Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

The HTTP Service service failed to start due to the following error:%%1009


  • Please log in to reply
20 replies to this topic

#1 GaryG45

GaryG45

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 24 April 2015 - 11:37 AM

Yesterday my wife's HP ENVY laptop began to have problems; screen blinking and slow typing.  The laptop is running Windows 8.  I ran MiniToolBox and found numerous errors for HpConnectedRemoteService.exe continually terminating and restarting.  After finding a post on this site about that service I uninstalled it.  Things seemed to be fine after uninstalling it, but then I found the Print Spooler Service wouldn't start.  I finally fixed it.

 

After all of this I decided to run MiniToolBox again and found error messages stating "The HTTP Service service failed to start due to the following error: %%1009.  I don't know if this is a problem and if her PC is infected.

 

The link to Speccy is: http://speccy.piriform.com/results/nuE8q6rLm8H0gWnsGDhyGDE

 

The MiniToolBox output from this morning is below.  I've also run ADWCleaner and Malwarebytes.  Malwarebytes found nothing and ADWCleaner found some things from another old tool that had been uninstalled.  Any help you can provide would be appreciated.

 

Gary

 

MiniToolBox by Farbar  Version: 14-04-2015
Ran by Diane (administrator) on 24-04-2015 at 07:07:18
Running from "C:\Users\Diane\Downloads"
Microsoft Windows 8  (X64)
Model: HP ENVY TS Sleekbook 4 Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/23/2015 05:44:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DIANES-HP-PC)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (04/23/2015 00:50:17 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (04/23/2015 00:50:17 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)
Description: Unable to read the Last Counter registry value. The first DWORD in the Data section contains the Win32 error code.

Error: (04/23/2015 07:42:33 AM) (Source: Microsoft-Windows-RestartManager) (User: DIANES-HP-PC)
Description: Application or service 'HP Connected Remote Service' could not be restarted.

Error: (04/23/2015 07:42:19 AM) (Source: Application Error) (User: )
Description: Faulting application name: HPConnectedRemoteService.exe, version: 1.0.1218.0, time stamp: 0x5078a573
Faulting module name: KERNELBASE.dll, version: 6.2.9200.16864, time stamp: 0x531d34d8
Exception code: 0xe0434352
Fault offset: 0x0000000000047b8c
Faulting process id: 0xec8
Faulting application start time: 0xHPConnectedRemoteService.exe0
Faulting application path: HPConnectedRemoteService.exe1
Faulting module path: HPConnectedRemoteService.exe2
Report Id: HPConnectedRemoteService.exe3
Faulting package full name: HPConnectedRemoteService.exe4
Faulting package-relative application ID: HPConnectedRemoteService.exe5

Error: (04/23/2015 07:42:19 AM) (Source: .NET Runtime) (User: )
Description: Application: HPConnectedRemoteService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.PlatformNotSupportedException
Stack:
   at System.ServiceModel.Channels.TransportManager.Open(System.ServiceModel.Channels.TransportChannelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(System.ServiceModel.Channels.SelectTransportManagersCallback)
   at System.ServiceModel.Channels.HttpChannelListener`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.ServiceHostBase.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at SwitchBoard.Utils.WCFServiceHostUtil.setupService(System.Object, System.Type, Int32, Boolean)
   at SwitchBoard.SwitchBoardService.RunService()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

Error: (04/23/2015 07:42:08 AM) (Source: Application Error) (User: )
Description: Faulting application name: HPConnectedRemoteService.exe, version: 1.0.1218.0, time stamp: 0x5078a573
Faulting module name: KERNELBASE.dll, version: 6.2.9200.16864, time stamp: 0x531d34d8
Exception code: 0xe0434352
Fault offset: 0x0000000000047b8c
Faulting process id: 0x9d4
Faulting application start time: 0xHPConnectedRemoteService.exe0
Faulting application path: HPConnectedRemoteService.exe1
Faulting module path: HPConnectedRemoteService.exe2
Report Id: HPConnectedRemoteService.exe3
Faulting package full name: HPConnectedRemoteService.exe4
Faulting package-relative application ID: HPConnectedRemoteService.exe5

Error: (04/23/2015 07:42:08 AM) (Source: .NET Runtime) (User: )
Description: Application: HPConnectedRemoteService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.PlatformNotSupportedException
Stack:
   at System.ServiceModel.Channels.TransportManager.Open(System.ServiceModel.Channels.TransportChannelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(System.ServiceModel.Channels.SelectTransportManagersCallback)
   at System.ServiceModel.Channels.HttpChannelListener`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.ServiceHostBase.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at SwitchBoard.Utils.WCFServiceHostUtil.setupService(System.Object, System.Type, Int32, Boolean)
   at SwitchBoard.SwitchBoardService.RunService()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

Error: (04/23/2015 07:41:57 AM) (Source: Application Error) (User: )
Description: Faulting application name: HPConnectedRemoteService.exe, version: 1.0.1218.0, time stamp: 0x5078a573
Faulting module name: KERNELBASE.dll, version: 6.2.9200.16864, time stamp: 0x531d34d8
Exception code: 0xe0434352
Fault offset: 0x0000000000047b8c
Faulting process id: 0x1344
Faulting application start time: 0xHPConnectedRemoteService.exe0
Faulting application path: HPConnectedRemoteService.exe1
Faulting module path: HPConnectedRemoteService.exe2
Report Id: HPConnectedRemoteService.exe3
Faulting package full name: HPConnectedRemoteService.exe4
Faulting package-relative application ID: HPConnectedRemoteService.exe5

Error: (04/23/2015 07:41:57 AM) (Source: .NET Runtime) (User: )
Description: Application: HPConnectedRemoteService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.PlatformNotSupportedException
Stack:
   at System.ServiceModel.Channels.TransportManager.Open(System.ServiceModel.Channels.TransportChannelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(System.ServiceModel.Channels.SelectTransportManagersCallback)
   at System.ServiceModel.Channels.HttpChannelListener`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.ServiceHostBase.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at SwitchBoard.Utils.WCFServiceHostUtil.setupService(System.Object, System.Type, Int32, Boolean)
   at SwitchBoard.SwitchBoardService.RunService()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

System errors:
=============
Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The SSDP Discovery service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/24/2015 07:06:52 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1068

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Provider Host service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/24/2015 07:06:52 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1068

Error: (04/24/2015 07:06:52 AM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Microsoft Office Sessions:
=========================
Error: (04/23/2015 05:44:19 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: DIANES-HP-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2144927141

Error: (04/23/2015 00:50:17 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)
Description: WmiApRplWmiApRpl802000000E5050000

Error: (04/23/2015 00:50:17 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)
Description: Last Counter8020000000D050000

Error: (04/23/2015 07:42:33 AM) (Source: Microsoft-Windows-RestartManager)(User: DIANES-HP-PC)
Description: 0HPConnectedRemoteService.exeHP Connected Remote Service03026217825160

Error: (04/23/2015 07:42:19 AM) (Source: Application Error)(User: )
Description: HPConnectedRemoteService.exe1.0.1218.05078a573KERNELBASE.dll6.2.9200.16864531d34d8e04343520000000000047b8cec801d07dc2ef5e64c1C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exeC:\Windows\system32\KERNELBASE.dll2d9539aa-e9b6-11e4-bef2-f4b7e2ab8336

Error: (04/23/2015 07:42:19 AM) (Source: .NET Runtime)(User: )
Description: Application: HPConnectedRemoteService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.PlatformNotSupportedException
Stack:
   at System.ServiceModel.Channels.TransportManager.Open(System.ServiceModel.Channels.TransportChannelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(System.ServiceModel.Channels.SelectTransportManagersCallback)
   at System.ServiceModel.Channels.HttpChannelListener`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.ServiceHostBase.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at SwitchBoard.Utils.WCFServiceHostUtil.setupService(System.Object, System.Type, Int32, Boolean)
   at SwitchBoard.SwitchBoardService.RunService()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

Error: (04/23/2015 07:42:08 AM) (Source: Application Error)(User: )
Description: HPConnectedRemoteService.exe1.0.1218.05078a573KERNELBASE.dll6.2.9200.16864531d34d8e04343520000000000047b8c9d401d07dc2e8856d5dC:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exeC:\Windows\system32\KERNELBASE.dll26cd4bb6-e9b6-11e4-bef2-f4b7e2ab8336

