1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
  2. Welcome to iHelpForum - the place to get help from knowledgeable techs in all areas of Tech, Home and Auto help. Consider checking out our Guides or Registering an account to post on our forums today.

    Dismiss Notice

Solved Slow Computer

Discussion in 'Virus, Spyware and Malware Removal Help' started by brewster393, May 20, 2015.

  1. driver_ian

    driver_ian In at the Deep End... Administrator iHF Legend Security Advisor

    Joined:
    May 2, 2014
    Messages:
    2,388
    Likes Received:
    523
    Trophy Points:
    123
    Instructions in how to create a new user account can be found here. Ensure you give the new account Administrators rights...
     
  2. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Yes lets see if creating a new admin account will help. :)
     
  3. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93

    Is ethernet running any quicker for you? Can you bypass the router and plug directly into the modem?
     
  4. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and salutations!
    I'm obviously missing something simple here, but when I try and activate the new user account all I get is "The User Profile Service service failed the logon. User profile cannot be loaded".

    I'm afraid there's no difference in the speed with ethernet, and I'm unable to by-pass the router because the ethernet sockets are in the back of it (yellow). The modem has just got the infinity socket on it (red).
     
  5. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    I am not seeing any issue with your connection, I think you need a repair install here.



    Also I am not seeing anymore malware on your machine, can you post a FRESH FRST log prior to doing the repair install, so I can have one last look to see, make sure and tick addition.txt as well.

    Download attached fixlist.txt file and save it to the Desktop.

    NOTE. It's important that both files, FRST/FRST64andfixlist.txt are in the same location or the fix will not work.

    NOTICE:This script was written specifically for this user,for use on that particular machine.Running this on another machine may cause damage to your operating system

    RunFRST/FRST64and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally.After that let the tool complete its run.When finished FRST will generate a log on the Desktop(Fixlog.txt).Please post it to your reply.

    Hey Brewster, I will be active today. No work so we may be able to get something done.
     

    Attached Files:

    Last edited by a moderator: May 31, 2015
  6. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and salutations!
    O.K. As requested:-
    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-05-2015
    Ran by Brewster (administrator) on BREWSTER-PUTER on 31-05-2015 15:27:40
    Running from C:\Users\Brewster\Desktop
    Loaded Profiles: Brewster (Available Profiles: Brewster & Margies)
    Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    () C:\Program Files\Reason\Security\Protection\rscp\bin\rscp_svc.exe
    (Reason Software Company Inc.) C:\Program Files\Reason\Security\rsEngineSvc.exe
    (TG Soft Sas www.tgsoft.it) C:\VEXPLite\viritsvc.exe
    (Zemana Ltd.) C:\Program Files\Zemana AntiMalware\ZAM.exe
    () C:\Program Files\Reason\Security\Protection\rscp\bin\rscp_bg.exe
    () C:\Program Files\RocketDock\RocketDock.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
    (Reason Software Company Inc.) C:\Program Files\Reason\Security\rsUI.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
    (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
    (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2014-04-11] (Citrix Online, a division of Citrix Systems, Inc.)
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] ()
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
    BootExecute: autocheck autochk /p \??\H:autocheck autochk *

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    SearchScopes: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
    BHO: VirIT eXplorer Antivirus -> {373BCD12-5B7A-4c09-897B-6B42EC48B0F8} -> C:\VEXPLite\viritie.dll [2013-05-03] (TG Soft S.a.s. - www.tgsoft.it)
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-24] (Oracle Corporation)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-24] (Oracle Corporation)
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
    Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
    Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254

    FireFox:
    ========
    FF ProfilePath: C:\Users\Brewster\AppData\Roaming\Mozilla\Firefox\Profiles\yabp1zv0.default-1432304493341
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-17] ()
    FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
    FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-24] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-24] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Motive.com/NpMotive,version=1.0 -> C:\Program Files\Common Files\Motive\npMotive.dll [2012-10-05] (Alcatel-Lucent)
    FF Plugin: @Motive.com/npMotiveRequest,version=1.0 -> C:\Program Files\Common Files\Motive\npMotiveRequest.dll [2011-12-06] (Alcatel-Lucent)
    FF Plugin: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Brewster\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-04-15] (RocketLife, LLP)
    FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
    FF Extension: Motive Extension - C:\Program Files\Mozilla Firefox\browser\extensions\mcciwbch@motive.com.xpi [2015-03-22]

    Chrome:
    =======
    CHR Profile: C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Docs) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-02]
    CHR Extension: (Google Drive) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-02]
    CHR Extension: (YouTube) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-02]
    CHR Extension: (Google Search) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-02]
    CHR Extension: (avast! Online Security) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-06-02]
    CHR Extension: (Google Wallet) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-02]
    CHR Extension: (Gmail) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-02]

