C46E3AD1-F150-4BB9-95E3-A71A0A6FE6D9}] => (Allow) c:\program files\pcmax\pcmax.exe
FirewallRules: [{4367A904-9BDC-48D9-9D20-103901850AC9}] => (Allow) c:\program files\pcmax\pcmax.exe
FirewallRules: [{39A79686-72DB-4805-8177-C7DB4412A822}] => (Allow) c:\program files\pcmax\service.exe
FirewallRules: [{22D48403-E286-4BC9-9102-9A2681FE24CD}] => (Allow) c:\program files\pcmax\service.exe
FirewallRules: [{4AD53368-7FB6-4C5A-9B07-A62705493699}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55720.exe
FirewallRules: [{175B321D-9740-4C06-9030-B9BB308C29F1}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55720.exe
FirewallRules: [{CCF0EA46-F48D-44DA-B799-FDA04BD1AE5D}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55428.exe
FirewallRules: [{3C36CF10-2FDE-41BC-933D-FEEC6F1CDB5B}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55428.exe
FirewallRules: [{39EB686F-2A0A-4707-AF9A-2462D657B1AC}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{D2436DEF-46A2-41E4-83A1-DC7B56D79795}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{F52DFA7A-AC01-4F13-A7D5-3C748888975C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{4B9F8327-2C72-4FB7-8B53-D8CC9922A3B2}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{D9BB7A29-4000-4226-AD3B-CF0A5424C7DB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{4992FC9D-747B-4BAC-972A-1945D53B25E1}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS15F8\HPDiagnosticCoreUI.exe
FirewallRules: [{24D78248-EA3F-4972-82F4-AD6894E73E82}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS15F8\HPDiagnosticCoreUI.exe
FirewallRules: [{06D14F67-F1B3-4499-A172-69A865D06F43}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS002D\HPDiagnosticCoreUI.exe
FirewallRules: [{CC50A56F-70BB-4722-913E-C981747091EE}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS002D\HPDiagnosticCoreUI.exe
FirewallRules: [{6070F7D3-9311-4AC5-96C3-957BD25F17F5}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS007E\HPDiagnosticCoreUI.exe
FirewallRules: [{4FBC4404-766B-4663-B1CF-F6DBCDB8D1D9}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS007E\HPDiagnosticCoreUI.exe
FirewallRules: [{A591AEC1-2B7B-4129-B095-482AB20B4006}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS015C\HPDiagnosticCoreUI.exe
FirewallRules: [{7840A9CE-1E5B-46DA-8AEF-ACC87E48CD1B}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS015C\HPDiagnosticCoreUI.exe
FirewallRules: [{ADA7F9D2-29A5-490F-A782-DD22A48A8015}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS28A0\HPDiagnosticCoreUI.exe
FirewallRules: [{63ADD7C2-A412-4B67-B99F-EF13B14CCE0A}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS28A0\HPDiagnosticCoreUI.exe
FirewallRules: [{B3C8CAEB-DFFC-4561-8607-8EEA3FF29960}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5C45\HPDiagnosticCoreUI.exe
FirewallRules: [{153BDD50-E308-4694-BEFF-5FAFA018D7F7}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5C45\HPDiagnosticCoreUI.exe
FirewallRules: [{AB08D670-0837-4299-BAB5-D85BF8C1F7E2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS48A5\HPDiagnosticCoreUI.exe
FirewallRules: [{ED030D6E-C4B0-4BF8-9B77-ED943BC428F5}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS48A5\HPDiagnosticCoreUI.exe
FirewallRules: [{D92B3D85-DF50-41C2-B14C-9F2551B095BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C6499CDE-A177-4805-96D5-F458B6483848}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{E93ABC9A-4963-4988-ACD6-9AF657774A17}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{1EC0FF29-84DE-4156-9C70-5032A1B7B411}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{46E16B45-1F73-4B55-9BA5-288C91A6E012}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3124\HPDiagnosticCoreUI.exe
FirewallRules: [{D20391A3-AC99-4193-82CA-AEAAF0CFFFFC}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3124\HPDiagnosticCoreUI.exe
FirewallRules: [{67031B83-DE4D-427C-8DE9-ECE061BC2935}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS315B\HPDiagnosticCoreUI.exe
FirewallRules: [{1A89905F-9900-48FB-B4BC-C4C0AF1EFF06}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS315B\HPDiagnosticCoreUI.exe