Error: (04/23/2015 07:42:08 AM) (Source: .NET Runtime)(User: )
Description: Application: HPConnectedRemoteService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.PlatformNotSupportedException
Stack:
   at System.ServiceModel.Channels.TransportManager.Open(System.ServiceModel.Channels.TransportChannelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(System.ServiceModel.Channels.SelectTransportManagersCallback)
   at System.ServiceModel.Channels.HttpChannelListener`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.ServiceHostBase.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at SwitchBoard.Utils.WCFServiceHostUtil.setupService(System.Object, System.Type, Int32, Boolean)
   at SwitchBoard.SwitchBoardService.RunService()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

Error: (04/23/2015 07:41:57 AM) (Source: Application Error)(User: )
Description: HPConnectedRemoteService.exe1.0.1218.05078a573KERNELBASE.dll6.2.9200.16864531d34d8e04343520000000000047b8c134401d07dc2e27a0336C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exeC:\Windows\system32\KERNELBASE.dll20ac1467-e9b6-11e4-bef2-f4b7e2ab8336

Error: (04/23/2015 07:41:57 AM) (Source: .NET Runtime)(User: )
Description: Application: HPConnectedRemoteService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.PlatformNotSupportedException
Stack:
   at System.ServiceModel.Channels.TransportManager.Open(System.ServiceModel.Channels.TransportChannelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(System.ServiceModel.Channels.SelectTransportManagersCallback)
   at System.ServiceModel.Channels.HttpChannelListener`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at System.ServiceModel.ServiceHostBase.OnOpen(System.TimeSpan)
   at System.ServiceModel.Channels.CommunicationObject.Open(System.TimeSpan)
   at SwitchBoard.Utils.WCFServiceHostUtil.setupService(System.Object, System.Type, Int32, Boolean)
   at SwitchBoard.SwitchBoardService.RunService()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

 

=========================== Installed Programs ============================
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.1.0.8 - Absolute Software)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.)
Airport Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Azteca (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.98 - WildTangent) Hidden
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
Build-a-lot (x32 Version: 2.2.0.98 - WildTangent) Hidden
Citrix Authentication Manager (x32 Version: 5.1.0.62606 - Citrix Systems, Inc.) Hidden
Citrix Online Launcher (HKLM-x32\...\{77463C86-BB3A-426E-A6C2-06B4D28C250F}) (Version: 1.0.223 - Citrix)
Citrix Receiver (HDX Flash Redirection) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.1.0.0 - Citrix Systems, Inc.)
Citrix Receiver Inside (x32 Version: 4.1.0.56471 - Citrix Systems, Inc.) Hidden
Citrix Receiver Updater (x32 Version: 4.1.0.56461 - Citrix Systems, Inc.) Hidden
Citrix Receiver(Aero) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver(DV) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver(USB) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.)
CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)
CyberLink PowerDVD (x32 Version: 10.0.6.4319 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.6.6119 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.6.6119 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Family Tree Maker 2012 (HKLM-x32\...\Family Tree Maker 2012) (Version: 21.0.388 - Ancestry.com, Inc.)
Family Tree Maker 2012 (x32 Version: 21.0.388 - Ancestry.com, Inc.) Hidden
FATE: The Cursed King (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 11.0.0.1019 - Citrix Online, a division of Citrix Systems, Inc.)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden
HP 3D DriveGuard (HKLM\...\{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP CoolSense (HKLM-x32\...\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}) (Version: 2.10.51 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Documentation (HKLM-x32\...\{73A33079-D1A0-4469-8903-C4A48B4975E2}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP MyRoom (HKLM-x32\...\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company)
HP Officejet 6700 Basic Device Software (HKLM\...\{A1CFA587-90D4-4DE6-B200-68CC0F92252F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6700 Help (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard)
HP Officejet 6700 Product Improvement Study (HKLM\...\{988D55BB-08DE-43C9-8D16-3751361E2A79}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Quick Launch (HKLM-x32\...\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company)
HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden
HP Registration Service (HKLM\...\{C2E428EB-116E-41C0-9E84-B22DE9CCA42F}) (Version: 1.1.6232.4245 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.8 - Hewlett-Packard)
HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2867 - Intel Corporation)
Intel® Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 2.1.0.1002 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.9.1002 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1108.0727 - Microsoft) Hidden
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.1 - Nikon)
Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.2 - Nikon)
Norton Security Suite (HKLM-x32\...\N360) (Version: 21.7.0.11 - Symantec Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Online Plug-in (HKLM-x32\...\{7BD3DC6D-A2BE-4345-B6EE-D146193DB18F}) (Version: 13.4.0.25 - Citrix Systems, Inc.)
Online Plug-in (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.5.1 - Nikon)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Ralink Bluetooth Stack (HKLM\...\{C079427A-BB28-5168-3DB1-DC6608D226D4}) (Version: 11.0.748.2 - Mediatek)
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.5.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.9200.27029 - Realtek Semiconductor Corp.)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Self-service Plug-in (x32 Version: 4.1.0.41738 - Citrix Systems, Inc.) Hidden
Sonos Controller (HKLM-x32\...\{7BBA9BF8-05DF-47D8-8880-82A9B99505B9}) (Version: 28.1.83040 - Sonos, Inc.)
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 16.5.3.3 - Synaptics Incorporated)
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: 7.3.0.5 - 2BrightSparks)
The Treasures of Mystery Island: The Ghost Ship (x32 Version: 2.2.0.98 - WildTangent) Hidden
True Image 2013 (HKLM-x32\...\{75BC2136-B6A1-4F3B-8A69-55E39C647B1F}Visible) (Version: 16.0.6514 - Acronis)
True Image 2013 (x32 Version: 16.0.6514 - Acronis) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.9.2 - Nikon)
VIP Access (HKLM-x32\...\{97C89A11-9AD7-49CE-9F90-54BF075623CE}) (Version: 2.1.1.34 - Symantec Corporation)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.9.7 - WildTangent) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden

========================= Memory info: ===================================

Percentage of memory in use: 44%
Total physical RAM: 3992.27 MB
Available physical RAM: 2224.47 MB
Total Pagefile: 8088.27 MB
Available Pagefile: 6221.45 MB
Total Virtual: 4095.88 MB
Available Virtual: 3971.65 MB

========================= Partitions: =====================================

1 Drive c: (OS) (Fixed) (Total:434.35 GB) (Free:350.64 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:30.64 GB) (Free:3.57 GB) NTFS

========================= Users: ========================================

User accounts for \\DIANES-HP-PC

Administrator            Diane                    Guest                   

========================= Minidump Files ==================================

No minidump file found

**** End of log ****



BC AdBot (Login to Remove)

 


#2 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 25 April 2015 - 05:31 PM

Download and run wipe  and system ninja,

 

https://privacyroot.com/software/www/en/wipe.php

https://singularlabs.com/software/system-ninja/

 

Then.....

 

Go ahead and install Ccleaner. Now that you have the program installed go ahead and run the cleaner function.
kwLN4uv.png


Now that you have cleaned out some temp files, lets go ahead and disable all of the items starting up with your machine except your antivirus. To do this you will need to click on tools then start up select each item then disable.

GjWwvEu.png

Now that you have disabled those un-needed start ups lets go into the settings, we will have Ccleaner run when your machine boots, so that you will never have to worry about cleaning temp files again.

To do this:

  • Hit options.
  • Settings.
  • Place a tick to run Ccleaner when the computer starts.


Lxioao1.png

Now go to the advanced tab, and select close program after cleaning, now run the cleaner again this will close Ccleaner.

SnqZ2JW.png

 

Reboot your machine and then follow the  instructions below.

 

Step 1: eScanAV.

 

Disable your antivirus prior to this scan.

http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

Download the eScanAV Anti-Virus Toolkit (MWAV)
http://www.escanav.com/english/content/products/downloadlink/downloadcounter.asp?pcode=MWAV&src=english_dwn&type=alter
Save the file to your desktop.
Right click run as administrator.
A new icon will appear on your desktop.
Right click run as administrator on new icon.
Click on the update tab.
ZCDJtZN.png
Once you have updated the program, make sure the settings are the same as the picture below.
7DUFn5c.png
Once you have made sure the settings match the picture, hit the Scan & Clean button.
Upon scan completion, click View Log.
ApSVXsQ.png
Copy and paste entire log into your next reply.
Note: Reboot if needed to remove infections.

 

Step 2: Zemana

 

Run a full scan with Zemana antimalware.

http://www.zemana.us/product/zemana-antimalware/default.aspx

Install and select deep scan.

jdmyscF.jpg

Remove any infections found.

