Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015 Ran by Barbara at 2015-06-02 21:56:00 Running from C:\Users\Barbara\Desktop\FIXITPC Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-847376195-2476872231-1730056214-500 - Administrator - Disabled) ASPNET (S-1-5-21-847376195-2476872231-1730056214-1004 - Limited - Enabled) Barbara (S-1-5-21-847376195-2476872231-1730056214-1001 - Administrator - Enabled) => C:\Users\Barbara Guest (S-1-5-21-847376195-2476872231-1730056214-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-847376195-2476872231-1730056214-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-847376195-2476872231-1730056214-1001\...\uTorrent) (Version: 3.4.2.34024 - BitTorrent Inc.) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) Accountants' Dataset Manager (HKLM-x32\...\InstallShield_{A4FDE0D3-49D8-4C18-95CD-CC620848B25A}) (Version: 3.00.0000 - Sage (UK) Ltd) Accountants' Dataset Manager (x32 Version: 3.00.0000 - Sage (UK) Ltd) Hidden Accounts (x32 Version: 16.0.14.147 - Sage (UK) Ltd) Hidden Accounts (x32 Version: 17.0.12.196 - Sage (UK) Ltd) Hidden Accounts (x32 Version: 18.0.10.208 - Sage (UK) Ltd) Hidden Accounts (x32 Version: 19.0.11.260 - Sage (UK) Ltd) Hidden Accounts (x32 Version: 20.0.9.320 - Sage (UK) Ltd) Hidden Adobe Flash Player ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 9.0.47.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 4.8.1245.73583 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 4.8.1245.73583 - Alcor Micro Corp.) Hidden Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros) Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Basic PAYE Tools (HKLM-x32\...\Basic PAYE Tools - Real Time Information) (Version: 14.1.14168.197 - HM Revenue & Customs) BlackBerry Link (HKLM-x32\...\BlackBerry_10_Desktop) (Version: 1.2.3.56 - BlackBerry Ltd.) BlackBerry Link (x32 Version: 1.2.3.56 - BlackBerry Ltd.) Hidden BTC CT Solution Express 2014 (v7.1.04) (HKLM\...\{4B957365-8568-406A-B17E-447BC79759E9}) (Version: 7.1.04 - BTCSoftware) BTC Solution Centre 2015 (v7.3.03) (HKLM\...\{9D08597B-9B96-4867-B24E-C93ADA8655D6}) (Version: 7.3.03 - BTCSoftware) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.) Canon MG5600 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5600_series) (Version: 1.00 - Canon Inc.) Canon MG5600 series On-screen Manual (HKLM-x32\...\Canon MG5600 series On-screen Manual) (Version: 7.7.1 - Canon Inc.) Canon MG5600 series User Registration (HKLM-x32\...\Canon MG5600 series User Registration) (Version: - ‭Canon Inc.) Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.0.1 - Canon Inc.) Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.0.0 - Canon Inc.) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.) Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.4.1 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform) Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft) Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform) Dropbox (HKU\S-1-5-21-847376195-2476872231-1730056214-1001\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.) DTS Sound (HKLM-x32\...\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.) EBankingCoreTestInstaller (HKLM-x32\...\{76A94B09-345D-4778-AC70-AD7486466727}) (Version: 4.0.74.0 - Sage (UK) Limited) Free YouTube Downloader 3.5.134 (HKLM-x32\...\{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1) (Version: - HOW Inc.) Google Drive (HKLM-x32\...\{6C36881B-0E51-4231-9D02-BF2149664D34}) (Version: 1.20.8672.3137 - Google, Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden IDT Audio Driver (HKLM\...\{588A747E-CFF6-46B3-9207-CD754F9473AF}) (Version: 6.10.6491.0 - IDT) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3282 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) K-Lite Codec Pack 10.4.5 Basic (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.4.5 - ) Malwarebytes Anti-Malware wersja 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MPC-HC 1.7.8 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.8 - MPC-HC Team) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Odkurzacz (HKLM-x32\...\Odkurzacz 13.5_is1) (Version: 13.5.0.1911 - FranmoSoftware - Maciej Opaliñski) Opera Stable 29.0.1795.60 (HKLM-x32\...\Opera 29.0.1795.60) (Version: 29.0.1795.60 - Opera Software ASA) PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.300 - Qualcomm Atheros) Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.) QuickBooks (x32 Version: 23.0.4001.2305 - Intuit Limited) Hidden QuickBooks (x32 Version: 23.0.4004.2305 - Intuit Limited) Hidden QuickBooks Enterprise Solutions 13.0 (HKLM-x32\...\{325F711A-0529-4A06-97CB-703BED98136D}) (Version: 23.0.4004.2305 - Intuit Limited) QuickBooks Pro 2013 (HKLM-x32\...\{3C631966-387E-4054-85D9-BBFFABE32BD8}) (Version: 23.0.4001.2305 - Intuit Limited) QuickBooks SimpleStart Edition (HKLM-x32\...\{7E545666-F420-45FD-B3DF-C0B99A1A579F}) (Version: - ) Rapport (x32 Version: 3.5.1412.158 - Trusteer) Hidden Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Sage 50 Accounts 2010 (HKLM-x32\...\InstallShield_{7061F715-D782-4120-A034-2B4B4F28CC1D}) (Version: 16.0.14.147 - Sage (UK) Ltd) Sage 50 Accounts 2011 (HKLM-x32\...\InstallShield_{4D21F997-85AD-42D2-986F-D91C4836438D}) (Version: 17.0.12.196 - Sage (UK) Ltd) Sage 50 Accounts 2012 (HKLM-x32\...\InstallShield_{EFC6C877-6E77-4E3B-B350-DF4F35D66B51}) (Version: 18.0.10.208 - Sage (UK) Ltd) Sage 50 Accounts 2013 (HKLM-x32\...