    ========================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-10-03] (SUPERAntiSpyware.com)
    S4 BT Help Wizard; C:\Program Files\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe [321024 2014-04-09] (Alcatel-Lucent) [File not signed]
    S3 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2014-04-11] (Citrix Online, a division of Citrix Systems, Inc.)
    S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
    R2 rscp; C:\Program Files\Reason\Security\Protection\rscp\bin\rscp_svc.exe [164600 2015-05-28] ()
    R2 rsEngineSvc; C:\Program Files\Reason\Security\rsEngineSvc.exe [81168 2015-05-18] (Reason Software Company Inc.)
    R2 viritsvclite; C:\VEXPLite\viritsvc.exe [106496 2015-02-02] (TG Soft Sas www.tgsoft.it) [File not signed]
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
    R2 ZAMSvc; C:\Program Files\Zemana AntiMalware\ZAM.exe [11804528 2015-05-28] (Zemana Ltd.)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 athur; C:\Windows\System32\DRIVERS\athur.sys [1559552 2010-07-28] (Atheros Communications, Inc.)
    R3 cmuda; C:\Windows\System32\drivers\cmuda.sys [1332544 2005-05-12] (C-Media Inc)
    R3 ctxS51; C:\Windows\System32\DRIVERS\ctxS51.sys [1903646 2006-05-01] (Intel Corporation)
    R3 FETNDIS; C:\Windows\System32\DRIVERS\fetn62.sys [53872 2011-04-08] (VIA Technologies, Inc. )
    S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [35992 2015-05-27] ()
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
    S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    R3 nvmpu401; C:\Windows\System32\drivers\nvmpu401.sys [10240 2005-04-13] (NVIDIA Corporation)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 trufos; C:\Windows\System32\drivers\trufos.sys [343456 2015-05-21] (BitDefender S.R.L.)
    R0 VIRAGTLT; C:\Windows\System32\drivers\VIRAGTLT.SYS [96304 2013-11-29] (TG Soft S.a.s.)
    R1 ZAM; C:\Windows\System32\drivers\zam32.sys [96512 2015-05-21] (Zemana Ltd.)
    R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard32.sys [96512 2015-05-21] (Zemana Ltd.)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-05-31 15:27 - 2015-05-31 15:28 - 00011430 _____ () C:\Users\Brewster\Desktop\FRST.txt
    2015-05-31 15:27 - 2015-05-31 15:27 - 00000000 ____D () C:\Users\Brewster\Desktop\FRST-OlderVersion
    2015-05-31 15:18 - 2015-05-31 15:18 - 00000349 _____ () C:\Users\Brewster\Desktop\fixlist.txt
    2015-05-31 13:07 - 2015-05-31 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sigil
    2015-05-31 13:06 - 2015-05-31 13:06 - 28166248 _____ (John Schember ) C:\Users\Brewster\Downloads\Sigil-0.7.4-Windows-Setup.exe
    2015-05-31 12:52 - 2015-05-31 12:53 - 30368764 _____ (John Schember ) C:\Users\Brewster\Downloads\Sigil-0.8.6-Windows-Setup(1).exe
    2015-05-31 12:46 - 2015-05-31 12:57 - 00000000 ___HD () C:\Program Files\InstallJammer Registry
    2015-05-31 12:45 - 2015-05-31 13:07 - 00000000 ____D () C:\Program Files\Sigil
    2015-05-31 12:44 - 2015-05-31 12:45 - 11713653 _____ (Strahinja Marković) C:\Users\Brewster\Downloads\Sigil-0.3.2-Windows-Setup.exe
    2015-05-31 12:23 - 2015-05-31 12:23 - 00000000 ____D () C:\ProgramData\Package Cache
    2015-05-31 12:21 - 2015-05-31 12:21 - 30368764 _____ (John Schember ) C:\Users\Brewster\Downloads\Sigil-0.8.6-Windows-Setup.exe
    2015-05-31 11:34 - 2015-05-31 14:50 - 00035629 _____ () C:\Windows\WindowsUpdate.log
    2015-05-30 15:31 - 2015-05-30 15:31 - 00252835 _____ () C:\Users\Brewster\Downloads\BREWSTER-PUTER.txt
    2015-05-30 15:12 - 2015-05-30 15:06 - 00026747 _____ () C:\Users\Brewster\Documents\BREWSTER-PUTER.speccy
    2015-05-30 15:06 - 2015-05-30 15:06 - 00026747 _____ () C:\Users\Brewster\Desktop\BREWSTER-PUTER.speccy
    2015-05-30 13:32 - 2015-05-30 13:32 - 00022729 _____ () C:\Users\Brewster\Desktop\Result.txt
    2015-05-30 13:29 - 2015-05-30 13:29 - 00001463 _____ () C:\Users\Brewster\Desktop\MiniToolBox.exe - Shortcut.lnk
    2015-05-29 15:13 - 2015-05-29 15:14 - 64610304 _____ () C:\Users\Brewster\Downloads\calibre-2.29.0.msi
    2015-05-29 15:09 - 2015-05-29 15:09 - 00007605 _____ () C:\Users\Brewster\AppData\Local\Resmon.ResmonCfg
    2015-05-29 13:20 - 2015-05-29 13:21 - 00000000 ____D () C:\Users\Brewster\Downloads\23 Stephen Leather Novels in Mobi, KK
    2015-05-29 13:19 - 2015-05-29 13:19 - 00409898 ____R () C:\Users\Brewster\Downloads\White Lies_ The 11th Spider Shepherd Thril - Stephen Leather.epub
    2015-05-29 11:21 - 2015-05-29 11:21 - 00000000 ___SD () C:\Windows\system32\GWX
    2015-05-29 10:53 - 2015-05-29 10:54 - 00000000 ____D () C:\Users\Brewster\Desktop\Tweaking.com - Windows Repair
    2015-05-28 14:47 - 2015-05-28 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
    2015-05-28 13:59 - 2015-05-28 13:59 - 00000000 ____D () C:\ProgramData\Reason
    2015-05-28 13:45 - 2015-05-28 13:45 - 00000000 ____D () C:\ProgramData\TP-LINK
    2015-05-28 11:53 - 2015-05-28 15:09 - 00001028 _____ () C:\Users\Public\Desktop\Reason Core Security.lnk
    2015-05-28 11:53 - 2015-05-28 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reason Core Security
    2015-05-28 11:53 - 2015-05-28 11:53 - 00000000 ____D () C:\Program Files\Reason
    2015-05-28 11:52 - 2015-05-28 11:52 - 04151848 _____ (Reason Software Company Inc.) C:\Users\Brewster\Desktop\reason-core-security-setup.exe
    2015-05-28 11:37 - 2015-05-28 11:37 - 05684904 _____ (Avast Software s.r.o.) C:\Users\Brewster\Desktop\avastclear.exe
    2015-05-27 15:42 - 2015-05-27 15:54 - 00000000 ____D () C:\Users\Brewster\Downloads\Tales of The Empire 1-3 by S. J. A. Turney
    2015-05-27 15:06 - 2015-05-31 13:28 - 00000000 ____D () C:\Users\Brewster\Documents\Calibre Library
    2015-05-27 15:05 - 2015-05-29 18:37 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\calibre
    2015-05-27 15:05 - 2015-05-27 15:05 - 02313029 _____ () C:\Users\Brewster\Downloads\Cussler, Clive-Piranha.epub
    2015-05-27 14:56 - 2015-05-27 14:56 - 00000000 ____D () C:\Users\Brewster\Downloads\S. J. A. Turney
    2015-05-27 13:33 - 2015-05-27 13:33 - 00001051 _____ () C:\Users\Public\Desktop\Removal Tool.lnk
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\9-lab
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D () C:\ProgramData\9-lab
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D () C:\Program Files\9-lab
    2015-05-27 13:32 - 2015-05-27 13:32 - 06330112 _____ () C:\Users\Brewster\Downloads\rmtool-setup-x86.exe
    2015-05-27 12:58 - 2015-05-27 12:58 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Brewster\Desktop\tdsskiller.exe
    2015-05-27 12:17 - 2015-05-27 12:17 - 00415232 _____ (Farbar) C:\Users\Brewster\Desktop\FSS.exe
    2015-05-27 12:06 - 2015-05-27 12:06 - 00006876 _____ () C:\Windows\system32\.crusader
    2015-05-27 11:54 - 2015-05-27 12:09 - 00035992 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
    2015-05-27 11:43 - 2015-05-27 12:06 - 00000000 ____D () C:\ProgramData\HitmanPro
    2015-05-27 11:41 - 2015-05-27 11:41 - 10105736 _____ (SurfRight B.V.) C:\Users\Brewster\Desktop\HitmanPro.exe
    2015-05-27 09:43 - 2015-05-27 09:43 - 06549184 _____ (Piriform Ltd) C:\Users\Brewster\Downloads\ccsetup506.exe
    2015-05-25 18:16 - 2015-05-26 16:32 - 00000000 ____D () C:\VEXPLite
    2015-05-25 18:16 - 2015-05-25 18:16 - 00000636 _____ () C:\Users\Public\Desktop\VirIT eXplorer Lite.lnk
    2015-05-25 18:16 - 2015-05-25 18:16 - 00000000 __HDC () C:\ProgramData\{4E087BF8-6308-46DD-81BB-D2519CDB172A}
    2015-05-25 18:16 - 2015-05-25 18:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirIT eXplorer Lite
    2015-05-25 18:11 - 2015-05-25 18:13 - 70903880 _____ (TG Soft S.a.s. ) C:\Users\Brewster\Downloads\vnlt7923.exe
    2015-05-25 12:09 - 2015-05-29 09:39 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\Vso
    2015-05-25 12:09 - 2015-05-28 18:03 - 00000671 _____ () C:\Users\Brewster\AppData\Roaming\vso_ts_preview.xml
    2015-05-25 11:40 - 2015-05-31 15:27 - 00000000 ____D () C:\FRST
    2015-05-25 11:38 - 2015-05-31 15:27 - 01147392 _____ (Farbar) C:\Users\Brewster\Desktop\FRST.exe
    2015-05-25 10:31 - 2015-03-04 17:29 - 00027245 _____ () C:\zoek-results2015-03-04-162941.log
    2015-05-24 15:40 - 2015-05-24 15:40 - 00000000 ____D () C:\Users\Brewster\Downloads\Anthony Beevor - The Second World War
    2015-05-24 15:39 - 2015-05-24 16:30 - 00000000 ____D () C:\Users\Brewster\Downloads\[E-book ENG - epub-mobi-pdf] - Antony Beevor - Berlin. The Downfall, 1945
    2015-05-24 15:37 - 2015-05-24 15:37 - 00000000 ____D () C:\Users\Brewster\Downloads\The Fall Of Berlin 1945 By Antony Beevor (Epub,Mobi) Gooner
    2015-05-24 14:30 - 2015-05-24 14:31 - 10389256 _____ (Zemana) C:\Users\Brewster\Downloads\ZemanaAntiMalware.exe
    2015-05-24 14:29 - 2015-05-28 14:47 - 00001776 _____ () C:\Users\Public\Desktop\Zemana AntiMalware.lnk
    2015-05-24 14:28 - 2015-05-24 14:28 - 04772600 _____ ( ) C:\Users\Brewster\Desktop\Zemana.AntiMalware.Setup.exe
    2015-05-24 13:00 - 2015-05-24 13:00 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Brewster\Desktop\mbar-1.09.1.1004.exe
    2015-05-24 12:55 - 2015-05-24 12:55 - 00024522 _____ () C:\ComboFix.txt
    2015-05-24 12:14 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
    2015-05-24 12:14 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
    2015-05-24 12:14 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
    2015-05-24 12:14 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
    2015-05-24 12:14 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
    2015-05-24 12:14 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
    2015-05-24 12:14 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
    2015-05-24 12:14 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
    2015-05-24 12:13 - 2015-05-24 12:55 - 00000000 ____D () C:\Qoobox
    2015-05-24 12:13 - 2015-05-24 12:52 - 00000000 ____D () C:\Windows\erdnt
    2015-05-24 12:10 - 2015-05-24 12:10 - 05627500 ____R (Swearware) C:\Users\Brewster\Desktop\ComboFix.exe
    2015-05-23 13:26 - 2015-05-23 13:26 - 00000000 ____D () C:\Program Files\ESET
    2015-05-23 13:22 - 2015-05-23 13:22 - 00001566 _____ () C:\Users\Brewster\Desktop\esetsmartinstaller_enu.exe - Shortcut.lnk
    2015-05-23 13:20 - 2015-05-23 13:21 - 02347384 _____ (ESET) C:\Users\Brewster\Downloads\esetsmartinstaller_enu.exe
    2015-05-23 13:03 - 2015-05-30 13:31 - 00022729 _____ () C:\Users\Brewster\Downloads\Result.txt
    2015-05-23 12:18 - 2015-05-23 12:19 - 00001584 _____ () C:\Users\Brewster\Desktop\ZHPCleaner-2015.5.22.248.exe - Shortcut.lnk
    2015-05-23 12:14 - 2015-05-23 12:14 - 01837056 _____ () C:\Users\Brewster\Downloads\ZHPCleaner-2015.5.22.248.exe
    2015-05-23 11:58 - 2015-05-23 11:58 - 00001054 _____ () C:\Users\Brewster\Desktop\SecurityCheck.exe - Shortcut.lnk
    2015-05-23 11:49 - 2015-05-23 11:49 - 00852639 _____ () C:\Users\Brewster\Downloads\SecurityCheck.exe
    2015-05-23 11:17 - 2015-05-23 11:18 - 00290304 _____ (Microsoft Corporation) C:\Windows\system32\subinacl.exe
    2015-05-23 11:17 - 2015-05-23 11:17 - 00000000 ____D () C:\Program Files\Adware-Removal-Tool
    2015-05-23 11:16 - 2015-05-23 11:17 - 00001602 _____ () C:\Users\Brewster\Desktop\Adware-Removal-Tool-v3.9.1.exe - Shortcut.lnk
    2015-05-23 11:14 - 2015-05-23 11:14 - 00753184 _____ () C:\Users\Brewster\Downloads\Adware-Removal-Tool-v3.9.1.exe
    2015-05-23 11:11 - 2015-05-31 15:14 - 00000000 ____D () C:\logs for Malnutrition
    2015-05-22 13:43 - 2015-05-22 13:43 - 00021007 _____ () C:\Users\Brewster\Downloads\MWAV.LOG
    2015-05-22 12:58 - 2015-05-22 12:58 - 02223104 _____ () C:\Users\Brewster\Downloads\adwcleaner_4.205.exe
    2015-05-22 12:27 - 2015-05-22 12:27 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-BREWSTER-PUTER-Windows-7-Ultimate-(32-bit).dat
    2015-05-22 12:27 - 2015-05-22 12:27 - 00000000 ____D () C:\RegBackup
    2015-05-21 19:35 - 2015-05-28 14:50 - 00000000 ____D () C:\Program Files\Zemana AntiMalware
    2015-05-21 19:35 - 2015-05-21 19:35 - 00096512 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard32.sys
    2015-05-21 19:35 - 2015-05-21 19:35 - 00096512 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam32.sys
    2015-05-21 19:35 - 2015-05-21 19:35 - 00000000 ____D () C:\Users\Brewster\AppData\Local\Zemana
    2015-05-21 16:56 - 2015-05-21 16:58 - 11119633 _____ () C:\Windows\REGBK00.ZIP
    2015-05-21 16:54 - 2015-05-21 17:08 - 00000056 _____ () C:\Windows\Lic.xxx
    2015-05-21 16:53 - 2015-05-21 16:53 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\msvcr90.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00632064 _____ (Microsoft Corporation) C:\Windows\system32\msvcr80.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00572928 _____ (Microsoft Corporation) C:\Windows\system32\msvcp90.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00554240 _____ (Microsoft Corporation) C:\Windows\system32\msvcp80.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00343456 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
    2015-05-21 16:53 - 2015-05-21 16:53 - 00156392 _____ (MicroWorld Technologies Inc.) C:\Windows\system32\eEmpty.exe
    2015-05-21 16:53 - 2015-05-21 16:53 - 00001046 _____ () C:\Users\Brewster\Desktop\MWAVSCAN.lnk
    2015-05-21 16:53 - 2015-05-21 16:53 - 00000000 ____D () C:\ProgramData\MicroWorld
    2015-05-21 16:41 - 2015-05-21 16:45 - 158158304 _____ () C:\Users\Brewster\Downloads\mwav.exe
    2015-05-21 15:59 - 2015-05-27 09:44 - 00000000 ____D () C:\Program Files\CCleaner
    2015-05-21 15:59 - 2015-05-21 15:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    2015-05-21 15:08 - 2015-05-29 15:26 - 00063544 _____ () C:\Users\Brewster\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-05-21 15:07 - 2015-05-21 15:20 - 00000000 ____D () C:\Program Files\System Ninja
    2015-05-21 15:07 - 2015-05-21 15:07 - 00000977 _____ () C:\Users\Public\Desktop\System Ninja.lnk
    2015-05-21 15:07 - 2015-05-21 15:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Ninja
    2015-05-21 14:31 - 2015-05-22 18:25 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\Wipe
    2015-05-21 14:31 - 2015-05-21 14:31 - 00001723 _____ () C:\Users\Brewster\Desktop\Wipe.lnk
    2015-05-21 14:31 - 2015-05-21 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wipe
    2015-05-21 14:31 - 2015-05-21 14:31 - 00000000 ____D () C:\Program Files\Wipe
    2015-05-21 14:29 - 2015-05-21 14:29 - 00546456 _____ (www.privacyroot.com) C:\Users\Brewster\Downloads\setup_wipe.exe
    2015-05-19 16:19 - 2015-05-19 16:19 - 00000000 ____D () C:\Users\Brewster\Documents\Leawo
    2015-05-19 16:19 - 2015-05-19 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Leawo
    2015-05-19 16:19 - 2013-06-20 09:10 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\msvcp71.dll
    2015-05-19 16:19 - 2013-06-20 09:10 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll
    2015-05-19 16:18 - 2015-05-21 15:20 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
    2015-05-19 16:18 - 2015-05-19 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
    2015-05-19 16:18 - 2012-06-09 18:21 - 00178688 _____ () C:\Windows\system32\unrar.dll
    2015-05-19 16:17 - 2015-05-19 16:17 - 00000000 ____D () C:\Program Files\Leawo
    2015-05-19 16:15 - 2015-05-19 16:16 - 42643064 _____ (Leawo Software Co.,Ltd. ) C:\Users\Brewster\Downloads\videoconverter_free.exe
    2015-05-19 11:24 - 2015-04-24 12:10 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
    2015-05-19 11:24 - 2015-04-24 12:10 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
    2015-05-19 11:24 - 2015-04-24 12:10 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
    2015-05-19 11:22 - 2015-04-24 12:10 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
    2015-05-19 11:19 - 2015-05-19 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
    2015-05-15 16:08 - 2015-05-15 16:09 - 64577536 _____ () C:\Users\Brewster\Downloads\calibre-2.28.0.msi
    2015-05-14 12:51 - 2015-05-14 12:53 - 00000000 ____D () C:\Users\Brewster\Downloads\Steve Berry
    2015-05-14 12:50 - 2015-05-14 12:53 - 00000000 ____D () C:\Users\Brewster\Downloads\Steve Berry Books (7) Mobi, KK
    2015-05-13 19:41 - 2015-05-01 14:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-05-13 19:10 - 2015-05-13 19:10 - 00000000 ____D () C:\Users\Default
    2015-05-13 17:30 - 2015-05-14 13:21 - 00000000 ____D () C:\Users\Brewster\Downloads\Cotton Malone Collection - Steve Berry [EPUB]
    2015-05-13 17:13 - 2015-04-27 20:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
    2015-05-13 17:13 - 2015-04-27 20:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-05-13 17:13 - 2015-04-27 20:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-05-13 17:13 - 2015-04-27 20:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-05-13 17:13 - 2015-04-27 20:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-05-13 17:13 - 2015-04-27 20:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-05-13 17:13 - 2015-04-27 20:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
    2015-05-13 17:13 - 2015-04-27 20:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-05-13 17:13 - 2015-04-27 20:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-05-13 17:13 - 2015-04-27 19:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-05-13 17:13 - 2015-04-27 19:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-05-13 17:13 - 2015-04-27 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
    2015-05-13 17:13 - 2015-01-29 04:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
    2015-05-13 17:12 - 2015-05-05 02:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-05-13 17:12 - 2015-04-20 03:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-05-13 17:12 - 2015-04-20 03:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-05-13 17:12 - 2015-04-20 03:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-05-13 17:12 - 2015-04-18 03:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
    2015-05-13 17:11 - 2015-04-22 02:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-05-13 17:11 - 2015-04-21 17:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-05-13 17:11 - 2015-04-21 17:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-05-13 17:11 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-05-13 17:11 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-05-13 17:11 - 2015-04-21 17:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-05-13 17:11 - 2015-04-21 17:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-05-13 17:11 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-05-13 17:11 - 2015-04-21 17:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-05-13 17:11 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-05-13 17:11 - 2015-04-21 17:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-05-13 17:11 - 2015-04-21 17:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-05-13 17:11 - 2015-04-21 17:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-05-13 17:11 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-05-13 17:11 - 2015-04-21 16:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-05-13 17:11 - 2015-04-21 16:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-05-13 17:11 - 2015-04-21 16:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-05-13 17:11 - 2015-04-21 16:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-05-13 17:11 - 2015-04-21 16:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-05-13 17:11 - 2015-04-21 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-05-13 17:11 - 2015-04-21 16:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-05-13 17:11 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-05-13 17:11 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-05-13 17:11 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-05-13 17:11 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-05-13 17:11 - 2015-04-21 16:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-05-13 17:11 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-05-13 17:11 - 2015-04-21 16:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-05-13 17:11 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-05-13 17:11 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-05-13 17:11 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-05-13 17:11 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-05-13 17:11 - 2015-04-13 04:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
    2015-05-13 17:10 - 2015-04-08 04:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-05-13 17:10 - 2015-04-08 04:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-05-13 17:10 - 2015-03-04 05:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-05-13 17:10 - 2015-03-04 05:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-05-13 17:10 - 2015-03-04 05:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-05-13 17:10 - 2015-03-04 05:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-05-13 17:10 - 2015-02-18 08:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2015-05-10 17:01 - 2015-05-12 18:57 - 00000000 ____D () C:\Users\Brewster\Downloads\The Lost Fleet Beyond the Frontier Steadfast - Jack Campbell
    2015-05-10 17:00 - 2015-05-10 17:00 - 00000000 ____D () C:\Users\Brewster\Downloads\Campbell, Jack - Lost Stars 1-3 mobi
    2015-05-10 16:22 - 2015-05-10 16:22 - 00000000 ____D () C:\Users\Brewster\Downloads\Tarnished Knight by Jack Campbell (The Lost Stars Book 1)
    2015-05-10 16:21 - 2015-05-10 16:21 - 00000000 ____D () C:\Users\Brewster\Downloads\Jack Campbell - The Lost Fleet 08 - Beyond the Frontier 02 - Invincible
    2015-05-10 13:15 - 2015-05-10 13:16 - 00000000 ____D () C:\Users\Brewster\Documents\Marg's Glasses Claim (HSF)
    2015-05-04 15:57 - 2015-05-11 11:47 - 00000000 ___RD () C:\Users\Brewster\Documents\HP Photo Creations
    2015-05-04 15:56 - 2015-05-11 11:46 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\HP Photo Creations
    2015-05-04 15:56 - 2015-05-04 15:57 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\Visan
    2015-05-04 15:56 - 2015-05-04 15:56 - 00002073 _____ () C:\Users\Brewster\Desktop\HP Photo Creations.lnk
    2015-05-04 15:56 - 2015-05-04 15:56 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
    2015-05-04 11:01 - 2015-05-04 11:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
    2015-05-04 11:01 - 2015-05-04 11:01 - 00000000 ____D () C:\Program Files\Auslogics
    2015-05-01 13:59 - 2015-05-01 13:59 - 07902295 _____ () C:\Users\Brewster\Downloads\The Emperor Series Omnibus Edition [Books 1 - 5] - Conn Iggulden.epub