FirewallRules: [{8AC5F686-CA29-468D-AF46-CCB11B334BF3}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS32A2\HPDiagnosticCoreUI.exe
FirewallRules: [{4D50AF72-4BAB-4C72-9DA1-53E707F22780}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS32A2\HPDiagnosticCoreUI.exe
FirewallRules: [{4DC6CDEF-A81B-48A3-97FC-ADCFD8FA0450}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS218B\HPDiagnosticCoreUI.exe
FirewallRules: [{425A582C-6C31-450C-9776-E5B3E3F82457}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS218B\HPDiagnosticCoreUI.exe
FirewallRules: [{18648448-F9BE-495D-8899-C5A132E211A6}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0B81\HPDiagnosticCoreUI.exe
FirewallRules: [{06FF5FF3-5683-43C9-B9CB-D242CFDEED20}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0B81\HPDiagnosticCoreUI.exe
FirewallRules: [{3A59A446-AEA5-461A-8F95-B426A90A6486}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0BC9\HPDiagnosticCoreUI.exe
FirewallRules: [{C0AD9B1B-97AF-439E-9FFA-FEF7EB155D92}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0BC9\HPDiagnosticCoreUI.exe
FirewallRules: [{730815A7-6CAA-42B6-B18A-CC74B7D146F2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55715.exe
FirewallRules: [{6C47E9E8-AF3A-494E-A8DE-D95305484568}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55715.exe
FirewallRules: [{23D41958-B4C5-426C-8948-2E78CCAFFE04}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{5D1FC8B4-E58A-4154-ADE5-BBFF438965A1}] => (Allow) C:\Users\Patti\AppData\Local\Chromium\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device
Description: TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: TOSHIBA
Service: TVALZ
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/21/2015 02:51:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.
Error: (09/21/2015 01:50:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_DeviceAssociationService, version: 6.3.9600.17415, time stamp: 0x54504177
Faulting module name: ntdll.dll, version: 6.3.9600.17936, time stamp: 0x55a68e0c
Exception code: 0xc0000374
Fault offset: 0x00000000000f1280
Faulting process id: 0x1cc
Faulting application start time: 0xsvchost.exe_DeviceAssociationService0
Faulting application path: svchost.exe_DeviceAssociationService1
Faulting module path: svchost.exe_DeviceAssociationService2
Report Id: svchost.exe_DeviceAssociationService3
Faulting package full name: svchost.exe_DeviceAssociationService4
Faulting package-relative application ID: svchost.exe_DeviceAssociationService5
Error: (09/21/2015 01:43:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: setup.exe_unknown, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0x000006ba
Fault offset: 0x00014598
Faulting process id: 0x1b1c
Faulting application start time: 0xsetup.exe_unknown0
Faulting application path: setup.exe_unknown1
Faulting module path: setup.exe_unknown2
Report Id: setup.exe_unknown3
Faulting package full name: setup.exe_unknown4
Faulting package-relative application ID: setup.exe_unknown5
Error: (09/19/2015 02:03:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: ea4
Start Time: 01d0f304cd6cc51c
Termination Time: 4294967295
Application Path: C:\WINDOWS\syswow64\wwahost.exe
Report Id: c2af9fae-5ef8-11e5-bed7-008cfa434a00
Faulting package full name: Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c
Faulting package-relative application ID: App
Error: (09/19/2015 02:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.20911 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 8e0
Start Time: 01d0f304c1e98d27
Termination Time: 4294967295
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe
Report Id: b57a5249-5ef8-11e5-bed7-008cfa434a00
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
Error: (09/19/2015 02:01:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chVrTxzlCKe.exe, version: 1.0.0.0, time stamp: 0x55fa4b62
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0xc06d007e
Fault offset: 0x00014598
Faulting process id: 0x1144
Faulting application start time: 0xchVrTxzlCKe.exe0
Faulting application path: chVrTxzlCKe.exe1
Faulting module path: chVrTxzlCKe.exe2
Report Id: chVrTxzlCKe.exe3