\InstallShield_{45ECE61A-C8EE-4847-852C-6E8A8192D424}) (Version: 19.0.11.260 - Sage (UK) Ltd) Sage 50 Accounts 2014 (HKLM-x32\...\InstallShield_{2F43F76F-8108-4F39-8DB5-C2C0FA215889}) (Version: 20.0.9.320 - Sage (UK) Ltd) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.101 - Skype Technologies S.A.) Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform) Stellar Phoenix Outlook PST Repair (HKLM\...\Stellar Phoenix Outlook PST Repair_is1) (Version: 5.0.0.0 - Stellar Information Technology Pvt Ltd.) SupportSoft Assisted Service (HKLM-x32\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.10.51 - Synaptics Incorporated) TaxCalc (HKLM-x32\...\TaxCalcHub) (Version: 3 - Acorah Software Products) TaxCalc 2009 (HKLM-x32\...\TaxCalc 2009) (Version: - ) TOSHIBA Addendum (HKLM-x32\...\{CE0374A6-B204-4336-8293-63FBB1DADBF4}) (Version: 1.00 - TOSHIBA) TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation) TOSHIBA Display Utility (HKLM\...\{84FA4D2D-4273-4C66-BD3D-ADD3FE48DFA2}) (Version: 1.1.5.0 - Toshiba Corporation) TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation) TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.1.0001.6403 - Toshiba Corporation) TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.10 - TOSHIBA) TOSHIBA Password Utility (HKLM-x32\...\InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}) (Version: 3.00.344 - Toshiba Corporation) TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation) TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.1.02.55065006 - Toshiba Corporation) TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation) TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0030 - Toshiba Corporation) TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.1.2.32001 - Toshiba Corporation) Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.0 - Toshiba Europe GmbH) TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102 - Toshiba Corporation) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH) Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1412.158 - Trusteer) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) WinISO (HKLM-x32\...\WinISO) (Version: 6.4.0.5170 - WinISO Computing Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-847376195-2476872231-1730056214-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Barbara\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 20-01-2015 13:47:55 Windows Update 23-01-2015 19:20:35 Windows Update 27-01-2015 23:36:32 Revo Uninstaller's restore point - Vosteran 01-02-2015 00:40:24 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 05-02-2015 00:52:00 przed przywracaniem systemu 05-02-2015 01:10:37 Restore Operation 09-02-2015 22:51:58 Windows Update 13-02-2015 00:45:07 Windows Update 17-02-2015 18:45:35 Windows Update 20-02-2015 22:49:18 Windows Update 25-02-2015 00:05:56 Windows Update 05-03-2015 00:19:18 Windows Update 07-03-2015 23:51:29 Revo Uninstaller's restore point - Gameo 13-03-2015 19:31:07 Windows Update 18-03-2015 10:14:07 Windows Update 23-03-2015 22:47:16 Windows Update 26-03-2015 23:35:01 Windows Update 11-04-2015 13:49:47 Windows Update 15-04-2015 22:31:53 Windows Update 28-04-2015 19:07:33 Windows Update 29-04-2015 21:27:20 Installed BTC Solution Centre 2015 (v7.3.03) 06-05-2015 14:50:52 Windows Update 07-05-2015 18:18:41 Revo Uninstaller's restore point - PC Mechanic 11-05-2015 19:36:55 Windows Update 23-05-2015 12:12:05 Uniblue PC Mechanic installation 26-05-2015 18:10:34 Windows Update 29-05-2015 23:55:36 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {095D3251-E54F-4B9E-B322-35B32238A288} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {1524180D-2778-4DE5-A227-15D8B38617C0} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-18] (Toshiba Europe GmbH) Task: {26B6292E-6E58-45B9-B357-7C86A0B72518} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation) Task: {36E1AFA3-C545-4958-8977-E92C2C5B8452} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-05-26] (Avast Software s.r.o.) Task: {3DA6F9A3-0EE5-429E-B24B-CB8A61555C94} - System32\Tasks\Opera scheduled Autoupdate 1411684083 => C:\Program Files (x86)\Opera\launcher.exe [2015-05-18] (Opera Software) Task: {44B117C4-60DD-4B6F-8802-D8E37E6A02D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-15] (Google Inc.) Task: {7028581E-0582-4DA6-BEEA-224350089331} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-05-23] (Microsoft Corporation) Task: {75A04CE3-A484-4749-A81A-930AA3B908F4} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {8045A4AE-F4B6-4AFD-A7B0-0A261DE4BD66} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2013-08-28] (TODO: ) Task: {A38EBA28-CB87-4886-B8E7-1315F15CA245} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-15] (Google Inc.) Task: {AB0EB8CF-9B91-4337-A864-422119FF80B5} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {B8148CCF-ED84-4DC0-B997-E2B0EE95FD31} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-23] (Adobe Systems Incorporated) Task: {C934A6A7-6BF1-4C02-A1C8-5B325385DFB7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd) Task: {C93F6A9F-C901-42B1-BF60-EA41C352E402} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-847376195-2476872231-1730056214-1001 Task: {D2D8F922-8F10-4071-9F1B-2B5849629014} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-08-06] (Synaptics Incorporated) Task: {D3879419-E054-49F9-8D21-3D631D8B5A3C} - System32\Tasks\avastBCLRestartS-1-5-21-847376195-2476872231-1730056214-1001 => Chrome.exe Task: {DF9C7622-0C3A-4124-AF66-45FF2DDEFB1A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {E034524B-E8DB-40E8-8D47-5D695D5E1E3A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation) Task: {F7857699-EFCB-4962-8FBD-1E284515206A} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2013-03-27 12:53 - 2013-03-27 12:53 - 00163168 _____ () C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe 2013-09-10 12:54 - 2013-09-10 12:54 - 00019792 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe 2014-12-19 12:45 - 2013-06-28 16:28 - 00084616 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-09-09 17:59 - 2013-08-12 18:52 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-07-18 18:38 - 2012-07-18 18:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll 2015-04-01 20:51 - 2015-04-01 20:51 - 00055576 _____ () C:\Program Files\CCleaner\branding.dll 2015-04-08 20:53 - 2015-04-08 20:53 - 00050688 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll 2015-05-09 20:00 - 2015-05-09 20:00 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\ErrorReporting.dll 2015-05-26 19:44 - 2015-05-26 19:44 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-05-26 19:44 - 2015-05-26 19:44 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-06-01 20:00 - 2015-06-01 20:00 - 02951680 _____ () C:\Program Files\AVAST Software\Avast\defs\15060101\algo.dll 2015-06-02 18:59 - 2015-06-02 18:59 - 02951680 _____ () C:\Program Files\AVAST Software\Avast\defs\15060201\algo.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2014-03-23 17:04 - 2014-03-23 17:04 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll 2015-05-26 19:44 - 2015-05-26 19:44 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-06-02 18:08 - 2015-06-02 18:08 - 00098816 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32api.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00110080 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\pywintypes27.dll 2015-06-02 18:08 - 2015-06-02 18:08 - 00364544 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\pythoncom27.dll 2015-06-02 18:08 - 2015-06-02 18:08 - 00045568 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_socket.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 01161216 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_ssl.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00320512 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32com.shell.shell.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00713216 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_hashlib.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 01175040 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._core_.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00805888 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._gdi_.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00811008 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._windows_.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 01062400 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._controls_.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00735232 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._misc_.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00682496 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\pysqlite2._sqlite.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00128512 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_elementtree.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00127488 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\pyexpat.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00087552 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_ctypes.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00119808 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32file.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00108544 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32security.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00007168 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\hashobjs_ext.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00167936 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32gui.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00018432 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32event.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00038912 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32inet.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00011264 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32crypt.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00070656 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._html2.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00027136 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_multiprocessing.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00020480 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\_yappi.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00035840 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32process.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00686080 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\unicodedata.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00122368 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._wizard.