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-05-31 11:59 - 2009-07-14 05:34 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-05-31 11:59 - 2009-07-14 05:34 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-05-31 11:51 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-05-30 13:18 - 2010-11-20 22:01 - 00778180 _____ () C:\Windows\system32\PerfStringBackup.INI
    2015-05-29 18:37 - 2014-04-05 18:39 - 00000000 ____D () C:\Users\Brewster\AppData\Local\calibre-cache
    2015-05-29 15:36 - 2014-04-07 11:22 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\uTorrent
    2015-05-29 15:33 - 2015-03-04 15:26 - 00000000 ____D () C:\Windows\pss
    2015-05-29 15:26 - 2009-07-14 05:33 - 00287616 _____ () C:\Windows\system32\FNTCACHE.DAT
    2015-05-29 15:24 - 2010-11-21 01:46 - 00000000 ____D () C:\Windows\CSC
    2015-05-29 15:18 - 2014-04-07 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
    2015-05-29 15:18 - 2014-04-07 15:14 - 00000000 ____D () C:\Program Files\Calibre2
    2015-05-28 18:03 - 2014-04-07 15:08 - 00000000 ____D () C:\Users\Brewster\Documents\ConvertXtoDVD
    2015-05-28 14:12 - 2014-04-07 18:08 - 00045056 _____ (Northern Codeworks) C:\Windows\NCUNINST.EXE
    2015-05-28 11:27 - 2014-04-06 16:38 - 00000000 ____D () C:\ProgramData\AVAST Software
    2015-05-27 11:04 - 2015-01-18 12:18 - 00000000 ____D () C:\Users\Brewster\AppData\Local\WinZip
    2015-05-25 11:23 - 2015-03-04 16:34 - 00033069 _____ () C:\zoek-results.log
    2015-05-25 11:08 - 2015-03-04 16:32 - 00000000 ____D () C:\zoek_backup
    2015-05-24 13:05 - 2014-11-28 17:09 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-05-24 13:04 - 2014-11-28 17:09 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-05-24 12:55 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
    2015-05-24 12:48 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
    2015-05-24 12:39 - 2014-04-08 17:48 - 00000000 ____D () C:\Users\Brewster\Documents\CCleaner
    2015-05-23 10:51 - 2009-07-14 03:04 - 00002009 _____ () C:\Windows\system32\Drivers\etc\hosts.old
    2015-05-22 13:04 - 2014-05-23 11:18 - 00000000 ____D () C:\AdwCleaner
    2015-05-21 17:01 - 2009-07-14 03:04 - 00000922 _____ () C:\Windows\win.ini
    2015-05-21 16:02 - 2015-01-20 12:17 - 00000000 ____D () C:\ProgramData\VSO
    2015-05-21 16:00 - 2014-04-06 02:39 - 00000000 ____D () C:\Windows\Panther
    2015-05-21 15:20 - 2015-03-22 13:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
    2015-05-21 15:19 - 2014-10-08 13:35 - 00000000 ____D () C:\Users\Brewster\AppData\Roaming\dvdcss
    2015-05-19 11:20 - 2014-04-07 14:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
    2015-05-19 11:20 - 2014-04-07 14:33 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
    2015-05-19 11:19 - 2015-01-18 12:18 - 00002247 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
    2015-05-19 11:19 - 2015-01-18 12:18 - 00002241 _____ () C:\Users\Public\Desktop\WinZip.lnk
    2015-05-19 11:19 - 2015-01-18 12:17 - 00000000 ____D () C:\Program Files\WinZip
    2015-05-17 16:31 - 2014-04-15 11:48 - 00000000 ____D () C:\Users\Brewster\AppData\Local\Adobe
    2015-05-17 16:23 - 2014-09-05 13:16 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
    2015-05-17 16:23 - 2014-06-13 11:57 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
    2015-05-17 16:19 - 2009-07-14 05:53 - 00032620 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
    2015-05-17 13:31 - 2014-11-28 17:09 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-05-17 13:31 - 2014-11-28 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-05-17 13:31 - 2014-07-26 10:33 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
    2015-05-15 14:10 - 2014-04-08 14:32 - 00000000 ____D () C:\Users\Brewster\Documents\My Kindle Content
    2015-05-15 13:08 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
    2015-05-15 12:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
    2015-05-15 12:06 - 2014-04-15 11:52 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
    2015-05-14 13:27 - 2010-11-21 01:46 - 00000000 ____D () C:\Program Files\Windows Journal
    2015-05-14 11:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
    2015-05-13 19:40 - 2014-04-06 18:29 - 00000000 ____D () C:\Windows\system32\MRT
    2015-05-13 19:20 - 2014-04-06 18:28 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-05-04 15:57 - 2014-04-07 17:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP

    ==================== Files in the root of some directories =======

    2015-05-25 12:09 - 2015-05-28 18:03 - 0000671 _____ () C:\Users\Brewster\AppData\Roaming\vso_ts_preview.xml
    2015-05-29 15:09 - 2015-05-29 15:09 - 0007605 _____ () C:\Users\Brewster\AppData\Local\Resmon.ResmonCfg

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-05-29 17:34

    ==================== End of log ============================
    MiniToolBox by Farbar Version: 23-01-2014
    Ran by Brewster (administrator) on 30-05-2015 at 13:31:22
    Running from "C:\Users\Brewster\Downloads"
    Microsoft Windows 7 Ultimate Service Pack 1 (X86)
    Boot Mode: Normal
    ***************************************************************************

    ========================= Flush DNS: ===================================

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========================= IE Proxy Settings: ==============================

    Proxy is not enabled.
    No Proxy Server is set.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.

    ========================= FF Proxy Settings: ==============================


    "Reset FF Proxy Settings": Firefox Proxy settings were reset.

    ========================= Hosts content: =================================

    ::1 localhost

    0.0.0.0 0.0.0.0 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
    0.0.0.0 media.opencandy.com
    0.0.0.0 cdn.opencandy.com
    0.0.0.0 tracking.opencandy.com
    0.0.0.0 api.opencandy.com
    0.0.0.0 installer.betterinstaller.com
    0.0.0.0 installer.filebulldog.com
    0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
    0.0.0.0 inno.bisrv.com
    0.0.0.0 nsis.bisrv.com
    0.0.0.0 cdn.file2desktop.com
    0.0.0.0 cdn.goateastcach.us
    0.0.0.0 cdn.guttastatdk.us
    0.0.0.0 cdn.inskinmedia.com
    0.0.0.0 cdn.insta.oibundles2.com
    0.0.0.0 cdn.insta.playbryte.com
    0.0.0.0 cdn.llogetfastcach.us
    0.0.0.0 cdn.montiera.com
    0.0.0.0 cdn.msdwnld.com
    0.0.0.0 cdn.mypcbackup.com
    0.0.0.0 cdn.ppdownload.com
    0.0.0.0 cdn.riceateastcach.us
    0.0.0.0 cdn.shyapotato.us
    0.0.0.0 cdn.solimba.com
    0.0.0.0 cdn.tuto4pc.com
    0.0.0.0 cdn.appround.biz
    0.0.0.0 cdn.bigspeedpro.com
    0.0.0.0 cdn.bispd.com
    0.0.0.0 cdn.bisrv.com
    0.0.0.0 cdn.cdndp.com
    0.0.0.0 cdn.download.sweetpacks.com
    0.0.0.0 cdn.dpdownload.com
    0.0.0.0 cdn.visualbee.net

    127.0.0.1 localhost

    ========================= IP Configuration: ================================

    VIA Rhine III Fast Ethernet Adapter = Local Area Connection (Connected)


    # ----------------------------------
    # IPv4 Configuration
    # ----------------------------------
    pushd interface ipv4

    reset
    set global icmpredirects=enabled


    popd
    # End of IPv4 configuration



    Windows IP Configuration

    Host Name . . . . . . . . . . . . : Brewster-Puter
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Hybrid
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : home

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . : home
    Description . . . . . . . . . . . : VIA Rhine III Fast Ethernet Adapter
    Physical Address. . . . . . . . . : 00-0C-76-84-77-97
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    Link-local IPv6 Address . . . . . : fe80::ad56:54f5:b4c9:8192%12(Preferred)
    IPv4 Address. . . . . . . . . . . : 192.168.1.72(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Lease Obtained. . . . . . . . . . : 30 May 2015 13:14:10
    Lease Expires . . . . . . . . . . : 31 May 2015 13:14:10
    Default Gateway . . . . . . . . . : 192.168.1.254
    DHCP Server . . . . . . . . . . . : 192.168.1.254
    DHCPv6 IAID . . . . . . . . . . . : 251661430
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1C-FB-42-0F-00-0C-76-84-77-97
    DNS Servers . . . . . . . . . . . : 192.168.1.254
    192.168.1.254
    NetBIOS over Tcpip. . . . . . . . : Enabled
    Server: BTHomeHub.home
    Address: 192.168.1.254

    Name: google.com
    Address: 216.58.208.78


    Pinging google.com [216.58.208.78] with 32 bytes of data:
    Reply from 216.58.208.78: bytes=32 time=12ms TTL=54
    Reply from 216.58.208.78: bytes=32 time=12ms TTL=54

    Ping statistics for 216.58.208.78:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 12ms, Maximum = 12ms, Average = 12ms
    Server: BTHomeHub.home
    Address: 192.168.1.254

    Name: yahoo.com
    Addresses: 206.190.36.45
    98.139.183.24
    98.138.253.109


    Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
    Reply from 206.190.36.45: bytes=32 time=173ms TTL=47
    Reply from 206.190.36.45: bytes=32 time=176ms TTL=47

    Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 173ms, Maximum = 176ms, Average = 174ms

    Pinging 127.0.0.1 with 32 bytes of data:
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

    Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
    ===========================================================================
    Interface List
    12...00 0c 76 84 77 97 ......VIA Rhine III Fast Ethernet Adapter
    1...........................Software Loopback Interface 1
    ===========================================================================

    IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.72 20
    127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
    127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
    127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
    192.168.1.0 255.255.255.0 On-link 192.168.1.72 276
    192.168.1.72 255.255.255.255 On-link 192.168.1.72 276
    192.168.1.255 255.255.255.255 On-link 192.168.1.72 276
    224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
    224.0.0.0 240.0.0.0 On-link 192.168.1.72 276
    255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
    255.255.255.255 255.255.255.255 On-link 192.168.1.72 276
    ===========================================================================
    Persistent Routes:
    None

    IPv6 Route Table
    ===========================================================================
    Active Routes:
    If Metric Network Destination Gateway
    1 306 ::1/128 On-link
    12 276 fe80::/64 On-link
    12 276 fe80::ad56:54f5:b4c9:8192/128
    On-link
    1 306 ff00::/8 On-link
    12 276 ff00::/8 On-link
    ===========================================================================
    Persistent Routes:
    None
    ========================= Winsock entries =====================================

    Catalog5 01 C:\Windows\system32\NLAapi.dll [52224] (Microsoft Corporation)
    Catalog5 02 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
    Catalog5 03 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 04 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 05 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog5 06 C:\Windows\system32\winrnr.dll [20992] (Microsoft Corporation)
    Catalog5 07 C:\Windows\system32\wshbth.dll [36352] (Microsoft Corporation)
    Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [] ()
    Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [] ()
    Catalog9 01 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 02 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 03 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 04 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 05 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 06 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 07 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 08 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 09 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 10 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 11 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)

    ========================= Event log errors: ===============================

    Application errors:
    ==================
    Error: (05/30/2015 01:31:24 PM) (Source: Application Error) (User: )
    Description: Faulting application name: plugin-container.exe, version: 38.0.1.5611, time stamp: 0x55541a90
    Faulting module name: mozalloc.dll, version: 38.0.1.5611, time stamp: 0x55540a1e
    Exception code: 0x80000003
    Fault offset: 0x00001aa1
    Faulting process id: 0x138
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3

    Error: (05/30/2015 01:14:23 PM) (Source: PerfNet) (User: )
    Description:

    Error: (05/30/2015 11:10:59 AM) (Source: PerfNet) (User: )
    Description:

    Error: (05/30/2015 10:32:00 AM) (Source: PerfNet) (User: )
    Description:

    Error: (05/29/2015 04:29:13 PM) (Source: .NET Runtime) (User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3892. Message ID: [0x2509].

    Error: (05/29/2015 04:27:08 PM) (Source: .NET Runtime) (User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2212. Message ID: [0x2509].

    Error: (05/29/2015 04:22:35 PM) (Source: .NET Runtime) (User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2956. Message ID: [0x2509].

    Error: (05/29/2015 03:36:27 PM) (Source: Windows Search Service) (User: )
    Description: The Windows Search Service has failed to create the new search index. Internal error <4, 0xc0041800, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service) (User: )
    Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

    Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service) (User: )
    Description: The search service has detected corrupted data files in the index {id=2801}. The service will attempt to automatically correct this problem by rebuilding the index.

    Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)


    System errors:
    =============
    Error: (05/30/2015 01:14:15 PM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 01:14:12 PM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 11:10:46 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 11:10:43 AM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 10:57:56 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 10:57:53 AM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 10:32:01 AM) (Source: WMPNetworkSvc) (User: )
    Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

    Error: (05/30/2015 10:31:44 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 10:31:30 AM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 10:31:28 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\athExt.dll
    Error Code: 126


    Microsoft Office Sessions:
    =========================
    Error: (05/30/2015 01:31:24 PM) (Source: Application Error)(User: )
    Description: plugin-container.exe38.0.1.561155541a90mozalloc.dll38.0.1.561155540a1e8000000300001aa113801d09ad306f115b7C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dllc836f930-06c7-11e5-8fbc-000c76847797

    Error: (05/30/2015 01:14:23 PM) (Source: PerfNet)(User: )
    Description:

    Error: (05/30/2015 11:10:59 AM) (Source: PerfNet)(User: )
    Description:

    Error: (05/30/2015 10:32:00 AM) (Source: PerfNet)(User: )
    Description:

    Error: (05/29/2015 04:29:13 PM) (Source: .NET Runtime)(User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3892. Message ID: [0x2509].

    Error: (05/29/2015 04:27:08 PM) (Source: .NET Runtime)(User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2212. Message ID: [0x2509].

    Error: (05/29/2015 04:22:35 PM) (Source: .NET Runtime)(User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2956. Message ID: [0x2509].

    Error: (05/29/2015 03:36:27 PM) (Source: Windows Search Service)(User: )
    Description: 40xc0041800Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service)(User: )
    Description: Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)
    The catalog is corrupt

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service)(User: )
    Description: Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)
    2801


    CodeIntegrity Errors:
    ===================================
    Date: 2015-05-29 10:48:35.475
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:35.177
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:34.869
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:34.583
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:34.272
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:33.945
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-28 11:57:32.838
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-28 11:57:32.471
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-27 14:11:46.584
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-27 12:53:58.757
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.


    =========================== Installed Programs ============================

    ******** (Version: 3.4.3.40298)
    9-lab Removal Tool
    Adobe Flash Player 17 ActiveX (Version: 17.0.0.188)
    Adobe Flash Player 17 NPAPI (Version: 17.0.0.188)
    Adobe Reader XI (11.0.11) (Version: 11.0.11)
    Adobe Refresh Manager (Version: 1.8.0)
    Amazon Kindle
    Apple Application Support (32-bit) (Version: 3.1.2)
    Apple Mobile Device Support (Version: 8.1.1.3)
    Apple Software Update (Version: 2.1.3.127)
    Audacity 2.0.6 (Version: 2.0.6)
    Auslogics DiskDefrag (Version: 5.4.0.0)
    Bonjour (Version: 3.0.0.10)
    BT Desktop Help
    calibre (Version: 2.29.0)
    CCleaner (Version: 5.06)
    C-Media WDM Audio Driver
    Cole2k Media - Codec Pack (Advanced) 8.0.2 (Version: 8.0.2)
    ConvertXtoDVD 3.3.2.100 (Version: 3.3.2.100)
    Creatix V.9X DSP Data Fax Modem
    DC-Bass Source 1.3.0
    DVD Decrypter (Remove Only)
    DVD Shrink 3.2
    ESET Online Scanner v3
    ffdshow v1.1.4399 [2012-03-22] (Version: 1.1.4399.0)
    Free PDF to JPG Converter (Version: 1.0.0)
    Google Update Helper (Version: 1.3.25.11)
    GoToAssist Corporate (Version: 10.4.0.896)
    Haali Media Splitter
    HP FWUpdateEDO2 (Version: 1.2.0.0)
    HP Photo Creations (Version: 1.0.0.18142)
    HP Photosmart 5510 series Basic Device Software (Version: 24.0.342.0)
    HP Photosmart 5510 series Help (Version: 140.0.2.2)
    HP Photosmart 5510 series Product Improvement Study (Version: 24.0.342.0)
    HP Update (Version: 5.005.002.002)
    HPDiagnosticAlert (Version: 1.00.0001)
    iTunes (Version: 12.1.1.4)
    Java 7 Update 65 (Version: 7.0.650)
    Java 7 Update 80 (Version: 7.0.800)
    Java 8 Update 31 (Version: 8.0.310)
    Java 8 Update 45 (Version: 8.0.450)
    Java Auto Updater (Version: 2.8.45.14)
    K-Lite Codec Pack 9.4.0 (Basic) (Version: 9.4.0)
    Lagarith Lossless Codec (1.3.27)
    LAME v3.99.3 (for Windows)
    Leawo Video Converter version 6.0.0.0 (Version: 6.0.0.0)
    Malwarebytes Anti-Malware version 2.1.6.1022 (Version: 2.1.6.1022)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
    Microsoft Office 2000 Premium (Version: 9.00.2720)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
    Mozilla Firefox 38.0.1 (x86 en-US) (Version: 38.0.1)
    Mozilla Maintenance Service (Version: 34.0.5)
    Nero 6 Ultra Edition
    QuickTime 7 (Version: 7.76.80.95)
    Reason Core Security (Version: 1.0.7.0)
    Recuva (Version: 1.51)
    Revo Uninstaller 1.95 (Version: 1.95)
    RocketDock 1.3.5
    Sigil 0.7.4
    Speccy (Version: 1.26)
    SUPERAntiSpyware (Version: 5.7.1026)
    System Ninja version 3.0.6 (Version: 3.0.6)
    TP-LINK Wireless Client Utility (Version: 7.0)
    TreeSize Free V2.4 (Version: 2.4)
    Unknown Device Identifier 8.01 (Version: 8.01)
    VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
    VIA Rhine Family Fast Ethernet Adapter
    VirIT eXplorer Lite (Version: 7.9.23)
    WinRAR 5.21 (32-bit) (Version: 5.21.0)
    WinZip 19.0 (Version: 19.0.11294)
    WinZip 19.5 (Version: 19.5.11475)
    Wipe (Version: 2015.05)
    Xvid Video Codec (Version: 1.3.2)
    Zemana AntiMalware (Version: 2.15.206)

    ========================= Memory info: ===================================

    Percentage of memory in use: 21%
    Total physical RAM: 3327.55 MB
    Available physical RAM: 2628.68 MB
    Total Pagefile: 6651.36 MB
    Available Pagefile: 5970.82 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1942.11 MB

    ========================= Partitions: =====================================

    2 Drive c: () (Fixed) (Total:149.04 GB) (Free:66.57 GB) NTFS
    5 Drive f: () (Fixed) (Total:74.52 GB) (Free:36.34 GB) NTFS
    6 Drive h: () (Fixed) (Total:931.51 GB) (Free:306.54 GB) NTFS

    ========================= Users: ========================================

    User accounts for \\BREWSTER-PUTER

    Administrator Brewster Guest
    Margies


    **** End of log ****
    MiniToolBox by Farbar Version: 23-01-2014
    Ran by Brewster (administrator) on 30-05-2015 at 13:31:22
    Running from "C:\Users\Brewster\Downloads"
    Microsoft Windows 7 Ultimate Service Pack 1 (X86)
    Boot Mode: Normal
    ***************************************************************************

    ========================= Flush DNS: ===================================

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========================= IE Proxy Settings: ==============================

    Proxy is not enabled.
    No Proxy Server is set.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.

