GotoMeeting - view recorded webinar - issues.

  • 7 November 2013
  • 2 replies
  • 17 views

Userlevel 5
Badge +22
I am sure this is a configuration issue but I can't find it, yet.  Here are the symptoms.
 
I can go to GoToMeeting to test connectivity and it says I'm successful.
Open a link to a recorded webinar and then click "View Recorded Webinar", Windows Media Player starts but then states there is an error.  Help suggests a codec issue....
Shutting down Webroot allows the webinar to play.
Shut down all applications and restarting Webroot and the webinar can be restarted and played.
 
PC Security
View Active Connnections:  No process is blocked
Quarantine: empty
Block/Allow Files:  empty
 
Identity Protection
Application Protection:   three apps listed (2 IE (in folder x86 and the other), and Keepass are listed, all are protect)
 
I know this is something done to myself.  Any suggestions?

2 replies

Userlevel 7
Badge +6
Right click the (W) in the taskbar > Save scan log
 
Please paste the last 40 lines.
Userlevel 5
Badge +22
Interesting, the original reply didn't get posted. 
 
Here are four entries that you might have wanted.
 
The most recent Media Player entries showing no issues:
Wed 2013-11-06 17:05:17.0930 Monitoring process C:Program Files (x86)Windows Media Playerwmplayer.exe [A80C173AC5C75706BB74AE4D78F2A53D]. Type: 1 (663)
Wed 2013-11-06 17:05:17.0930 Monitoring process C:Program Files (x86)Windows Media Playerwmplayer.exe [A80C173AC5C75706BB74AE4D78F2A53D]. Type: 0 (663)
 
Earlier entries with one showing a blocked process:
Wed 2013-11-06 16:52:47.0222 Blocked process from connecting to the Internet: C:Program Files (x86)Windows Media Playerwmplayer.exe [MD5: A80C173AC5C75706BB74AE4D78F2A53D]
Wed 2013-11-06 16:52:47.0222 Monitoring process C:Program Files (x86)Windows Media Playerwmplayer.exe [A80C173AC5C75706BB74AE4D78F2A53D]. Type: 1 (663)
 
So, the log shows a blocked process.  However, (per documentation) the only way to check blocked processes is in "PC Security > Tab: Scan & Shields > View Active Connections" where nothing is blocked.
wmpnscfg.exe, wmpnetwk.exe, wmplayer.exe are all allowed.  I might have missed some because there are 32 pages of processes and no way to sort by name, allowed, or blocked.
 