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00024064 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32pipe.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00010240 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\select.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00025600 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32pdh.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00525640 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\windows._lib_cacheinvalidation.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00017408 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32profile.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00022528 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\win32ts.pyd 2015-06-02 18:08 - 2015-06-02 18:08 - 00078336 _____ () C:\Users\Barbara\AppData\Local\Temp\_MEI31002\wx._animate.pyd 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll 2015-03-21 15:41 - 2015-03-14 11:12 - 01174856 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libglesv2.dll 2015-03-21 15:41 - 2015-03-14 11:12 - 00080200 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libegl.dll 2015-03-21 15:41 - 2015-03-14 11:12 - 09278792 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\pdf.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Barbara\SkyDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-847376195-2476872231-1730056214-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Barbara\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "QuickBooks_Standard_21.lnk" HKLM\...\StartupApproved\StartupFolder: => "QuickBooks Update Agent.lnk" HKLM\...\StartupApproved\Run32: => "Intuit SyncManager" HKLM\...\StartupApproved\Run32: => "BCSSync" HKLM\...\StartupApproved\Run32: => "AmIcoSinglun64" HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive" HKLM\...\StartupApproved\Run32: => "RIM PeerManager" HKLM\...\StartupApproved\Run32: => "CanonQuickMenu" HKLM\...\StartupApproved\Run32: => "DivXMediaServer" HKLM\...\StartupApproved\Run32: => "DivXUpdate" HKU\S-1-5-21-847376195-2476872231-1730056214-1001\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-847376195-2476872231-1730056214-1001\...\StartupApproved\Run: => "OfficeSyncProcess" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{A0112D31-EADF-45DE-B4FD-86EA3FD6046F}] => (Allow) C:\Users\Barbara\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{FBAF7B02-9A16-4457-AE54-E1595784461D}] => (Allow) C:\Users\Barbara\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{14277A01-7031-470F-8C12-E5BAC786A981}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{69324431-6167-4D3E-8D06-9E64301965D4}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{E91575B9-4FB9-4450-9D37-05BA9C8F3843}] => (Allow) C:\Users\Barbara\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{67F312FC-BA09-4F0B-AB0A-A8B3DCBA0C63}] => (Allow) C:\Users\Barbara\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C34E8810-E327-4EE0-BD4D-120F0D5B92D4}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe FirewallRules: [{57C55770-1895-4CB4-91F1-3974975D574E}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe FirewallRules: [{4CA10EE0-B9BD-4C1F-92E5-9E1E7166A7C0}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe FirewallRules: [{B3056C94-928C-4511-8788-071A8B3AE1E4}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe FirewallRules: [{EC7D4FC5-EBF6-42A6-B424-33054CEDBB44}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\nginx\nginx.exe FirewallRules: [{00712810-98DB-4500-94C6-159E7C41767C}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe FirewallRules: [{75C6E68B-9977-47B5-9F5F-578B6D8D26DB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{78BE90AD-D445-49B1-B74B-F3139DCE5C9F}] => (Allow) C:\Program Files (x86)\Acorah Software Products\TaxCalcHub\TaxCalcHub.exe FirewallRules: [{9A6FA90F-70A5-4B62-9B09-AE39F14E4033}] => (Allow) C:\Program Files (x86)\Acorah Software Products\TaxCalcHub\TaxCalcHub.exe FirewallRules: [{D1E6A5E8-1ACB-4123-ABF7-74668A56AE2F}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{BB658C6A-7F0F-4D94-90CA-BB851CDC365D}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe ==================== Faulty Device Manager Devices ============= Name: avast! SecureLine TAP Adapter v3 Description: avast! SecureLine TAP Adapter v3 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TAP-Windows Provider V9 Service: aswTap Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: TAP-Windows Adapter V9 Description: TAP-Windows Adapter V9 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TAP-Windows Provider V9 Service: tap0901 Problem: : Windows cannot load the device driver for this hardware. The driver may be corrupted or missing. (Code 39) Resolution: Reasons for this error include a driver that is not present; a binary file that is corrupt; a file I/O problem, or a driver that references an entry point in another binary file that could not be loaded. Uninstall the driver, and then click "Scan for hardware changes" to reinstall or upgrade the driver. ==================== Event log errors: ========================= Application errors: ================== Error: (06/02/2015 06:39:04 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 560: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (06/02/2015 06:39:04 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 500: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 