    ========================= FF Proxy Settings: ==============================


    "Reset FF Proxy Settings": Firefox Proxy settings were reset.

    ========================= Hosts content: =================================

    ::1 localhost

    0.0.0.0 0.0.0.0 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
    0.0.0.0 media.opencandy.com
    0.0.0.0 cdn.opencandy.com
    0.0.0.0 tracking.opencandy.com
    0.0.0.0 api.opencandy.com
    0.0.0.0 installer.betterinstaller.com
    0.0.0.0 installer.filebulldog.com
    0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
    0.0.0.0 inno.bisrv.com
    0.0.0.0 nsis.bisrv.com
    0.0.0.0 cdn.file2desktop.com
    0.0.0.0 cdn.goateastcach.us
    0.0.0.0 cdn.guttastatdk.us
    0.0.0.0 cdn.inskinmedia.com
    0.0.0.0 cdn.insta.oibundles2.com
    0.0.0.0 cdn.insta.playbryte.com
    0.0.0.0 cdn.llogetfastcach.us
    0.0.0.0 cdn.montiera.com
    0.0.0.0 cdn.msdwnld.com
    0.0.0.0 cdn.mypcbackup.com
    0.0.0.0 cdn.ppdownload.com
    0.0.0.0 cdn.riceateastcach.us
    0.0.0.0 cdn.shyapotato.us
    0.0.0.0 cdn.solimba.com
    0.0.0.0 cdn.tuto4pc.com
    0.0.0.0 cdn.appround.biz
    0.0.0.0 cdn.bigspeedpro.com
    0.0.0.0 cdn.bispd.com
    0.0.0.0 cdn.bisrv.com
    0.0.0.0 cdn.cdndp.com
    0.0.0.0 cdn.download.sweetpacks.com
    0.0.0.0 cdn.dpdownload.com
    0.0.0.0 cdn.visualbee.net

    127.0.0.1 localhost

    ========================= IP Configuration: ================================

    VIA Rhine III Fast Ethernet Adapter = Local Area Connection (Connected)


    # ----------------------------------
    # IPv4 Configuration
    # ----------------------------------
    pushd interface ipv4

    reset
    set global icmpredirects=enabled


    popd
    # End of IPv4 configuration



    Windows IP Configuration

    Host Name . . . . . . . . . . . . : Brewster-Puter
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Hybrid
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : home

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . : home
    Description . . . . . . . . . . . : VIA Rhine III Fast Ethernet Adapter
    Physical Address. . . . . . . . . : 00-0C-76-84-77-97
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    Link-local IPv6 Address . . . . . : fe80::ad56:54f5:b4c9:8192%12(Preferred)
    IPv4 Address. . . . . . . . . . . : 192.168.1.72(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Lease Obtained. . . . . . . . . . : 30 May 2015 13:14:10
    Lease Expires . . . . . . . . . . : 31 May 2015 13:14:10
    Default Gateway . . . . . . . . . : 192.168.1.254
    DHCP Server . . . . . . . . . . . : 192.168.1.254
    DHCPv6 IAID . . . . . . . . . . . : 251661430
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1C-FB-42-0F-00-0C-76-84-77-97
    DNS Servers . . . . . . . . . . . : 192.168.1.254
    192.168.1.254
    NetBIOS over Tcpip. . . . . . . . : Enabled
    Server: BTHomeHub.home
    Address: 192.168.1.254

    Name: google.com
    Address: 216.58.208.78


    Pinging google.com [216.58.208.78] with 32 bytes of data:
    Reply from 216.58.208.78: bytes=32 time=12ms TTL=54
    Reply from 216.58.208.78: bytes=32 time=12ms TTL=54

    Ping statistics for 216.58.208.78:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 12ms, Maximum = 12ms, Average = 12ms
    Server: BTHomeHub.home
    Address: 192.168.1.254

    Name: yahoo.com
    Addresses: 206.190.36.45
    98.139.183.24
    98.138.253.109


    Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
    Reply from 206.190.36.45: bytes=32 time=173ms TTL=47
    Reply from 206.190.36.45: bytes=32 time=176ms TTL=47

    Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 173ms, Maximum = 176ms, Average = 174ms

    Pinging 127.0.0.1 with 32 bytes of data:
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

    Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
    ===========================================================================
    Interface List
    12...00 0c 76 84 77 97 ......VIA Rhine III Fast Ethernet Adapter
    1...........................Software Loopback Interface 1
    ===========================================================================

    IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.72 20
    127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
    127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
    127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
    192.168.1.0 255.255.255.0 On-link 192.168.1.72 276
    192.168.1.72 255.255.255.255 On-link 192.168.1.72 276
    192.168.1.255 255.255.255.255 On-link 192.168.1.72 276
    224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
    224.0.0.0 240.0.0.0 On-link 192.168.1.72 276
    255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
    255.255.255.255 255.255.255.255 On-link 192.168.1.72 276
    ===========================================================================
    Persistent Routes:
    None

    IPv6 Route Table
    ===========================================================================
    Active Routes:
    If Metric Network Destination Gateway
    1 306 ::1/128 On-link
    12 276 fe80::/64 On-link
    12 276 fe80::ad56:54f5:b4c9:8192/128
    On-link
    1 306 ff00::/8 On-link
    12 276 ff00::/8 On-link
    ===========================================================================
    Persistent Routes:
    None
    ========================= Winsock entries =====================================

    Catalog5 01 C:\Windows\system32\NLAapi.dll [52224] (Microsoft Corporation)
    Catalog5 02 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
    Catalog5 03 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 04 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 05 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog5 06 C:\Windows\system32\winrnr.dll [20992] (Microsoft Corporation)
    Catalog5 07 C:\Windows\system32\wshbth.dll [36352] (Microsoft Corporation)
    Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [] ()
    Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [] ()
    Catalog9 01 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 02 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 03 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 04 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 05 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 06 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 07 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 08 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 09 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 10 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 11 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)

    ========================= Event log errors: ===============================

    Application errors:
    ==================
    Error: (05/30/2015 01:31:24 PM) (Source: Application Error) (User: )
    Description: Faulting application name: plugin-container.exe, version: 38.0.1.5611, time stamp: 0x55541a90
    Faulting module name: mozalloc.dll, version: 38.0.1.5611, time stamp: 0x55540a1e
    Exception code: 0x80000003
    Fault offset: 0x00001aa1
    Faulting process id: 0x138
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3

    Error: (05/30/2015 01:14:23 PM) (Source: PerfNet) (User: )
    Description:

    Error: (05/30/2015 11:10:59 AM) (Source: PerfNet) (User: )
    Description:

    Error: (05/30/2015 10:32:00 AM) (Source: PerfNet) (User: )
    Description:

    Error: (05/29/2015 04:29:13 PM) (Source: .NET Runtime) (User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3892. Message ID: [0x2509].

    Error: (05/29/2015 04:27:08 PM) (Source: .NET Runtime) (User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2212. Message ID: [0x2509].

    Error: (05/29/2015 04:22:35 PM) (Source: .NET Runtime) (User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2956. Message ID: [0x2509].

    Error: (05/29/2015 03:36:27 PM) (Source: Windows Search Service) (User: )
    Description: The Windows Search Service has failed to create the new search index. Internal error <4, 0xc0041800, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service) (User: )
    Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

    Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service) (User: )
    Description: The search service has detected corrupted data files in the index {id=2801}. The service will attempt to automatically correct this problem by rebuilding the index.

    Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)


    System errors:
    =============
    Error: (05/30/2015 01:14:15 PM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 01:14:12 PM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 11:10:46 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 11:10:43 AM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 10:57:56 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 10:57:53 AM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 10:32:01 AM) (Source: WMPNetworkSvc) (User: )
    Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

    Error: (05/30/2015 10:31:44 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (05/30/2015 10:31:30 AM) (Source: NETLOGON) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (05/30/2015 10:31:28 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\athExt.dll
    Error Code: 126


    Microsoft Office Sessions:
    =========================
    Error: (05/30/2015 01:31:24 PM) (Source: Application Error)(User: )
    Description: plugin-container.exe38.0.1.561155541a90mozalloc.dll38.0.1.561155540a1e8000000300001aa113801d09ad306f115b7C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dllc836f930-06c7-11e5-8fbc-000c76847797

    Error: (05/30/2015 01:14:23 PM) (Source: PerfNet)(User: )
    Description:

    Error: (05/30/2015 11:10:59 AM) (Source: PerfNet)(User: )
    Description:

    Error: (05/30/2015 10:32:00 AM) (Source: PerfNet)(User: )
    Description:

    Error: (05/29/2015 04:29:13 PM) (Source: .NET Runtime)(User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3892. Message ID: [0x2509].

    Error: (05/29/2015 04:27:08 PM) (Source: .NET Runtime)(User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2212. Message ID: [0x2509].

    Error: (05/29/2015 04:22:35 PM) (Source: .NET Runtime)(User: )
    Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2956. Message ID: [0x2509].

    Error: (05/29/2015 03:36:27 PM) (Source: Windows Search Service)(User: )
    Description: 40xc0041800Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service)(User: )
    Description: Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)
    The catalog is corrupt

    Error: (05/29/2015 03:36:26 PM) (Source: Windows Search Service)(User: )
    Description: Context: Windows Application


    Details:
    The content index catalog is corrupt. 0xc0041801 (0xc0041801)
    2801


    CodeIntegrity Errors:
    ===================================
    Date: 2015-05-29 10:48:35.475
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:35.177
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:34.869
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:34.583
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:34.272
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-29 10:48:33.945
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-28 11:57:32.838
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-28 11:57:32.471
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-27 14:11:46.584
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-05-27 12:53:58.757
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.