Then click on the icon in the pic below.

DOLGyto.jpg

Double click on the scan log, copy and paste here in your reply.

 

 

Step 3: Junkware Removal Tool.
 
Please download Junkware Removal Tool and save it on your desktop.

  • Shut down your anti-virus, anti-spyware, and firewall software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log is saved to your desktop and will automatically open.
  • Please post the JRT log.

Step 4: Adware Cleaner.
 
Please download AdwCleaner by Xplode onto your desktop.


  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


#3 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 27 April 2015 - 12:54 PM

Here is the MWAV eScanAV log

 

27 Apr 2015 12:06:15 [0bd0] - **********************************************************
27 Apr 2015 12:06:15 [0bd0] - MWAV - eScanAV AntiVirus Toolkit.
27 Apr 2015 12:06:15 [0bd0] - Copyright © MicroWorld Technologies
27 Apr 2015 12:06:15 [0bd0] - **********************************************************
27 Apr 2015 12:06:15 [0bd0] - Source: C:\Users\Diane\Downloads\mwav.exe
27 Apr 2015 12:06:15 [0bd0] - Version 14.0.178 (C:\USERS\DIANE\APPDATA\LOCAL\TEMP\MEXE.COM)
27 Apr 2015 12:06:15 [0bd0] - Log File: C:\Users\Diane\AppData\Local\Temp\MWAV.LOG
27 Apr 2015 12:06:15 [0bd0] - MWAV Registered: TRUE
27 Apr 2015 12:06:15 [0bd0] - User Account: Diane (Administrator Mode)
27 Apr 2015 12:06:15 [0bd0] - OS Type: Windows Workstation [InstallType: Client]
27 Apr 2015 12:06:15 [0bd0] - OS: Windows 8 64-Bit [OS Install Date: 21 Apr 2013 20:00:40]
27 Apr 2015 12:06:15 [0bd0] - Ver: Personal Build 9200
27 Apr 2015 12:06:15 [0bd0] - System Up Time: 1 Hour, 19 Minutes, 1 Second

27 Apr 2015 12:06:15 [0bd0] - Parent Process Name : C:\Users\Diane\Downloads\mwav.exe
27 Apr 2015 12:06:15 [0bd0] - Windows Root  Folder: C:\Windows
27 Apr 2015 12:06:15 [0bd0] - Windows Sys32 Folder: C:\Windows\system32
27 Apr 2015 12:06:15 [0bd0] - DHCP NameServer: 75.75.75.75 75.75.76.76
27 Apr 2015 12:06:15 [0bd0] - Interface0 NameServer: 208.67.222.222,208.67.220.220
27 Apr 2015 12:06:15 [0bd0] - Interface1 NameServer: 208.67.222.222,208.67.220.220
27 Apr 2015 12:06:15 [0bd0] - Interface0 DHCPNameServer: 75.75.75.75 75.75.76.76
27 Apr 2015 12:06:15 [0bd0] - Local Fixed Drives: c:\,d:\
27 Apr 2015 12:06:15 [0bd0] - MWAV Mode(A): Scan and Clean files (for viruses, adware and spyware)
27 Apr 2015 12:06:15 [0bd0] - [CREATED ZIP FILE: C:\Users\Diane\AppData\Local\Temp\pinfect.zip]
27 Apr 2015 12:06:15 [0bd0] - Latest Date of files inside MWAV: Mon Mar  2 17:13:53 2015.
27 Apr 2015 12:06:17 [0bd0] - ** Changed Value of "Path"
27 Apr 2015 12:06:17 [0bd0] - Loading/Creating FileScan Cache Database C:\ProgramData\MicroWorld\MWAV\ESCANDBY.MDB [Log: C:\Users\Diane\AppData\Local\Temp\ESCANDB.LOG]
27 Apr 2015 12:06:18 [0bd0] - Loaded/Created FileScan Cache Database...
27 Apr 2015 12:06:18 [0bd0] - Loading AV Library [DB]...
27 Apr 2015 12:06:36 [0bd0] - ArchiveScan: DISABLED
27 Apr 2015 12:06:37 [0bd0] - AV Library Loaded - MultiThreaded - 8 : [DB-DIRECT].
27 Apr 2015 12:06:37 [0bd0] - MWAV doing self scanning...
27 Apr 2015 12:06:37 [0bd0] - MWAV files are clean.
27 Apr 2015 12:06:48 [0bd0] - ArchiveScan: DISABLED
27 Apr 2015 12:06:48 [0bd0] - Virus Database Date: 02 Mar 2015
27 Apr 2015 12:06:48 [0bd0] - Virus Database Count: 6701505
27 Apr 2015 12:06:48 [0bd0] - Sign Version: 7.59505 [518257]
27 Apr 2015 12:07:00 [0bd0] - Downloading AntiVirus and Anti-Spyware Databases...
27 Apr 2015 12:12:30 [0bd0] - Update Successful...
27 Apr 2015 12:14:35 [0bd0] - Indexed Spyware Databases Successfully Created...
27 Apr 2015 12:14:36 [0bd0] - Old Sign Version: 7.59505 New Sign Version: 7.60320
27 Apr 2015 12:14:53 [0bd0] - Reload of AntiVirus Signatures successfully done.
27 Apr 2015 12:14:53 [0bd0] - Virus Database Date: 27 Apr 2015
27 Apr 2015 12:14:53 [0bd0] - Virus Database Count: 5762444
27 Apr 2015 12:14:53 [0bd0] - Sign Version: 7.60320 [519072]
 
27 Apr 2015 12:15:52 [0bd0] - **********************************************************
27 Apr 2015 12:15:52 [0bd0] - MWAV - eScanAV AntiVirus Toolkit.
27 Apr 2015 12:15:52 [0bd0] - Copyright © MicroWorld Technologies
27 Apr 2015 12:15:52 [0bd0] -
27 Apr 2015 12:15:52 [0bd0] - Support: support@escanav.com
27 Apr 2015 12:15:52 [0bd0] - Web: http://www.escanav.com
27 Apr 2015 12:15:52 [0bd0] - **********************************************************
27 Apr 2015 12:15:52 [0bd0] - Version 14.0.178[DB] (C:\USERS\DIANE\APPDATA\LOCAL\TEMP\MEXE.COM)
27 Apr 2015 12:15:52 [0bd0] - Log File: C:\Users\Diane\AppData\Local\Temp\MWAV.LOG
27 Apr 2015 12:15:52 [0bd0] - User Account: Diane (Administrator Mode)
27 Apr 2015 12:15:52 [0bd0] - Parent Process Name : C:\Users\Diane\Downloads\mwav.exe
27 Apr 2015 12:15:52 [0bd0] - Windows Root  Folder: C:\Windows
27 Apr 2015 12:15:52 [0bd0] - Windows Sys32 Folder: C:\Windows\system32
27 Apr 2015 12:15:52 [0bd0] - OS: Windows 8 64-Bit [OS Install Date: 21 Apr 2013 20:00:40]
27 Apr 2015 12:15:52 [0bd0] - Ver: Personal Build 9200
27 Apr 2015 12:15:52 [0bd0] - Latest Date of files inside MWAV: Mon Mar  2 17:13:53 2015.
 
27 Apr 2015 12:15:52 [06f4] - Options Selected by User:
27 Apr 2015 12:15:52 [06f4] - Memory Check: Enabled
27 Apr 2015 12:15:52 [06f4] - Registry Check: Enabled
27 Apr 2015 12:15:52 [06f4] - StartUp Folder Check: Enabled
27 Apr 2015 12:15:52 [06f4] - System Folder Check: Enabled
27 Apr 2015 12:15:52 [06f4] - Services Check: Enabled
27 Apr 2015 12:15:52 [06f4] - Scan Spyware: Enabled
27 Apr 2015 12:15:52 [06f4] - Scan Archives: Disabled
27 Apr 2015 12:15:52 [06f4] - Drive Check: Enabled
27 Apr 2015 12:15:52 [06f4] - All Drive Check :Disabled
27 Apr 2015 12:15:52 [06f4] - Drive Selected = C:\
27 Apr 2015 12:15:52 [06f4] - Folder Check: Disabled
27 Apr 2015 12:15:52 [06f4] - SCAN: All_Files [ANSI]
27 Apr 2015 12:15:52 [06f4] - MWAV Mode(B): Scan and Clean files (for viruses, adware and spyware)
 
27 Apr 2015 12:15:52 [06f4] - Scanning DNS Records...
27 Apr 2015 12:15:52 [06f4] - Scanning Master Boot Record (User)...
27 Apr 2015 12:15:53 [06f4] - Scanning Logical Boot Records...
27 Apr 2015 12:15:53 [06f4] - ***** Scanning For Hidden Rootkit Processes *****
27 Apr 2015 12:15:53 [06f4] - ***** Scanning For Hidden Rootkit Services *****
 
27 Apr 2015 12:15:59 [06f4] - ***** Scanning Memory Files *****
 
27 Apr 2015 12:16:07 [06f4] - ***** Scanning Registry Files *****
27 Apr 2015 12:16:09 [06f4] - ** NON-STANDARD WINLOGON NOTIFY KEY [SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
27 Apr 2015 12:16:10 [06f4] - ERROR(3)!!! Invalid Entry CitrixReceiver = "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" (in key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). Action Taken: Removing it.
27 Apr 2015 12:16:10 [06f4] - ERROR(3)!!! Invalid Entry  Maintance = "C:\Program Files\\net1.exe" windowsStartup (in key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). Action Taken: Removing it.
 
