1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
  2. Welcome to iHelpForum - the place to get help from knowledgeable techs in all areas of Tech, Home and Auto help. Consider checking out our Guides or Registering an account to post on our forums today.

    Dismiss Notice

Solved Slow Computer

Discussion in 'Virus, Spyware and Malware Removal Help' started by brewster393, May 20, 2015.

  1. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations! Pt 2
    One other thing
    I get this at start up
    Application Error
    Exception EAccessViolation in module ltr. exe at 0055AB.
    Access violation at address 009SAB4B in module 'ltr. exe'. Read of address 00000198
     
  2. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Post a new FRST log we will take care of that. :)
     
  3. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2015
    Ran by Brewster (administrator) on BREWSTER-PUTER on 09-06-2015 13:56:07
    Running from C:\Users\Brewster\Desktop
    Loaded Profiles: Brewster (Available Profiles: Brewster & Margies)
    Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    () C:\Program Files\SecureAge\Everything\Everything.exe
    (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe
    (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\saappsvc.exe
    (SecureAge Technology) C:\Program Files\SecureAge\Everything\EverythingServer.exe
    (SecureAge Technology) C:\Program Files\SecureAge\AntiVirus\sascansvc.exe
    (SecureAge Technology) C:\Program Files\SecureAge\UniversalAV\UniversalAVService.exe
    (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\SecureAPlusService.exe
    (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\sanotifier.exe
    (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\SecureAPlus.exe
    (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
    () C:\Program Files\RocketDock\RocketDock.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
    (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
    (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
    (SourceFire, Inc.) C:\Program Files\SecureAge\AntiVirus\clamd.exe
    (Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SAAppWhitelistingNotifier] => C:\Program Files\SecureAge\Whitelist\sanotifier.exe [7804096 2015-05-15] (SecureAge Technology)
    HKLM\...\Run: [SecureAPlus] => C:\Program Files\SecureAge\Whitelist\SecureAPlus.exe [23413200 2015-05-15] (SecureAge Technology)
    HKLM\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [2618680 2015-04-08] (Malwarebytes Corporation)
    Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2014-04-11] (Citrix Online, a division of Citrix Systems, Inc.)
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] ()
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
    BootExecute: autocheck autochk /p \??\H:autocheck autochk *

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    SearchScopes: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-24] (Oracle Corporation)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-24] (Oracle Corporation)
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254

    FireFox:
    ========
    FF ProfilePath: C:\Users\Brewster\AppData\Roaming\Mozilla\Firefox\Profiles\yabp1zv0.default-1432304493341
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-17] ()
    FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-24] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-24] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Motive.com/NpMotive,version=1.0 -> C:\Program Files\Common Files\Motive\npMotive.dll [2012-10-05] (Alcatel-Lucent)
    FF Plugin: @Motive.com/npMotiveRequest,version=1.0 -> C:\Program Files\Common Files\Motive\npMotiveRequest.dll [2011-12-06] (Alcatel-Lucent)
    FF Plugin: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Brewster\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-04-15] (RocketLife, LLP)
    FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
    FF Extension: Qualys BrowserCheck - C:\Users\Brewster\AppData\Roaming\Mozilla\Firefox\Profiles\yabp1zv0.default-1432304493341\Extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} [2015-06-08]
    FF Extension: WOT - C:\Users\Brewster\AppData\Roaming\Mozilla\Firefox\Profiles\yabp1zv0.default-1432304493341\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-06-08]
    FF Extension: Adguard AdBlocker - C:\Users\Brewster\AppData\Roaming\Mozilla\Firefox\Profiles\yabp1zv0.default-1432304493341\Extensions\adguardadblocker@adguard.com.xpi [2015-06-08]
    FF Extension: Adblock Plus - C:\Users\Brewster\AppData\Roaming\Mozilla\Firefox\Profiles\yabp1zv0.default-1432304493341\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-06-08]
    FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\mcciwbch@motive.com.xpi [2015-06-02]

    Chrome:
    =======
    CHR Profile: C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Docs) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-02]
    CHR Extension: (Google Drive) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-02]
    CHR Extension: (YouTube) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-02]
    CHR Extension: (Google Search) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-02]
    CHR Extension: (avast! Online Security) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-06-02]
    CHR Extension: (Google Wallet) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-02]
    CHR Extension: (Gmail) - C:\Users\Brewster\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-02]