    =========================== Installed Programs ============================

    ******** (Version: 3.4.3.40298)
    9-lab Removal Tool
    Adobe Flash Player 17 ActiveX (Version: 17.0.0.188)
    Adobe Flash Player 17 NPAPI (Version: 17.0.0.188)
    Adobe Reader XI (11.0.11) (Version: 11.0.11)
    Adobe Refresh Manager (Version: 1.8.0)
    Amazon Kindle
    Apple Application Support (32-bit) (Version: 3.1.2)
    Apple Mobile Device Support (Version: 8.1.1.3)
    Apple Software Update (Version: 2.1.3.127)
    Audacity 2.0.6 (Version: 2.0.6)
    Auslogics DiskDefrag (Version: 5.4.0.0)
    Bonjour (Version: 3.0.0.10)
    BT Desktop Help
    calibre (Version: 2.29.0)
    CCleaner (Version: 5.06)
    C-Media WDM Audio Driver
    Cole2k Media - Codec Pack (Advanced) 8.0.2 (Version: 8.0.2)
    ConvertXtoDVD 3.3.2.100 (Version: 3.3.2.100)
    Creatix V.9X DSP Data Fax Modem
    DC-Bass Source 1.3.0
    DVD Decrypter (Remove Only)
    DVD Shrink 3.2
    ESET Online Scanner v3
    ffdshow v1.1.4399 [2012-03-22] (Version: 1.1.4399.0)
    Free PDF to JPG Converter (Version: 1.0.0)
    Google Update Helper (Version: 1.3.25.11)
    GoToAssist Corporate (Version: 10.4.0.896)
    Haali Media Splitter
    HP FWUpdateEDO2 (Version: 1.2.0.0)
    HP Photo Creations (Version: 1.0.0.18142)
    HP Photosmart 5510 series Basic Device Software (Version: 24.0.342.0)
    HP Photosmart 5510 series Help (Version: 140.0.2.2)
    HP Photosmart 5510 series Product Improvement Study (Version: 24.0.342.0)
    HP Update (Version: 5.005.002.002)
    HPDiagnosticAlert (Version: 1.00.0001)
    iTunes (Version: 12.1.1.4)
    Java 7 Update 65 (Version: 7.0.650)
    Java 7 Update 80 (Version: 7.0.800)
    Java 8 Update 31 (Version: 8.0.310)
    Java 8 Update 45 (Version: 8.0.450)
    Java Auto Updater (Version: 2.8.45.14)
    K-Lite Codec Pack 9.4.0 (Basic) (Version: 9.4.0)
    Lagarith Lossless Codec (1.3.27)
    LAME v3.99.3 (for Windows)
    Leawo Video Converter version 6.0.0.0 (Version: 6.0.0.0)
    Malwarebytes Anti-Malware version 2.1.6.1022 (Version: 2.1.6.1022)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
    Microsoft Office 2000 Premium (Version: 9.00.2720)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
    Mozilla Firefox 38.0.1 (x86 en-US) (Version: 38.0.1)
    Mozilla Maintenance Service (Version: 34.0.5)
    Nero 6 Ultra Edition
    QuickTime 7 (Version: 7.76.80.95)
    Reason Core Security (Version: 1.0.7.0)
    Recuva (Version: 1.51)
    Revo Uninstaller 1.95 (Version: 1.95)
    RocketDock 1.3.5
    Sigil 0.7.4
    Speccy (Version: 1.26)
    SUPERAntiSpyware (Version: 5.7.1026)
    System Ninja version 3.0.6 (Version: 3.0.6)
    TP-LINK Wireless Client Utility (Version: 7.0)
    TreeSize Free V2.4 (Version: 2.4)
    Unknown Device Identifier 8.01 (Version: 8.01)
    VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
    VIA Rhine Family Fast Ethernet Adapter
    VirIT eXplorer Lite (Version: 7.9.23)
    WinRAR 5.21 (32-bit) (Version: 5.21.0)
    WinZip 19.0 (Version: 19.0.11294)
    WinZip 19.5 (Version: 19.5.11475)
    Wipe (Version: 2015.05)
    Xvid Video Codec (Version: 1.3.2)
    Zemana AntiMalware (Version: 2.15.206)

    ========================= Memory info: ===================================

    Percentage of memory in use: 21%
    Total physical RAM: 3327.55 MB
    Available physical RAM: 2628.68 MB
    Total Pagefile: 6651.36 MB
    Available Pagefile: 5970.82 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1942.11 MB

    ========================= Partitions: =====================================

    2 Drive c: () (Fixed) (Total:149.04 GB) (Free:66.57 GB) NTFS
    5 Drive f: () (Fixed) (Total:74.52 GB) (Free:36.34 GB) NTFS
    6 Drive h: () (Fixed) (Total:931.51 GB) (Free:306.54 GB) NTFS

    ========================= Users: ========================================

    User accounts for \\BREWSTER-PUTER

    Administrator Brewster Guest
    Margies


    **** End of log ****
     
  7. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Download attached fixlist.txt file and save it to the Desktop.

    NOTE. It's important that both files, FRST/FRST64andfixlist.txt are in the same location or the fix will not work.

    NOTICE:This script was written specifically for this user,for use on that particular machine.Running this on another machine may cause damage to your operating system

    RunFRST/FRST64and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally.After that let the tool complete its run.When finished FRST will generate a log on the Desktop(Fixlog.txt).Please post it to your reply.
     

    Attached Files:

  8. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations!
    First I must excuse my absence for the last few days but I have been feeling a little under the weather, and also feeling trepidation at doing a repair install - the last time I did anything like that was when I had XP and driver_ian suggested something similar, and it didn't go well, I forgot to disconnect the external drive I had done the back-up to - needless to say it took Ian a long time to get me back up and running.
    So I thought I would also disconnect the F drive as it has all of my music on it, only to find that when I rebooted the computer the damned thing was now behaving properly????
    So I reconnected the F drive and it still behaved itself - I plugged the external drive back in and I now have a computer that works as it should.
    This was before I actually backed anything up and did the repair install (which I have not done)
    So here I am feeling a little foolish wondering exactly what has has happened, and hoping that I have not wasted anybody's time.
    What would you like me to do with all of the downloaded programmes you have told me to download
    Yours in bewilderment
    Brewster
     
  9. driver_ian

    driver_ian In at the Deep End... Administrator iHF Legend Security Advisor

    Joined:
    May 2, 2014
    Messages:
    2,388
    Likes Received:
    523
    Trophy Points:
    123
    Glad it's all working as it should... but give it a week or so to see if the issue resurfaces...

    Mal will give you further instructions once he comes online.. Once he is satisfied he can do no more for the machine he will instruct on what tools to keep and which to remove..

    Rest assured you haven't wasted anyones time.... your pc has had a 'deep clean' and will finish up in the best condition it can be in and most certainly free of any malware...
     
    Malnutrition and Lord Chance like this.
  10. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Many thanks for that,
    P.S. what Anti-virus should I now Install?
     
  11. driver_ian

    driver_ian In at the Deep End... Administrator iHF Legend Security Advisor

    Joined:
    May 2, 2014
    Messages:
    2,388
    Likes Received:
    523
    Trophy Points:
    123
    Antivirus software is a personal choice... Whilst I use Avast and I know you've used it too. Mal may suggest another which would better suit your machine in terms of resource usage... meaning it would not slow the machine's performance...
     
    Malnutrition likes this.
  12. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Lets check with one more tool before we call this one solved. :)

    We will scan with a tool that will not be able to remove infections if found, so long as you get me the log we can then remove anything found with FRST if needed. Run a full scan with Loaris Trojan Remover The program will update on its own, it will then attempt a standard scan. Please stop the standard scan and then go to the update tab, just make sure it is updated. Then go back to the computer scan and select full scan.

    l.png

    Once complete, go to the logfiles tab and double click on the scan log.

    rr.png

    After you double click on the log a notepad will open, copy and paste that report into your next reply.

    You will not be able to use Loaris unless you pay for it, at this point the program has served its purpose and you may uninstall it. Having the logfile is all that is needed, if anything was detected by the program. [​IMG]
     
    Last edited: Jun 4, 2015
  13. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93

    For now reason core security is protecting you, we will get you set up with an antivirus when we are done here. :)
     
  14. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations!
    O.K. as requested................

    Trojan Remover v.1.3.7.3
    Report file date: 05/06/2015 11:39:18
    Last update: 05/06/2015 11:38:37

    Scanning for 1517350 virus strains and unwanted programs.