27 Apr 2015 12:16:10 [06f4] - ***** Scanning StartUp Folders *****
27 Apr 2015 12:16:40 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\ProgramData\Microsoft\Windows\WER\ReportArchive]: LastErr: 5. IGNORING.
27 Apr 2015 12:16:40 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\ProgramData\Microsoft\Windows\WER\ReportQueue]: LastErr: 5. IGNORING.
 
27 Apr 2015 12:16:56 [06f4] - ***** Scanning Service Files *****
27 Apr 2015 12:17:01 [06f4] - ERROR(2)!!! Invalid Entry C:\Users\Diane\AppData\Local\Temp\7zS682F\hpslpsvc64.dll. Action Taken: Removing HKLM64\SYSTEM\CurrentControlSet\Services\HPSLPSVC.
27 Apr 2015 12:17:06 [06f4] - Giving rights(a) to [HKLM64\SYSTEM\CurrentControlSet\Services\TrkWks].
 
27 Apr 2015 12:17:09 [06f4] - ***** Scanning Registry and File system for Adware/Spyware *****
27 Apr 2015 12:17:09 [06f4] - Loading Spyware Signatures from new External Database [Name: C:\Users\Diane\AppData\Local\Temp\spydb.avs, Size: 464724]...
27 Apr 2015 12:17:09 [06f4] - Indexed Spyware Databases Successfully Created...
 
27 Apr 2015 12:17:10 [06f4] - Offending file found: C:\Users\Diane\Favorites\GAMES\BLACKJACK.url
27 Apr 2015 12:17:10 [06f4] - System found infected with SmitFraud Browser Hijacker (BLACKJACK.url)! Action taken: File Deleted.
27 Apr 2015 12:17:10 [06f4] - Object "SmitFraud Browser Hijacker" found in File System! Action Taken: File Deleted.

27 Apr 2015 12:17:10 [06f4] - Offending file found: C:\Users\Diane\Favorites\GAMES\CRAPS.url
27 Apr 2015 12:17:10 [06f4] - System found infected with GoHip Spyware/Adware (CRAPS.url)! Action taken: File Deleted.
27 Apr 2015 12:17:10 [06f4] - Object "GoHip Spyware/Adware" found in File System! Action Taken: File Deleted.

27 Apr 2015 12:17:10 [06f4] - Offending file found: C:\Users\Diane\Favorites\GAMES\PARTY POKER.url
27 Apr 2015 12:17:10 [06f4] - System found infected with SmitFraud Browser Hijacker (PARTY POKER.url)! Action taken: File Deleted.
27 Apr 2015 12:17:10 [06f4] - Object "SmitFraud Browser Hijacker" found in File System! Action Taken: File Deleted.

27 Apr 2015 12:17:14 [06f4] - Offending file found: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\Logs\LU.dat
27 Apr 2015 12:17:14 [06f4] - System found infected with ImIServer IEPlugin Spyware/Adware (LU.dat)! Action taken: File Deleted.
27 Apr 2015 12:17:14 [06f4] - Object "ImIServer IEPlugin Spyware/Adware" found in File System! Action Taken: File Deleted.

 
27 Apr 2015 12:17:15 [06f4] - ***** Scanning Registry Files *****
27 Apr 2015 12:17:16 [06f4] - ** NON-STANDARD WINLOGON NOTIFY KEY [SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
27 Apr 2015 12:17:16 [06f4] - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://g.msn.com/HPNOT13/1
27 Apr 2015 12:17:16 [06f4] - ** Deleted Value of "NoActiveDesktop" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer". Its value was DWORD:1.
27 Apr 2015 12:17:16 [06f4] - ** Deleted Value of "ForceActiveDesktopOn" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer". Its value was DWORD:0.
27 Apr 2015 12:17:16 [06f4] - ** Deleted Value of "NoComponents" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop". Its value was DWORD:1.
27 Apr 2015 12:17:16 [06f4] - ** Deleted Value of "NoAddingComponents" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop". Its value was DWORD:1.
27 Apr 2015 12:17:17 [06f4] - ** Value in 64-bit HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://g.msn.com/HPNOT13/1
27 Apr 2015 12:17:17 [06f4] - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = http://www.google.com/
27 Apr 2015 12:17:17 [06f4] - ** Value in 64-bit HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = about:blank
 
27 Apr 2015 12:17:17 [06f4] - ***** Scanning System32 Folders *****
 
27 Apr 2015 12:17:34 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Diane\AppData\Local\Temp\RDRB382.tmp]: LastErr: 2. IGNORING.
 
27 Apr 2015 12:17:38 [06f4] - ***** Scanning Drive C:\ *****
27 Apr 2015 12:27:04 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\ProgramData\Microsoft\Windows\WER\ReportArchive]: LastErr: 5. IGNORING.
27 Apr 2015 12:27:04 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\ProgramData\Microsoft\Windows\WER\ReportQueue]: LastErr: 5. IGNORING.
27 Apr 2015 12:28:32 [1714] - Scanning File C:\System Volume Information\{2b6e36ae-e9b5-11e4-bef2-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [1244] - Scanning File C:\System Volume Information\{03a448f9-ea01-11e4-befc-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [16e8] - Scanning File C:\System Volume Information\{2b6e3acb-e9b5-11e4-bef2-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [170c] - Scanning File C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [16a8] - Scanning File C:\System Volume Information\{2b6e37fd-e9b5-11e4-bef2-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [0d80] - Scanning File C:\System Volume Information\{2b6e3803-e9b5-11e4-bef2-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [16e8] - Scanning File C:\System Volume Information\{ad1b923a-ecf4-11e4-befe-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [1448] - Scanning File C:\System Volume Information\{03a448a5-ea01-11e4-befc-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [1714] - Scanning File C:\System Volume Information\{4a4356ab-e9fc-11e4-bef8-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:28:32 [1244] - Scanning File C:\System Volume Information\{ad1b9234-ecf4-11e4-befe-f4b7e2ab8336}{3808876b-c176-4e48-b7ae-04046e6cc752}
27 Apr 2015 12:29:13 [16e8] - ScanFile (C:\Users\Diane\AppData\Local\Citrix\GoToAssist Corporate\1019\GoToAssist_Corporate_Customer.exe) took 6656 ms
27 Apr 2015 12:29:44 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Diane\AppData\Local\Microsoft\Windows\WER\ReportArchive]: LastErr: 5. IGNORING.
27 Apr 2015 12:29:44 [06f4] - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Diane\AppData\Local\Microsoft\Windows\WER\ReportQueue]: LastErr: 5. IGNORING.
27 Apr 2015 12:37:51 [1244] - ScanFile (C:\Windows\WinSxS\amd64_microsoft-windows-webapi_31bf3856ad364e35_6.2.9200.16384_none_65ee1aeac2568405\Windows.Web.dll) took 5109 ms
 