Faulting package full name: chVrTxzlCKe.exe4
Faulting package-relative application ID: chVrTxzlCKe.exe5
Error: (09/19/2015 02:01:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SUKAbQ.exe, version: 1.0.0.0, time stamp: 0x55fa4b73
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54505737
Exception code: 0xc06d007e
Fault offset: 0x0000000000008b9c
Faulting process id: 0x13ec
Faulting application start time: 0xSUKAbQ.exe0
Faulting application path: SUKAbQ.exe1
Faulting module path: SUKAbQ.exe2
Report Id: SUKAbQ.exe3
Faulting package full name: SUKAbQ.exe4
Faulting package-relative application ID: SUKAbQ.exe5
Error: (09/16/2015 09:35:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 45.0.2454.93, time stamp: 0x55f350f6
Faulting module name: chrome.exe, version: 45.0.2454.93, time stamp: 0x55f350f6
Exception code: 0xc0000409
Fault offset: 0x0004c8c1
Faulting process id: 0x1ec
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Faulting package full name: chrome.exe4
Faulting package-relative application ID: chrome.exe5
Error: (09/16/2015 01:27:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: setup.exe_unknown, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0x000006ba
Fault offset: 0x00014598
Faulting process id: 0xa54
Faulting application start time: 0xsetup.exe_unknown0
Faulting application path: setup.exe_unknown1
Faulting module path: setup.exe_unknown2
Report Id: setup.exe_unknown3
Faulting package full name: setup.exe_unknown4
Faulting package-relative application ID: setup.exe_unknown5
Error: (09/16/2015 01:26:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: setup.exe_unknown, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0x000006ba
Fault offset: 0x00014598
Faulting process id: 0x1a20
Faulting application start time: 0xsetup.exe_unknown0
Faulting application path: setup.exe_unknown1
Faulting module path: setup.exe_unknown2
Report Id: setup.exe_unknown3
Faulting package full name: setup.exe_unknown4
Faulting package-relative application ID: setup.exe_unknown5
System errors:
=============
Error: (09/21/2015 02:20:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The pcmaxservice Service service terminated unexpectedly. It has done this 1 time(s).
Error: (09/21/2015 02:20:16 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Windows\System32\drivers\TrueSight.sys
Error: (09/21/2015 02:10:56 PM) (Source: DCOM) (EventID: 10010) (User: NYKAMP-PC)
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (09/21/2015 01:57:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP Network Devices Support service hung on starting.
Error: (09/21/2015 01:51:46 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Device Association Service service, but this action failed with the following error:
%%1056
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Intel(R) Management and Security Application Local Management Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (09/21/2015 01:51:15 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056
CodeIntegrity:
===================================
Date: 2015-09-21 13:14:43.531
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-19 20:46:32.310
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-19 14:45:12.496
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-16 14:17:38.234
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-16 06:14:54.772
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-12 18:52:31.937
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-12 16:36:20.412
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-12 15:30:15.323
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-08-24 15:08:54.455
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-08-15 14:02:22.643
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
Percentage of memory in use: 27%
Total physical RAM: 8076.22 MB
Available physical RAM: 5866.38 MB
Total Virtual: 17292.22 MB
Available Virtual: 15325.61 MB
==================== Drives ================================
Drive c: (TI10658600C) (Fixed) (Total:686.49 GB) (Free:612.17 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================