Here are the last 40 entries from the log:
Wed 2013-11-06 20:51:03.0262 Monitoring process C:Windowssystem32defrag.exe [8FD0EC6EB52F9EFE15B7A605C827932C]. Type: 0 (2516)
Wed 2013-11-06 20:51:03.0280 Monitoring process C:WindowsSystem32conhost.exe [BF95EA5809E3BBF55370F7CB309FEBD0]. Type: 0 (1267)
Wed 2013-11-06 20:51:03.0327 Monitoring process C:Windowssystem32svchost.exe [C78655BC80301D76ED4FEF1C1EA40A7D]. Type: 1 (180)
Wed 2013-11-06 20:51:03.0327 Monitoring process C:Windowssystem32svchost.exe [C78655BC80301D76ED4FEF1C1EA40A7D]. Type: 0 (180)
Wed 2013-11-06 21:02:44.0263 Monitoring process C:Windowssystem32 askhost.exe [639774C9ACD063F028F6084ABF5593AD]. Type: 1 (308)
Wed 2013-11-06 21:02:44.0263 Monitoring process C:Windowssystem32 askhost.exe [639774C9ACD063F028F6084ABF5593AD]. Type: 0 (308)
Wed 2013-11-06 21:11:31.0339 Monitoring process C:Windowssystem32 askhost.exe [639774C9ACD063F028F6084ABF5593AD]. Type: 1 (308)
Wed 2013-11-06 21:11:31.0339 Monitoring process C:Windowssystem32 askhost.exe [639774C9ACD063F028F6084ABF5593AD]. Type: 0 (308)
Wed 2013-11-06 21:14:03.0455 Scan Started:  [ID: 9 - Flags: 1575/16]
Wed 2013-11-06 21:15:22.0181 Connected to C1
Wed 2013-11-06 21:15:22.0182 Monitoring process C:Program FilesMy Dellimstrayicon.exe [F9227540962792BBED4791281377927A]. Type: 0 (4965)
Wed 2013-11-06 21:15:22.0183 Monitoring process C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [ADDA5E1951B90D3D23C56D3CF0622ADC]. Type: 1 (376)
Wed 2013-11-06 21:15:22.0183 Monitoring process C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [ADDA5E1951B90D3D23C56D3CF0622ADC]. Type: 0 (376)
Wed 2013-11-06 21:15:22.0184 Monitoring process C:Program FilesIDTWDMstacsv64.exe [B00068BA94F5F306911B14B425AAEB56]. Type: 1 (690)
Wed 2013-11-06 21:15:22.0184 Monitoring process C:Program FilesIDTWDMstacsv64.exe [B00068BA94F5F306911B14B425AAEB56]. Type: 0 (690)
Wed 2013-11-06 21:15:22.0186 Monitoring process C:Program FilesWebrootWRSA.exe [232E78FCDC8AEF780EDB5F1AE4C77934]. Type: 1 (6802)
Wed 2013-11-06 21:15:22.0186 Monitoring process C:Program FilesWebrootWRSA.exe [232E78FCDC8AEF780EDB5F1AE4C77934]. Type: 0 (6802)
Wed 2013-11-06 21:15:22.0186 Monitoring process C:Program FilesWebrootWRSA.exe [232E78FCDC8AEF780EDB5F1AE4C77934]. Type: 1 (6802)
Wed 2013-11-06 21:15:23.0202 Scan Results: Files Scanned: 31904, Duration: 1m 19s, Malicious Files: 0
Wed 2013-11-06 21:15:23.0222 Scan Finished: [ID: 9 - Seq: 82178127]
Wed 2013-11-06 21:30:00.0003 Monitoring process C:Windowssystem32 askeng.exe [65EA57712340C09B1B0C427B4848AE05]. Type: 1 (1304)
Wed 2013-11-06 21:30:00.0003 Monitoring process C:Windowssystem32 askeng.exe [65EA57712340C09B1B0C427B4848AE05]. Type: 0 (1304)
Wed 2013-11-06 21:30:00.0149 Monitoring process C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [A283108E14F3970432C21AF4C0CB1BCE]. Type: 1 (957)
Wed 2013-11-06 21:30:00.0149 Monitoring process C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [A283108E14F3970432C21AF4C0CB1BCE]. Type: 0 (957)
Wed 2013-11-06 21:30:00.0179 Monitoring process C:WindowsSystem32conhost.exe [BF95EA5809E3BBF55370F7CB309FEBD0]. Type: 0 (1267)
Wed 2013-11-06 21:30:00.0209 Monitoring process C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [A283108E14F3970432C21AF4C0CB1BCE]. Type: 1 (957)
Wed 2013-11-06 21:30:00.0209 Monitoring process C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [A283108E14F3970432C21AF4C0CB1BCE]. Type: 0 (957)
Wed 2013-11-06 21:32:15.0263 Monitoring process C:Windowssystem32defrag.exe [8FD0EC6EB52F9EFE15B7A605C827932C]. Type: 1 (2516)
Wed 2013-11-06 21:32:15.0263 Monitoring process C:Windowssystem32defrag.exe [8FD0EC6EB52F9EFE15B7A605C827932C]. Type: 0 (2516)
Wed 2013-11-06 21:32:15.0281 Monitoring process C:WindowsSystem32conhost.exe [BF95EA5809E3BBF55370F7CB309FEBD0]. Type: 0 (1267)
Wed 2013-11-06 21:32:15.0329 Monitoring process C:Windowssystem32svchost.exe [C78655BC80301D76ED4FEF1C1EA40A7D]. Type: 1 (180)
Wed 2013-11-06 21:32:15.0329 Monitoring process C:Windowssystem32svchost.exe [C78655BC80301D76ED4FEF1C1EA40A7D]. Type: 0 (180)
Wed 2013-11-06 21:53:24.0261 Monitoring process C:Windowssystem32SearchProtocolHost.exe [D9E21CBF9E6A87847AFFD39EA3FA28EE]. Type: 1 (823)
Wed 2013-11-06 21:53:24.0261 Monitoring process C:Windowssystem32SearchProtocolHost.exe [D9E21CBF9E6A87847AFFD39EA3FA28EE]. Type: 0 (823)
Wed 2013-11-06 21:53:24.0302 Monitoring process C:Windowssystem32SearchFilterHost.exe [49A3AD5CE578CD77F445F3D244AEAB2D]. Type: 0 (761)
Wed 2013-11-06 22:01:33.0990 Monitoring process C:Windowssystem32SearchProtocolHost.exe [D9E21CBF9E6A87847AFFD39EA3FA28EE]. Type: 1 (823)
Wed 2013-11-06 22:01:33.0990 Monitoring process C:Windowssystem32SearchProtocolHost.exe [D9E21CBF9E6A87847AFFD39EA3FA28EE]. Type: 0 (823)
Wed 2013-11-06 22:01:34.0043 Monitoring process C:Windowssystem32SearchFilterHost.exe [49A3AD5CE578CD77F445F3D244AEAB2D]. Type: 0 (761)
Wed 2013-11-06 22:01:34.0275 Monitoring process C:Windowssystem32 askhost.exe [639774C9ACD063F028F6084ABF5593AD]. Type: 1 (308)
Wed 2013-11-06 22:01:34.0276 Monitoring process C:Windowssystem32 askhost.exe [639774C9ACD063F028F6084ABF5593AD]. Type: 0 (308).

Reply