27 Apr 2015 12:42:43 [06f4] - ***** Checking for specific ITW Viruses *****
 
27 Apr 2015 12:42:43 [06f4] - ***** Scanning complete. *****
 
27 Apr 2015 12:42:43 [06f4] - Total Objects Scanned: 306247
27 Apr 2015 12:42:43 [06f4] - Total Critical Objects: 4
27 Apr 2015 12:42:43 [06f4] - Total Disinfected Objects: 0
27 Apr 2015 12:42:43 [06f4] - Total Objects Renamed: 0
27 Apr 2015 12:42:43 [06f4] - Total Deleted Objects: 4
27 Apr 2015 12:42:43 [06f4] - Total Errors: 3
27 Apr 2015 12:42:43 [06f4] - Time Elapsed: 00:26:50
27 Apr 2015 12:42:43 [06f4] - Virus Database Date: 27 Apr 2015
27 Apr 2015 12:42:43 [06f4] - Virus Database Count: 5762444
27 Apr 2015 12:42:43 [06f4] - Sign Version: 7.60320 [519072]
 
27 Apr 2015 12:42:43 [06f4] - Scan Completed.



#4 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 27 April 2015 - 01:27 PM

Continue with the other scans, when ready. :)



#5 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 27 April 2015 - 01:28 PM

Here is the Zemana log

 

Zemana AntiMalware 2.10.2.18 (Installed)
-------------------------------------------------------
Scan Result           : Completed
Scan Date             : 2015/4/27
Operating System      : Windows 8 64-bit
Processor             : 4X Intel® Core™ i5-3337U CPU @ 1.80GHz
BIOS Mode             : UEFI
CUID                  : 008552E8BB19714DBA9AFF
Scan Type             : Deep Scan
Duration              : 5m 49s
Scanned Objects       : 54370
Detected Objects      : 3
Excluded Objects      : 0
Read Level            : SCSI
Auto Upload           : Yes
Show All Extensions   : No
Scan Documents        : Yes
Engines               : Zemana, Avira, Eset, Bitdefender, AVG, Kaspersky

Detected Objects
-------------------------------------------------------
HP Connected Remote CA
   Status             : Scanned
   Object             : HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB6727E02B96A30F8CA1331AF98507BCA431039\Blob
   MD5                : -
   Publisher          : -
   Size               : -
   Version            : -
   Detections         : Suspicious Root CA
   Cleaning Action    : Delete
   Traces             :
                Registry - HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB6727E02B96A30F8CA1331AF98507BCA431039\Blob

ninja-setup-3.0.6.exe
   Status             : Scanned
   Object             : %userprofile%\downloads\ninja-setup-3.0.6.exe
   MD5                : 24FE0BB7A85A866B487D15C0EB6E3A74
   Publisher          : -
   Size               : 2507200
   Version            : 0.0.0.0
   Detections         : Eset: Win32/OpenCandy potentially unsafe application
   Cleaning Action    : Quarantine
   Traces             :
                File - %userprofile%\downloads\ninja-setup-3.0.6.exe

OCSetupHlp.dll
   Status             : Scanned
   Object             : %temp%\is-p1pj1.tmp\ocsetuphlp.dll
   MD5                : 625EC1DB268E8290E4EA3A1A9E3C5996
   Publisher          : OpenCandy Inc.
   Size               : 782192
   Version            : 1.6.3.239
   Detections         : Eset: Win32/OpenCandy application, Kaspersky: not-a-virus:AdWare.Win32.OpenCandy.j
   Cleaning Action    : Quarantine
   Traces             :
                File - %temp%\is-p1pj1.tmp\ocsetuphlp.dll

Cleaning Result
-------------------------------------------------------
Cleaned               : 3
Reported as safe      : 0
Failed                : 0

 

 

Here is the JRT log

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.5 (04.27.2015:1)
OS: Windows 8 x64
Ran by Diane on Mon 04/27/2015 at 13:14:30.27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Tasks

Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-2697407184-2457862036-328659313-500
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-2889628332-1382817915-9411029-500
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3806650780-565415605-677574695-1001
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3806650780-565415605-677574695-500

 

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL

 

~~~ Registry Keys

 

~~~ Files

 

~~~ Folders

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 04/27/2015 at 13:16:27.12
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

Here is the ADWCleaner log

 

# AdwCleaner v4.202 - Logfile created 27/04/2015 at 13:20:56
# Updated 23/04/2015 by Xplode
# Database : 2015-04-23.2 [Server]
# Operating system : Windows 8  (x64)
# Username : Diane - DIANES-HP-PC
# Running from : C:\Users\Diane\Downloads\adwcleaner_4.202.exe
# Option : Cleaning

***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Scheduled tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

***** [ Web browsers ] *****

-\\ Internet Explorer v10.0.9200.17267

*************************

AdwCleaner[R0].txt - [1015 bytes] - [25/11/2014 18:22:27]
AdwCleaner[R1].txt - [1352 bytes] - [23/04/2015 17:42:38]
AdwCleaner[R2].txt - [929 bytes] - [27/04/2015 13:20:07]
AdwCleaner[S0].txt - [1087 bytes] - [25/11/2014 18:24:47]
AdwCleaner[S1].txt - [1313 bytes] - [23/04/2015 17:44:17]
AdwCleaner[S2].txt - [855 bytes] - [27/04/2015 13:20:56]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [913  bytes] ##########



#6 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 27 April 2015 - 01:30 PM

Adware Removal Tool.
 
Download Adware removal tool to your desktop, right click the icon and select Run as Administrator.

LOr0Gd7.png

Hit Ok.

sYFsqHx.png

Hit next make sure to leave all items checked, for removal.

8NcZjGc.png


The Program will close all open programs to complete the removal, so save any work and hit OK. Then hit OK after the removal process is complete,  then OK again to finish up. Post log generated by tool.

 

Step 2: ZHP Cleaner.

 

Download and save ZHP Cleaner to your desktop.

http://www.nicolascoolman.fr/download/zhpcleaner-2/

Right Click and run as administrator.

Click on the Repair button.

At the end of the process you will be asked to reboot your machine.

After you reboot a report will open on your desktop.

Copy and paste the report here in your next reply.

 

Step 3: Security Check.

 

Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document

 

 

 

Step 4: Minitoolbox.

 

Please download [b]MINITOOLBOX and run it.



Checkmark following boxes:


Flush DNS
Reset FF proxy Settings
Reset Ie Proxy Settings
Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List Devices (problems only)



Click Go and post the result.

 

Eset Scan
 

Disable your antivirus prior to this scan.

http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

 
 
 esetonlinebtn.png
 

  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.


#7 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 27 April 2015 - 03:35 PM

Norton Security removes both ZHP Cleaner and Security Check because it doesn't think they are safe.  Should I turn off Norton or should I skip them?



#8 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 27 April 2015 - 03:36 PM

Here is the log from the Adware Removal Tool

 

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Adware Removal Tool v3.9
Time: 2015_04_27_15_13_29
OS: Windows 8 - 64 Bit
Account Name: Diane
U0L0S11

\\\\\\\\\\\\\\\\\\\\\\\ Repair Logs \\\\\\\\\\\\\\\\\\\\\\

Deleted - RegistryValueData - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}:dllname
Deleted - RegistryValueData - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}:masterclsid
Deleted - RegistryValueData - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}:dllname
Deleted - RegistryValueData - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}:dllname
Deleted - RegistryValueData - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}:dllname
Deleted - RegistryValueData - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}:dllname
Deleted - RegistryKey - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility:{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}
Deleted - RegistryKey - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility:{2EECD738-5844-4A99-B4B6-146BF802613B}
Deleted - RegistryKey - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility:{472734EA-242A-422B-ADF8-83D1E48CC825}
Deleted - RegistryKey - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility:{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Deleted - RegistryKey - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility:{98889811-442D-49DD-99D7-DC866BE87DBC}

\\ Finished



#9 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 27 April 2015 - 03:48 PM

ZHP Cleaner and Security Check are very safe, disable norton and run the scans.



#10 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 27 April 2015 - 05:59 PM

Here is the ZHP Cleaner log

 

~ ZHPCleaner v2015.4.27.194 by Nicolas Coolman (27/04/2015)
~ Run by Diane (Administrator)  (27/04/2015 16:04:26)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\Diane\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Diane\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 8, 64-bit  (Build 9200)

---\\  Services (0)
~ No malicious items found.

---\\  Browser internet (1)
REPLACED Proxy: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyHttp1.1 ( 1 )

---\\  Hosts file (0)
~ No malicious items found.

---\\  Scheduled automatic tasks. (0)
~ No malicious items found.

---\\  Explorer ( File, Folder) (1)
MOVED file: C:\Windows\Prefetch\SOFTWAREUPDATE.EXE-2ED64A89.pf   (PUP.SoftwareUp)

---\\  Registry ( Key, Value, Data) (3)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PConverter_dzbar Uninstall Internet Explorer [Mindspark Interactive Network] (PUP.MindSpark)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent [] (PUP.MindSpark)
DELETED value: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\ConnectionCenter ["C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup] ()

---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Google Chrome)
~ Browser not found (Mozilla Firefox)
~ Browser not found (Opera Software)

---\\ Statistics
~ Items scanned : 660
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 5

End of clean at 16:04:38
===================
ZHPCleaner-[R]-27042015-16_04_38.txt
ZHPCleaner-[S]-27042015-16_02_02.txt

 

Here is the Security Check log

 

 Results of screen317's Security Check version 1.00 
   x64 (UAC is enabled) 
 Internet Explorer 10 Out of date!
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Norton Security Suite  
Windows Defender       
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
  Adobe Flash Player  14.0.0.145 Flash Player out of Date! 
 Adobe Reader XI 
````````Process Check: objlist.exe by Laurent```````` 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````

 

Here is the MiniToolBox log.  The errors for WLANsvc that occurred today were corrected by a reboot.  To me, they were another indication of strange things occurring on this PC.