552: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (06/01/2015 10:31:55 PM) (Source: MsiInstaller) (EventID: 1023) (User: WEBASIA-PC) Description: Product: Adobe Reader XI (11.0.10) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011011}' could not be installed. Error code 1625. Additional information is available in the log file C:\Users\Barbara\AppData\Local\Temp\MSI58e15.LOG. Error: (06/01/2015 09:39:41 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program LiveComm.exe version 17.5.9600.20856 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 960 Start Time: 01d09caa5e6c38e0 Termination Time: 4294967295 Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\LiveComm.exe Report Id: 52098a6e-089e-11e5-82cd-0c54a538478c Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1 Error: (06/01/2015 09:32:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DeviceAssociationService, version: 6.3.9600.16384, time stamp: 0x5215dfe3 Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f4336 Exception code: 0xc0000374 Fault offset: 0x00000000000f0f20 Faulting process ID: 0x3f8 Faulting application start time: 0xsvchost.exe_DeviceAssociationService0 Faulting application path: svchost.exe_DeviceAssociationService1 Faulting module path: svchost.exe_DeviceAssociationService2 Report ID: svchost.exe_DeviceAssociationService3 Faulting package full name: svchost.exe_DeviceAssociationService4 Faulting package-relative application ID: svchost.exe_DeviceAssociationService5 Error: (06/01/2015 06:46:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WEBASIA-PC) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (06/01/2015 10:14:02 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: WEBASIA-PC) Description: 0x8000002a116\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-847376195-2476872231-1730056214-1001-0-ntuser.dat Error: (06/01/2015 10:13:48 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: WEBASIA-PC) Description: 0x8000002a116\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-847376195-2476872231-1730056214-1001-0-ntuser.dat Error: (06/01/2015 09:32:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Media Player Network Sharing Service service depends on the Windows Search service which failed to start because of the following error: %%3 Error: (06/01/2015 09:32:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Search service failed to start due to the following error: %%3 Error: (06/01/2015 09:32:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Search service failed to start due to the following error: %%3 Error: (06/01/2015 09:32:59 PM) (Source: DCOM) (EventID: 10010) (User: WEBASIA-PC) Description: {9E175B68-F52A-11D8-B9A5-505054503030} Error: (06/01/2015 09:32:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The RIM MDNS service terminated unexpectedly. It has done this 1 time(s). Error: (06/01/2015 09:32:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The MBAMService service terminated unexpectedly. It has done this 1 time(s). Error: (06/01/2015 09:32:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The TEMPRO Service service terminated unexpectedly. It has done this 1 time(s). Error: (06/01/2015 09:32:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The TPCH Service service terminated unexpectedly. It has done this 1 time(s). Microsoft Office: ========================= Error: (06/02/2015 06:39:04 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 560: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (06/02/2015 06:39:04 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 500: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 552: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (06/02/2015 07:54:52 AM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (06/01/2015 10:31:55 PM) (Source: MsiInstaller) (EventID: 1023) (User: WEBASIA-PC) Description: Adobe Reader XI (11.0.10){AC76BA86-7AD7-0000-2550-7A8C40011011}1625C:\Users\Barbara\AppData\Local\Temp\MSI58e15.LOG(NULL)(NULL) Error: (06/01/2015 09:39:41 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: LiveComm.exe17.5.9600.2085696001d09caa5e6c38e04294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\LiveComm.exe52098a6e-089e-11e5-82cd-0c54a538478cmicrosoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 Error: (06/01/2015 09:32:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe_DeviceAssociationService6.3.9600.163845215dfe3ntdll.dll6.3.9600.17736550f4336c000037400000000000f0f203f801d09ac59a4d0212C:\Windows\System32\svchost.exeC:\Windows\SYSTEM32\ntdll.dll528ac7ad-089d-11e5-82cc-0c54a538478c Error: (06/01/2015 06:46:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WEBASIA-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 CodeIntegrity Errors: =================================== Date: 2014-08-22 19:00:21.458 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU 2020M @ 2.40GHz Percentage of memory in use: 30% Total physical RAM: 8067.27 MB Available physical RAM: 5573.87 MB Total Pagefile: 16259.27 MB Available Pagefile: 13516.16 MB Total Virtual: 131072 MB Available Virtual: 131071.84 MB ==================== Drives ================================ Drive c: (TI31205500A) (Fixed) (Total:465.4 GB) (Free:294.93 GB) NTFS Drive e: (New Volume) (Fixed) (Total:260.09 GB) (Free:259.64 GB) NTFS Drive f: (New Volume) (Fixed) (Total:195.31 GB) (Free:191.07 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================