    Licensed: UNREGISTERED
    Windows version: Windows 7 Ultimate (version 6.1)
    Username: Brewster
    Computer name: BREWSTER-PUTER

    Starting the file scan:

    Full Scan started
    Scanning process...
    ----- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ---- Registry Threat
    Adware.RPL.Boxore.vb


    ----- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL ---- Registry Suspicious
    LSP: Target-not-found
    RegPath: HKLM\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008


    ----- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL ---- Registry Suspicious
    LSP: Target-not-found
    RegPath: HKLM\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000009


    Checking Startup...
    ----- HKCU\Software\Microsoft\Windows\CurrentVersion\Run|uTorrent ""c:\users\brewster\appdata\roaming\utorrent\utorrent.exe" /minimized" ---- Registry Suspicious
    Target-not-found


    Checking Services...
    Checking BHO...
    Checking ActiveX...
    Checking Files...
    ----- C:\$RECYCLE.BIN\S-1-5-21-3299126282-3657997626-4182433575-1000\$R7X3BXI\updates\3.3.1_30017.exe ---- General Threat
    Malware.Win32.Gen.sm!s2
    ProdVer: 3.3.1.30017
    FileVer: 3.3.1.30017
    Name: \u00B5Torrent
    Company: ********** Inc.
    NAC: 34E007EE3962CFFCAC89D3FE08D51F7E:23
    MD5: AB11A6A7E1C011AD19BF674A01ACC2D5:1130576
    RIC: C391858A0485B9A3ACE343A146D780F2:106993
    RFH: 1536:/7CBjVwLIxVTtIYFAn++Z53WV0ompZxFiukgNYpNwkfslR5dbNilMwvbR9B2:OBR7Lyn+m53WVuxsIOLmIx
    SUBS: Win32 GUI
    PE: x86
    EP: 60BE00605A008DBE00B0E5FF5789E58D9C2480C1FFFF31C05039DC75FB4646536844C525005783C3045368E48C0B005683C3045350C70303000200909090909055
    EPSEC: 1
    EPRVA: 0025ECF0
    IBASE: 00400000
    SEC:
    UPX0:E0000080:00000000000000000000000000000000:0
    UPX1:E0000040:C5AED27D50C415360E9B4881322ABC81:760320
    .rsrc:C0000040:AEED1443859E22CBBC8D4AD776FEBD80:120320
    .bunndl:12000000:C2D1573136F7ECEE5E33194E1A9510C0:136192
    .adknow:12000000:E91CD5BBCF94D8B3455254F7744F738C:102400


    Terminated by user

    Scan result: 5 detected items
    Scan completed in: Scan completed in 27 minute(s) 37 sec.
    Files were scanned: 12519
     
  15. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Hello, you have not ran the fixlist from post 47. Please run it, also let Loaris Trojan remover complete the full scan. I would also like you to download and install this antivirus below, this I think will be perfect for you. It uses very very minimal resource, also it will scan each and every single file that you download at virus total for you. The initial install will take a while to run, but once installed on your machine you will be very happy with the protection that you are able to have.
    http://www.secureaplus.com/Main/secureaplus_download.php

    Combine it with crystal security and you should be very much protected, you can run these side by side no issue.
    http://www.crystalsecurity.eu/

    You can uninstall VirIT eXplorer Lite as it only offers on demand scanning.
     
  16. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    We will remove what loaris found when you allow it to complete a full scan. :)
     
  17. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and salutations!
    O.K. While secureplus is chuntering away to itself, i think I got it right this time:-
    Fix result of Farbar Recovery Scan Tool (x86) Version: 29-05-2015
    Ran by Brewster at 2015-06-06 11:36:13 Run:3
    Running from C:\Users\Brewster\Desktop
    Loaded Profiles: Brewster (Available Profiles: Brewster & Margies)
    Boot Mode: Normal

    ==============================================

    fixlist content:
    *****************
    start
    CloseProcesses:
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
    Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
    CMD: netsh advfirewall reset
    CMD: netsh advfirewall set allprofiles state ON
    CMD: ipconfig /flushdns
    CMD: netsh winsock reset catalog
    CMD: netsh int ip reset c:\resetlog.txt
    CMD: ipconfig /release
    CMD: ipconfig /renew
    CMD: netsh int ipv4 reset
    CMD: netsh int ipv6 reset
    hosts:
    Emptytemp:
    RemoveProxy:
    reboot:
    end
    *****************

    Processes closed successfully.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key Removed successfully.
    HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
    HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008" => key Removed successfully.
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000009" => key Removed successfully.

    ========= netsh advfirewall reset =========

    Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
    Ok.


    ========= End of CMD: =========


    ========= netsh advfirewall set allprofiles state ON =========

    Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
    Ok.


    ========= End of CMD: =========


    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========


    ========= netsh winsock reset catalog =========

    Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003

    Sucessfully reset the Winsock Catalog.
    You must restart the computer in order to complete the reset.


    ========= End of CMD: =========


    ========= netsh int ip reset c:\resetlog.txt =========

    Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
    Reseting Global, OK!
    Reseting Interface, OK!
    Restart the computer to complete this action.


    ========= End of CMD: =========


    ========= ipconfig /release =========


    Windows IP Configuration

    No operation can be performed on Wireless Network Connection 2 while it has its media disconnected.
    No operation can be performed on Local Area Connection while it has its media disconnected.

    Wireless LAN adapter Wireless Network Connection 2:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . :

    Wireless LAN adapter Wireless Network Connection:

    Connection-specific DNS Suffix . :
    Link-local IPv6 Address . . . . . : fe80::dcd5:6fd8:324f:1268%13
    Default Gateway . . . . . . . . . :

    Ethernet adapter Local Area Connection:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . : home

    ========= End of CMD: =========


    ========= ipconfig /renew =========


    Windows IP Configuration

    No operation can be performed on Wireless Network Connection 2 while it has its media disconnected.
    No operation can be performed on Local Area Connection while it has its media disconnected.

    Wireless LAN adapter Wireless Network Connection 2:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . :

    Wireless LAN adapter Wireless Network Connection:

    Connection-specific DNS Suffix . : home
    Link-local IPv6 Address . . . . . : fe80::dcd5:6fd8:324f:1268%13
    IPv4 Address. . . . . . . . . . . : 192.168.1.69
    Subnet Mask . . . . . . . . . . . : 0.0.0.0
    Default Gateway . . . . . . . . . : 192.168.1.254

    Ethernet adapter Local Area Connection:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . : home

    ========= End of CMD: =========


    ========= netsh int ipv4 reset =========

    Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
    Reseting Interface, OK!
    Restart the computer to complete this action.


    ========= End of CMD: =========


    ========= netsh int ipv6 reset =========

    Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
    There's no user specified settings to be reset.


    ========= End of CMD: =========

    C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
    Hosts restored successfully.

    ========= RemoveProxy: =========

    HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value Removed successfully.
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value Removed successfully.
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value Removed successfully.


    ========= End of RemoveProxy: =========

    EmptyTemp: => Removed 23.1 MB temporary data.


    The system needed a reboot.

    ==== End of Fixlog 11:36:32 ====


    Trojan Remover v.1.3.7.4
    Report file date: 06/06/2015 11:48:02
    Last update: 06/06/2015 11:47:43

    Scanning for 1517154 virus strains and unwanted programs.

    Licensed: UNREGISTERED
    Windows version: Windows 7 Ultimate (version 6.1)
    Username: Brewster
    Computer name: BREWSTER-PUTER

    Starting the file scan:

    Full Scan started
    Scanning process...
    Checking Startup...
    Checking Services...
    Checking BHO...
    Checking ActiveX...
    Checking Files...
    ----- C:\Users\Brewster\Documents\My Documents\Downloads\utorrent.exe ---- General Threat
    Malware.Win32.Gen.sm!s2
    ProdVer: 3.3.1.30017
    FileVer: 3.3.1.30017
    Name: \u00B5Torrent
    Company: ********** Inc.
    NAC: 34E007EE3962CFFCAC89D3FE08D51F7E:23
    MD5: AB11A6A7E1C011AD19BF674A01ACC2D5:1130576
    RIC: C391858A0485B9A3ACE343A146D780F2:106993
    RFH: 1536:/7CBjVwLIxVTtIYFAn++Z53WV0ompZxFiukgNYpNwkfslR5dbNilMwvbR9B2:OBR7Lyn+m53WVuxsIOLmIx
    SUBS: Win32 GUI
    PE: x86
    EP: 60BE00605A008DBE00B0E5FF5789E58D9C2480C1FFFF31C05039DC75FB4646536844C525005783C3045368E48C0B005683C3045350C70303000200909090909055
    EPSEC: 1
    EPRVA: 0025ECF0
    IBASE: 00400000
    SEC:
    UPX0:E0000080:00000000000000000000000000000000:0
    UPX1:E0000040:C5AED27D50C415360E9B4881322ABC81:760320
    .rsrc:C0000040:AEED1443859E22CBBC8D4AD776FEBD80:120320
    .bunndl:12000000:C2D1573136F7ECEE5E33194E1A9510C0:136192
    .adknow:12000000:E91CD5BBCF94D8B3455254F7744F738C:102400


    Scan completed

    Scan result: 1 detected items
    Scan completed in: Scan completed in 46 minute(s) 11 sec.
    Files were scanned: 34792
    Here's hoping that's correct
    Until the next time...........................
     
  18. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Here is a nice software that will help you update your software for free. Click Me To Update Software.

    Some Suggested Software To Keep You Safe On The Internet.

    Qualys BrowserCheck To update plugins.
    Web Of Trust To Avoid Shady Websites.
    Unchecky To Avoid Bundled Software.
    AdBlock Plus To Browse The Web Ad Free.
    Malwarebytes Anti Exploit To Block Zero Day Attacks.
    Malwarebytes Startup Lite To Disable Useless Items Starting With Your Computer.
    FanBoys Ultimate list. Add The Ultimate List.
    ToolWhiz Smart Defrag Defrag Your Machine With Speed.
    For Chrome Adguard
    For FireFox Adguard


    Now Lets Clean up the tools we used and remove old restore points.

    Download DelFix by "Xplode" to your Desktop.
    Right Click the tool and Run as Admin ( Xp Users Double Click)
    Put a check mark next the items below:


    Remove disinfection tools
    Create registry backup
    Purge System Restore




    Now click on "Run" button.
    allow the program to complete its work.
    all the tools we used will be removed.
    Tool will create and open a log report (DelFix.txt)
    Note: The report can be located at the following location C:\DelFix.txt
     
    driver_ian likes this.
  19. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Please let me know if you have any current issues.
     
  20. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations!
    I've done everything as requested, and the only thing I cannot run is unchecky even after uninstalling reason core security
    apart from that though it seems as everything is running as it should............................................
     
Loading...

Share This Page