 

MiniToolBox by Farbar  Version: 14-04-2015
Ran by Diane (administrator) on 27-04-2015 at 16:10:02
Running from "C:\Users\Diane\Downloads"
Microsoft Windows 8  (X64)
Model: HP ENVY TS Sleekbook 4 Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
Hosts file not detected in the default directory
========================= IP Configuration: ================================

Ralink RT3290 802.11bgn Wi-Fi Adapter = Wi-Fi (Connected)
Realtek PCIe GBE Family Controller = Ethernet (Media disconnected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection (Media disconnected)

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 9" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 11" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 13" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled

popd
# End of IPv4 configuration

 

Windows IP Configuration

   Host Name . . . . . . . . . . . . : Dianes-HP-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Bluetooth Network Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
   Physical Address. . . . . . . . . : F4-B7-E2-AB-83-36
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Local Area Connection* 11:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : F4-B7-E2-AB-83-37
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wi-Fi:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Ralink RT3290 802.11bgn Wi-Fi Adapter
   Physical Address. . . . . . . . . : F4-B7-E2-AB-83-35
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::7ce6:509d:c031:6df0%13(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.0.0.7(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, April 27, 2015 3:10:43 PM
   Lease Expires . . . . . . . . . . : Monday, May 4, 2015 3:10:49 PM
   Default Gateway . . . . . . . . . : 10.0.0.1
   DHCP Server . . . . . . . . . . . : 10.0.0.1
   DHCPv6 IAID . . . . . . . . . . . : 234141666
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-18-DC-25-6A-6C-3B-E5-82-6A-E4
   DNS Servers . . . . . . . . . . . : 208.67.222.222
                                       208.67.220.220
   NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Ethernet:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : 6C-3B-E5-82-6A-E4
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 14:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fd:2c20:1206:f5ff:fff8(Preferred)
   Link-local IPv6 Address . . . . . : fe80::2c20:1206:f5ff:fff8%17(Preferred)
   Default Gateway . . . . . . . . . : ::
   NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter isatap.{2D4F6A27-BA70-4E1D-95D7-A4D5CD57BA27}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #6
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  resolver1.opendns.com
Address:  208.67.222.222

Name:    google.com
Addresses:  2607:f8b0:4009:80a::200e
   216.58.216.78

Pinging google.com [216.58.216.78] with 32 bytes of data:
Reply from 216.58.216.78: bytes=32 time=11ms TTL=54
Reply from 216.58.216.78: bytes=32 time=19ms TTL=54

Ping statistics for 216.58.216.78:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 11ms, Maximum = 19ms, Average = 15ms
Server:  resolver1.opendns.com
Address:  208.67.222.222

Name:    yahoo.com
Addresses:  206.190.36.45
   98.138.253.109
   98.139.183.24

Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=52ms TTL=52
Reply from 98.139.183.24: bytes=32 time=42ms TTL=52

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 42ms, Maximum = 52ms, Average = 47ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 23...f4 b7 e2 ab 83 36 ......Bluetooth Device (Personal Area Network)
 15...f4 b7 e2 ab 83 37 ......Microsoft Wi-Fi Direct Virtual Adapter
 13...f4 b7 e2 ab 83 35 ......Ralink RT3290 802.11bgn Wi-Fi Adapter
 12...6c 3b e5 82 6a e4 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 14...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 17...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 25...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0         10.0.0.1         10.0.0.7     25
         10.0.0.0    255.255.255.0         On-link          10.0.0.7    281
         10.0.0.7  255.255.255.255         On-link          10.0.0.7    281
       10.0.0.255  255.255.255.255         On-link          10.0.0.7    281
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link          10.0.0.7    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link          10.0.0.7    281
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 17    306 ::/0                     On-link
  1    306 ::1/128                  On-link
 17    306 2001::/32                On-link
 17    306 2001:0:5ef5:79fd:2c20:1206:f5ff:fff8/128
                                    On-link
 13    281 fe80::/64                On-link
 17    306 fe80::/64                On-link
 17    306 fe80::2c20:1206:f5ff:fff8/128
                                    On-link
 13    281 fe80::7ce6:509d:c031:6df0/128
                                    On-link
  1    306 ff00::/8                 On-link
 17    306 ff00::/8                 On-link
 13    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\NLAapi.dll [55296] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog5 08 C:\Windows\SysWOW64\wshbth.dll [50688] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [66560] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [72192] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [53760] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog5 08 C:\Windows\System32\wshbth.dll [64000] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/27/2015 01:03:43 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service HP Network Devices Support since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (04/27/2015 10:46:27 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x2af8
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 10:44:20 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x1d64
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 10:43:58 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x21f4
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 09:45:01 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x2b34
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 09:43:14 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x1914
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 09:34:22 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x23d4
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 09:32:38 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x2af0
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 09:26:53 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x22a8
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 09:25:18 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0xea0
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

System errors:
=============
Error: (04/27/2015 04:10:05 PM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/27/2015 04:10:05 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Error: (04/27/2015 04:07:20 PM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/27/2015 04:07:20 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Error: (04/27/2015 03:18:45 PM) (Source: Service Control Manager) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056

Error: (04/27/2015 03:18:29 PM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/27/2015 03:18:15 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (04/27/2015 03:10:50 PM) (Source: Service Control Manager) (User: )
Description: The SSDP Discovery service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/27/2015 03:10:50 PM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/27/2015 03:10:50 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Microsoft Office Sessions:
=========================
Error: (04/27/2015 01:03:43 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service HP Network Devices Support since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (04/27/2015 10:46:27 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf4532af801d081010782bfddC:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll901b0370-ecf4-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 10:44:20 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf4531d6401d08100fa6a1456C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll449b76f0-ecf4-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 10:43:58 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf45321f401d080f8bdee1408C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll37a8f223-ecf4-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 09:45:01 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf4532b3401d080f87e3ef849C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dllfb044242-eceb-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 09:43:14 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf453191401d080f7411dfafbC:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dllbb6860d8-eceb-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 09:34:22 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf45323d401d080f703364691C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll7e344fa0-ecea-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 09:32:38 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf4532af001d080f635ba13a6C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll4047ae0c-ecea-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 09:26:53 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf45322a801d080f5fd53869aC:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll72cb7bf3-ece9-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 09:25:18 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf453ea001d080f57f506ec7C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll3a6516b5-ece9-11e4-befd-f4b7e2ab8336

 