    ========================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
    S4 BT Help Wizard; C:\Program Files\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe [321024 2014-04-09] (Alcatel-Lucent) [File not signed]
    R2 Everything; C:\Program Files\SecureAge\Everything\Everything.exe [1048576 2014-08-06] () [File not signed]
    S3 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2014-04-11] (Citrix Online, a division of Citrix Systems, Inc.)
    R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [656184 2015-04-08] (Malwarebytes Corporation)
    S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
    R2 saappsvc; C:\Program Files\SecureAge\Whitelist\saappsvc.exe [778944 2015-05-15] (SecureAge Technology)
    R2 SAEverythingServer; C:\Program Files\SecureAge\Everything\EverythingServer.exe [184512 2015-03-11] (SecureAge Technology)
    R2 sascansvc; C:\Program Files\SecureAge\AntiVirus\sascansvc.exe [827344 2015-05-15] (SecureAge Technology)
    R2 SAUAVSvc; C:\Program Files\SecureAge\UniversalAV\UniversalAVService.exe [962752 2015-05-15] (SecureAge Technology)
    R2 SecureAPlusService; C:\Program Files\SecureAge\Whitelist\SecureAPlusService.exe [769152 2015-05-15] (SecureAge Technology)
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
    S2 ZAMSvc; "C:\Program Files\Zemana AntiMalware\ZAM.exe" /service [X]