=========================== Installed Programs ============================
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.1.0.8 - Absolute Software)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.)
Airport Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Azteca (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.98 - WildTangent) Hidden
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
Build-a-lot (x32 Version: 2.2.0.98 - WildTangent) Hidden
Citrix Authentication Manager (x32 Version: 5.1.0.62606 - Citrix Systems, Inc.) Hidden
Citrix Online Launcher (HKLM-x32\...\{77463C86-BB3A-426E-A6C2-06B4D28C250F}) (Version: 1.0.223 - Citrix)
Citrix Receiver (HDX Flash Redirection) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.1.0.0 - Citrix Systems, Inc.)
Citrix Receiver Inside (x32 Version: 4.1.0.56471 - Citrix Systems, Inc.) Hidden
Citrix Receiver Updater (x32 Version: 4.1.0.56461 - Citrix Systems, Inc.) Hidden
Citrix Receiver(Aero) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver(DV) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver(USB) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.)
CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)
CyberLink PowerDVD (x32 Version: 10.0.6.4319 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.6.6119 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.6.6119 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Family Tree Maker 2012 (HKLM-x32\...\Family Tree Maker 2012) (Version: 21.0.388 - Ancestry.com, Inc.)
Family Tree Maker 2012 (x32 Version: 21.0.388 - Ancestry.com, Inc.) Hidden
FATE: The Cursed King (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 11.0.0.1019 - Citrix Online, a division of Citrix Systems, Inc.)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden
HP 3D DriveGuard (HKLM\...\{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP CoolSense (HKLM-x32\...\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}) (Version: 2.10.51 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Documentation (HKLM-x32\...\{73A33079-D1A0-4469-8903-C4A48B4975E2}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP MyRoom (HKLM-x32\...\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company)
HP Officejet 6700 Basic Device Software (HKLM\...\{A1CFA587-90D4-4DE6-B200-68CC0F92252F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6700 Help (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard)
HP Officejet 6700 Product Improvement Study (HKLM\...\{988D55BB-08DE-43C9-8D16-3751361E2A79}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Quick Launch (HKLM-x32\...\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company)
HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden
HP Registration Service (HKLM\...\{C2E428EB-116E-41C0-9E84-B22DE9CCA42F}) (Version: 1.1.6232.4245 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.8 - Hewlett-Packard)
HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2867 - Intel Corporation)
Intel® Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 2.1.0.1002 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.9.1002 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1108.0727 - Microsoft) Hidden
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.1 - Nikon)
Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.2 - Nikon)
Norton Security Suite (HKLM-x32\...\N360) (Version: 21.7.0.11 - Symantec Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Online Plug-in (HKLM-x32\...\{7BD3DC6D-A2BE-4345-B6EE-D146193DB18F}) (Version: 13.4.0.25 - Citrix Systems, Inc.)
Online Plug-in (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.5.1 - Nikon)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Ralink Bluetooth Stack (HKLM\...\{C079427A-BB28-5168-3DB1-DC6608D226D4}) (Version: 11.0.748.2 - Mediatek)
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.5.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.9200.27029 - Realtek Semiconductor Corp.)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Self-service Plug-in (x32 Version: 4.1.0.41738 - Citrix Systems, Inc.) Hidden
Sonos Controller (HKLM-x32\...\{7BBA9BF8-05DF-47D8-8880-82A9B99505B9}) (Version: 28.1.83040 - Sonos, Inc.)
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 16.5.3.3 - Synaptics Incorporated)
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: 7.3.0.5 - 2BrightSparks)
The Treasures of Mystery Island: The Ghost Ship (x32 Version: 2.2.0.98 - WildTangent) Hidden
True Image 2013 (HKLM-x32\...\{75BC2136-B6A1-4F3B-8A69-55E39C647B1F}Visible) (Version: 16.0.6514 - Acronis)
True Image 2013 (x32 Version: 16.0.6514 - Acronis) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.9.2 - Nikon)
VIP Access (HKLM-x32\...\{97C89A11-9AD7-49CE-9F90-54BF075623CE}) (Version: 2.1.1.34 - Symantec Corporation)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.9.7 - WildTangent) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden

========================= Devices: ================================

Name: Officejet 6700
Description: Officejet 6700
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Device ID: ROOT\MULTIFUNCTION\0000
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

========================= Memory info: ===================================

Percentage of memory in use: 43%
Total physical RAM: 3992.27 MB
Available physical RAM: 2247.83 MB
Total Pagefile: 5336.27 MB
Available Pagefile: 3537.1 MB
Total Virtual: 4095.88 MB
Available Virtual: 3967.64 MB

========================= Partitions: =====================================

1 Drive c: (OS) (Fixed) (Total:434.35 GB) (Free:356.46 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:30.64 GB) (Free:3.57 GB) NTFS

========================= Users: ========================================

User accounts for \\DIANES-HP-PC

Administrator            Diane                    Guest                   

**** End of log ****

 

Here is the ESET Scan log

 

C:\Users\All Users\{484395D8-1F9B-4C71-9DA9-A64CBD0E8DE2}\setup.res a variant of Win32/HiddenStart.A potentially unsafe application 
C:\Program Files\Adware-Removal-Tool\ARTP3.exe MSIL/FakeTool.PS trojan cleaned by deleting - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\APPINTEGRATOR.EXE a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\AppIntegrator64.exe Win64/Toolbar.MyWebSearch.D potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\APPINTEGRATORSTUB.DLL a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\AppIntegratorStub64.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\ASSISTMONITOR.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\ASSISTMONITOR64.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\CREXT.DLL a variant of Win32/Toolbar.MyWebSearch.Z potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzbar.dll a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzbarsvc.exe a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzbprtct.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzdatact.dll a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzdlghk.dll a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzdlghk64.dll a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzfeedmg.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzhighin.exe a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzhkstub.dll a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzhtmlmu.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzhttpct.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzidle.dll a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzmedint.exe a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzmlbtn.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzPlugin.dll a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzreghk.dll a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzregiet.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzscript.dll a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzskin.dll a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzskplay.exe a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dzSrcAs.dll a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\dztpinst.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\FF-NativeMessagingDispatcher.dll a variant of Win32/Toolbar.MyWebSearch.AO potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\HPG.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\Hpg64.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\T8EPMSUP.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\T8EXTEX.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\T8EXTPEX.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\T8HTML.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\T8TICKER.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\TOOLBARGUARD.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\TOOLBARGUARD64.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\TPIMANAGERCONSOLE.EXE Win32/Toolbar.MyWebSearch.AI potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\VERIFY.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL a variant of Win64/Toolbar.MyWebSearch.C potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\PConverter_dz\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE a variant of Win32/Toolbar.MyWebSearch.AF potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dzEI\Installr\1.bin\dzEIPlug.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dzEI\Installr\1.bin\dzEZSETP.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\Program Files (x86)\PConverter_dzEI\Installr\1.bin\NPdzEISb.dll a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application deleted - quarantined
C:\ProgramData\{484395D8-1F9B-4C71-9DA9-A64CBD0E8DE2}\setup.res a variant of Win32/HiddenStart.A potentially unsafe application deleted - quarantined
C:\Users\Diane\AppData\LocalLow\PConverter_dzEI\Installr\Cache\005F4E21.exe a variant of Win32/Toolbar.MyWebSearch.O potentially unwanted application deleted - quarantined
C:\Users\Diane\Downloads\ccsetup418.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined
C:\Users\Diane\Downloads\PConverter.exe a variant of Win32/AdInstaller potentially unwanted application deleted - quarantined
C:\Users\Diane\Downloads\spsetup128.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined
Operating memory a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application contained infected files

 

 

The PConverter entries that ESET found were picked up by accident when I clicked on the wrong Download when trying to download ZHP Cleaner.  After running ESET Scan I rebooted in order to make sure items were removed and to restart Norton for my firewall and AV.
 

 



#11 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 27 April 2015 - 07:12 PM

How is your machine now?



#12 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 27 April 2015 - 07:47 PM

I haven't used it a lot since the ESET scan, but everything seems to be OK.  I'll see it goes tonight and tomorrow.  Thanks for all of your help.



#13 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 27 April 2015 - 07:50 PM

Qualys BrowserCheck To update plugins.

Safe Browsing Tool Web of trust to keep away from shady sites.

Unchecky  To avoid bundled software.

Adblock Plus  To browse the web ad free.

Malwarebytes Anti-Exploit To block Zero day attacks.

Malwarebytes | StartUpLITE To disable un-needed start ups.

 

 

 

Download DelFix by "Xplode" to your Desktop.
Right Click the tool and Run as Admin ( Xp Users Double Click)
Put a check mark next the items below:


Remove disinfection tools
Create registry backup
Purge System Restore




Now click on "Run" button.
allow the program to complete its work.
all the tools we used will be removed.
Tool will create and open a log report (DelFix.txt)
Note: The report can be located at the following location C:\DelFix.txt



#14 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 28 April 2015 - 07:49 AM

I've run DelFix and rebooted.  I'm reviewing the items that were at the top of your last reply.  Everything seems to be running OK.  My wife didn't use the laptop much last night, but she didn't encounter anything strange.  I had hoped she was going to work remotely today in order to give it a good test, but she had to go in for a meeting.

 

Today I downloaded and ran MiniToolBox after a reboot around 7:30 AM.  I still see the HTTP Service error messages.  This error may be due to a corrupted file that may have been caused by a virus, malware, or something else.  Should I open an issue with the Microsoft Community or a Windows forum for this error?  Is this something I should not be concerned with?  The MiniToolBox log is below.  The entries from 4/27 were resolved by the tools run yesterday.  It is the entries from today, 4/28, that I'm concerned about.

 

MiniToolBox by Farbar  Version: 14-04-2015
Ran by Diane (administrator) on 28-04-2015 at 07:34:14
Running from "C:\Users\Diane\Downloads"
Microsoft Windows 8  (X64)
Model: HP ENVY TS Sleekbook 4 Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************
Hosts file not detected in the default directory
========================= IP Configuration: ================================

Ralink RT3290 802.11bgn Wi-Fi Adapter = Wi-Fi (Connected)
Realtek PCIe GBE Family Controller = Ethernet (Media disconnected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection (Media disconnected)

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 9" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 11" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 13" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled

popd
# End of IPv4 configuration

 

Windows IP Configuration

   Host Name . . . . . . . . . . . . : Dianes-HP-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Bluetooth Network Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
   Physical Address. . . . . . . . . : F4-B7-E2-AB-83-36
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Local Area Connection* 11:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : F4-B7-E2-AB-83-37
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wi-Fi:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Ralink RT3290 802.11bgn Wi-Fi Adapter
   Physical Address. . . . . . . . . : F4-B7-E2-AB-83-35
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::7ce6:509d:c031:6df0%13(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.0.0.7(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Tuesday, April 28, 2015 7:32:29 AM
   Lease Expires . . . . . . . . . . : Tuesday, May 5, 2015 7:34:11 AM
   Default Gateway . . . . . . . . . : 10.0.0.1
   DHCP Server . . . . . . . . . . . : 10.0.0.1
   DNS Servers . . . . . . . . . . . : 208.67.222.222
                                       208.67.220.220
   NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Ethernet:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : 6C-3B-E5-82-6A-E4
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 14:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6ab8:1022:f17:f5ff:fff8(Preferred)
   Link-local IPv6 Address . . . . . : fe80::1022:f17:f5ff:fff8%17(Preferred)
   Default Gateway . . . . . . . . . : ::
   NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter isatap.{2D4F6A27-BA70-4E1D-95D7-A4D5CD57BA27}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #6
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  resolver1.opendns.com
Address:  208.67.222.222

Name:    google.com
Addresses:  2607:f8b0:4009:807::1009
   216.58.216.238

Pinging google.com [173.194.46.100] with 32 bytes of data:
Reply from 173.194.46.100: bytes=32 time=11ms TTL=54
Reply from 173.194.46.100: bytes=32 time=11ms TTL=54

Ping statistics for 173.194.46.100:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 11ms, Maximum = 11ms, Average = 11ms
Server:  resolver1.opendns.com
Address:  208.67.222.222

Name:    yahoo.com
Addresses:  98.139.183.24
   98.138.253.109
   206.190.36.45

Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=43ms TTL=52
Reply from 98.139.183.24: bytes=32 time=51ms TTL=52

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 43ms, Maximum = 51ms, Average = 47ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 23...f4 b7 e2 ab 83 36 ......Bluetooth Device (Personal Area Network)
 15...f4 b7 e2 ab 83 37 ......Microsoft Wi-Fi Direct Virtual Adapter
 13...f4 b7 e2 ab 83 35 ......Ralink RT3290 802.11bgn Wi-Fi Adapter
 12...6c 3b e5 82 6a e4 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 14...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 17...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 25...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0         10.0.0.1         10.0.0.7     25
         10.0.0.0    255.255.255.0         On-link          10.0.0.7    281
         10.0.0.7  255.255.255.255         On-link          10.0.0.7    281
       10.0.0.255  255.255.255.255         On-link          10.0.0.7    281
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link          10.0.0.7    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link          10.0.0.7    281
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 17    306 ::/0                     On-link
  1    306 ::1/128                  On-link
 17    306 2001::/32                On-link
 17    306 2001:0:9d38:6ab8:1022:f17:f5ff:fff8/128
                                    On-link
 13    281 fe80::/64                On-link
 17    306 fe80::/64                On-link
 17    306 fe80::1022:f17:f5ff:fff8/128
                                    On-link
 13    281 fe80::7ce6:509d:c031:6df0/128
                                    On-link
  1    306 ff00::/8                 On-link
 17    306 ff00::/8                 On-link
 13    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\NLAapi.dll [55296] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog5 08 C:\Windows\SysWOW64\wshbth.dll [50688] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [66560] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [72192] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [53760] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog5 08 C:\Windows\System32\wshbth.dll [64000] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/27/2015 04:13:51 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (04/27/2015 04:13:48 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (04/27/2015 04:13:26 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (04/27/2015 04:13:26 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (04/27/2015 04:13:19 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (04/27/2015 04:12:42 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (04/27/2015 01:03:43 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service HP Network Devices Support since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (04/27/2015 10:46:27 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x2af8
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 10:44:20 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x1d64
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

Error: (04/27/2015 10:43:58 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_WlanSvc, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: wlansvc.dll, version: 6.2.9200.16451, time stamp: 0x50986d38
Exception code: 0xc0000005
Fault offset: 0x00000000000bf453
Faulting process id: 0x21f4
Faulting application start time: 0xsvchost.exe_WlanSvc0
Faulting application path: svchost.exe_WlanSvc1
Faulting module path: svchost.exe_WlanSvc2
Report Id: svchost.exe_WlanSvc3
Faulting package full name: svchost.exe_WlanSvc4
Faulting package-relative application ID: svchost.exe_WlanSvc5

System errors:
=============
Error: (04/28/2015 07:34:16 AM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/28/2015 07:34:16 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Error: (04/28/2015 07:34:12 AM) (Source: Service Control Manager) (User: )
Description: The SSDP Discovery service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/28/2015 07:34:12 AM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/28/2015 07:34:12 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Error: (04/28/2015 07:34:12 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1068

Error: (04/28/2015 07:34:12 AM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/28/2015 07:34:12 AM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Provider Host service depends on the HTTP Service service which failed to start because of the following error:
%%1009

Error: (04/28/2015 07:34:12 AM) (Source: Service Control Manager) (User: )
Description: The HTTP Service service failed to start due to the following error:
%%1009

Error: (04/28/2015 07:34:12 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueType=0 Index=2

Microsoft Office Sessions:
=========================
Error: (04/27/2015 04:13:51 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Diane\Downloads\esetsmartinstaller_enu.exe

Error: (04/27/2015 04:13:48 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Diane\Downloads\esetsmartinstaller_enu.exe

Error: (04/27/2015 04:13:26 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Diane\Downloads\esetsmartinstaller_enu.exe

Error: (04/27/2015 04:13:26 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Diane\Downloads\esetsmartinstaller_enu.exe

Error: (04/27/2015 04:13:19 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Diane\Downloads\esetsmartinstaller_enu (1).exe

Error: (04/27/2015 04:12:42 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Diane\Downloads\esetsmartinstaller_enu.exe

Error: (04/27/2015 01:03:43 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service HP Network Devices Support since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (04/27/2015 10:46:27 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf4532af801d081010782bfddC:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll901b0370-ecf4-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 10:44:20 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf4531d6401d08100fa6a1456C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll449b76f0-ecf4-11e4-befd-f4b7e2ab8336

Error: (04/27/2015 10:43:58 AM) (Source: Application Error)(User: )
Description: svchost.exe_WlanSvc6.2.9200.16420505a9a4ewlansvc.dll6.2.9200.1645150986d38c000000500000000000bf45321f401d080f8bdee1408C:\Windows\System32\svchost.exec:\windows\system32\wlansvc.dll37a8f223-ecf4-11e4-befd-f4b7e2ab8336

========================= Minidump Files ==================================

No minidump file found

**** End of log ****



#15 GaryG45

GaryG45
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vernon Hills, IL
  • Local time:08:15 AM

Posted 28 April 2015 - 08:42 AM

I looked at the Event Viewer Summary of Administrative Events and the found the following error events for HttpEvent.

An error occurred while using SSL configuration for endpoint Type=0 Index=2.  The error status code is contained within the returned data.

Event ID = 15021, Locale ID= 1033.

I've had 25 of them in the last hour and 1945 in the past 7 days.

I have Googled this message and cannot find anything that matches my exact message.  It may be related to a bad certificate on the laptop.  I plan to open an issue on the Microsoft forum, if I don't find anything with a couple more searches.

Thanks again for all of your help.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users