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 athur; C:\Windows\System32\DRIVERS\athur.sys [1559552 2010-07-28] (Atheros Communications, Inc.)
    R3 cmuda; C:\Windows\System32\drivers\cmuda.sys [1332544 2005-05-12] (C-Media Inc)
    R3 ctxS51; C:\Windows\System32\DRIVERS\ctxS51.sys [1903646 2006-05-01] (Intel Corporation)
    R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47928 2015-04-08] ()
    R3 FETNDIS; C:\Windows\System32\DRIVERS\fetn62.sys [53872 2011-04-08] (VIA Technologies, Inc. )
    S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [35992 2015-05-27] ()
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
    S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    R3 nvmpu401; C:\Windows\System32\drivers\nvmpu401.sys [10240 2005-04-13] (NVIDIA Corporation)
    R0 SAAppCtl; C:\Windows\System32\DRIVERS\saappctl.sys [201872 2015-05-12] (SecureAge Technology)
    R0 sascan; C:\Windows\System32\DRIVERS\sascan.sys [69312 2015-05-14] (SecureAge Technology)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 trufos; C:\Windows\System32\drivers\trufos.sys [343456 2015-05-21] (BitDefender S.R.L.)
    S1 ZAM; \??\C:\Windows\System32\drivers\zam32.sys [X]
    S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard32.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-09 13:56 - 2015-06-09 13:57 - 00012625 _____ C:\Users\Brewster\Desktop\FRST.txt
    2015-06-09 13:52 - 2015-06-09 13:56 - 00000000 ____D C:\FRST
    2015-06-09 13:52 - 2015-06-09 13:52 - 01147904 _____ (Farbar) C:\Users\Brewster\Desktop\FRST.exe
    2015-06-09 13:50 - 2015-06-09 13:56 - 00040807 _____ C:\Windows\WindowsUpdate.log
    2015-06-08 12:18 - 2015-06-08 14:55 - 00000000 ____D C:\Users\Brewster\Downloads\Mickey Haller 1-5 Michael Connelly
    2015-06-08 11:24 - 2015-06-08 11:24 - 00000000 ____D C:\Program Files\Toolwiz Smart Defrag FREE
    2015-06-08 11:23 - 2015-06-08 11:23 - 00776280 _____ (Toolwiz.com. ) C:\Users\Brewster\Downloads\Setup_SmartDefrag(1).exe
    2015-06-08 11:22 - 2015-06-08 11:23 - 00776280 _____ (Toolwiz.com. ) C:\Users\Brewster\Downloads\Setup_SmartDefrag.exe
    2015-06-08 11:20 - 2015-06-08 11:20 - 00204496 _____ (Malwarebytes) C:\Users\Brewster\Downloads\startuplite-setup-1.07.exe
    2015-06-08 11:19 - 2015-06-08 11:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
    2015-06-08 11:19 - 2015-06-08 11:19 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
    2015-06-08 11:19 - 2015-06-08 11:19 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Exploit
    2015-06-08 11:15 - 2015-06-08 11:15 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\Qualys
    2015-06-08 10:49 - 2015-06-08 10:49 - 00001445 _____ C:\Users\Brewster\Desktop\PatchMyPC.exe - Shortcut.lnk
    2015-06-08 10:45 - 2015-06-08 10:45 - 00130048 _____ (CodePlex Community) C:\Users\Brewster\Downloads\Microsoft.Win32.TaskScheduler.dll
    2015-06-08 10:43 - 2015-06-08 10:43 - 03020968 _____ (Malwarebytes ) C:\Users\Brewster\Downloads\mbae-setup-1.06.1.1019.exe
    2015-06-08 10:32 - 2015-06-08 10:32 - 00554528 _____ (www.patchmypc.net) C:\Users\Brewster\Downloads\PatchMyPC.exe
    2015-06-08 10:31 - 2015-06-08 10:31 - 00002298 _____ C:\Users\Brewster\Desktop\DelFix.txt
    2015-06-08 10:29 - 2015-06-08 10:30 - 00002298 _____ C:\DelFix.txt
    2015-06-07 15:33 - 2015-06-07 15:33 - 02094854 _____ C:\Users\Brewster\Downloads\The Forsaken - Atkins, Ace.epub
    2015-06-07 15:31 - 2015-06-07 15:31 - 00000000 ____D C:\Users\Brewster\Downloads\Ace Atkins_Nick Travers Series #1-#4 (Gritty Thrillers)
    2015-06-06 17:00 - 2015-06-08 18:43 - 00000000 ____D C:\Users\Brewster\AppData\Local\CrashDumps
    2015-06-06 16:53 - 2015-06-06 16:53 - 00789210 _____ C:\Users\Brewster\Downloads\Box, C. J.-The Highway.epub
    2015-06-06 15:06 - 2015-06-06 15:06 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\Crystal Security
    2015-06-06 15:06 - 2015-06-06 15:06 - 00000000 ____D C:\Program Files\Crystal Security
    2015-06-06 15:05 - 2015-06-06 15:05 - 00802816 _____ C:\Users\Brewster\Downloads\crystal_security_3.5.0.129_setup.msi
    2015-06-06 15:05 - 2015-06-06 15:05 - 00523598 _____ C:\Users\Brewster\Downloads\crystal_security_3.5.0.129.zip
    2015-06-06 14:02 - 2015-06-09 13:57 - 05042712 _____ C:\Windows\system32\Drivers\whitelist2.sa
    2015-06-06 14:02 - 2015-06-06 14:02 - 17408375 _____ C:\Windows\system32\scan.db
    2015-06-06 14:02 - 2015-06-06 14:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SecureAge
    2015-06-06 14:02 - 2015-06-06 14:02 - 00000000 ____D C:\ProgramData\ClamAV
    2015-06-06 14:01 - 2015-06-06 14:01 - 00000000 ____D C:\ProgramData\SecureAge Technology
    2015-06-06 14:01 - 2015-06-06 14:01 - 00000000 ____D C:\Program Files\SecureAge
    2015-06-06 14:00 - 2015-06-06 14:00 - 01919680 _____ (SecureAge Technology) C:\Users\Brewster\Downloads\SecureAPlusSetup.exe
    2015-06-06 13:56 - 2015-06-06 13:56 - 01142616 _____ (RaMMicHaeL) C:\Users\Brewster\Downloads\unchecky_setup.exe
    2015-06-05 18:19 - 2015-06-05 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
    2015-06-05 18:15 - 2015-06-05 18:17 - 64573440 _____ C:\Users\Brewster\Downloads\calibre-2.30.0.msi
    2015-06-05 18:10 - 2015-06-05 18:10 - 00000816 _____ C:\Users\Brewster\Desktop\********.lnk
    2015-06-05 18:08 - 2015-06-08 18:47 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\uTorrent
    2015-06-05 18:08 - 2015-06-05 18:08 - 01998432 _____ (********** Inc.) C:\Users\Brewster\Downloads\uTorrent.exe
    2015-06-05 10:32 - 2015-06-05 10:32 - 00000000 ____D C:\ProgramData\Loaris
    2015-06-05 10:32 - 2015-06-05 10:32 - 00000000 ____D C:\Program Files\Loaris
    2015-06-02 15:28 - 2015-06-04 14:09 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2015-05-31 16:46 - 2015-05-31 16:46 - 00000000 ____D C:\Users\Brewster\Downloads\Russell Blake
    2015-05-31 13:07 - 2015-05-31 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sigil
    2015-05-31 13:06 - 2015-05-31 13:06 - 28166248 _____ (John Schember ) C:\Users\Brewster\Downloads\Sigil-0.7.4-Windows-Setup.exe
    2015-05-31 12:52 - 2015-05-31 12:53 - 30368764 _____ (John Schember ) C:\Users\Brewster\Downloads\Sigil-0.8.6-Windows-Setup(1).exe
    2015-05-31 12:46 - 2015-05-31 12:57 - 00000000 ___HD C:\Program Files\InstallJammer Registry
    2015-05-31 12:45 - 2015-05-31 13:07 - 00000000 ____D C:\Program Files\Sigil
    2015-05-31 12:44 - 2015-05-31 12:45 - 11713653 _____ (Strahinja Marković) C:\Users\Brewster\Downloads\Sigil-0.3.2-Windows-Setup.exe
    2015-05-31 12:23 - 2015-05-31 12:23 - 00000000 ____D C:\ProgramData\Package Cache
    2015-05-31 12:21 - 2015-05-31 12:21 - 30368764 _____ (John Schember ) C:\Users\Brewster\Downloads\Sigil-0.8.6-Windows-Setup.exe
    2015-05-30 15:12 - 2015-05-30 15:06 - 00026747 _____ C:\Users\Brewster\Documents\BREWSTER-PUTER.speccy
    2015-05-29 15:09 - 2015-05-29 15:09 - 00007605 _____ C:\Users\Brewster\AppData\Local\Resmon.ResmonCfg
    2015-05-29 13:20 - 2015-05-29 13:21 - 00000000 ____D C:\Users\Brewster\Downloads\23 Stephen Leather Novels in Mobi, KK
    2015-05-29 11:21 - 2015-05-29 11:21 - 00000000 ___SD C:\Windows\system32\GWX
    2015-05-28 13:45 - 2015-05-28 13:45 - 00000000 ____D C:\ProgramData\TP-LINK
    2015-05-28 11:53 - 2015-06-08 11:37 - 00000000 ____D C:\Program Files\Reason
    2015-05-27 15:42 - 2015-05-27 15:54 - 00000000 ____D C:\Users\Brewster\Downloads\Tales of The Empire 1-3 by S. J. A. Turney
    2015-05-27 15:06 - 2015-05-31 13:28 - 00000000 ____D C:\Users\Brewster\Documents\Calibre Library
    2015-05-27 15:05 - 2015-05-29 18:37 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\calibre
    2015-05-27 14:56 - 2015-05-27 14:56 - 00000000 ____D C:\Users\Brewster\Downloads\S. J. A. Turney
    2015-05-27 13:33 - 2015-06-08 11:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\9-lab
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D C:\ProgramData\9-lab
    2015-05-27 13:33 - 2015-05-27 13:33 - 00000000 ____D C:\Program Files\9-lab
    2015-05-27 13:32 - 2015-05-27 13:32 - 06330112 _____ C:\Users\Brewster\Downloads\rmtool-setup-x86.exe
    2015-05-27 12:06 - 2015-05-27 12:06 - 00006876 _____ C:\Windows\system32\.crusader
    2015-05-27 11:54 - 2015-05-27 12:09 - 00035992 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
    2015-05-27 11:43 - 2015-05-27 12:06 - 00000000 ____D C:\ProgramData\HitmanPro
    2015-05-27 09:43 - 2015-05-27 09:43 - 06549184 _____ (Piriform Ltd) C:\Users\Brewster\Downloads\ccsetup506.exe
    2015-05-25 12:09 - 2015-06-02 14:56 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\Vso
    2015-05-25 12:09 - 2015-06-01 16:47 - 00000671 _____ C:\Users\Brewster\AppData\Roaming\vso_ts_preview.xml
    2015-05-24 15:40 - 2015-05-24 15:40 - 00000000 ____D C:\Users\Brewster\Downloads\Anthony Beevor - The Second World War
    2015-05-24 15:39 - 2015-05-24 16:30 - 00000000 ____D C:\Users\Brewster\Downloads\[E-book ENG - epub-mobi-pdf] - Antony Beevor - Berlin. The Downfall, 1945
    2015-05-24 15:37 - 2015-05-24 15:37 - 00000000 ____D C:\Users\Brewster\Downloads\The Fall Of Berlin 1945 By Antony Beevor (Epub,Mobi) Gooner
    2015-05-24 12:13 - 2015-05-24 12:52 - 00000000 ____D C:\Windows\erdnt
    2015-05-23 13:26 - 2015-05-23 13:26 - 00000000 ____D C:\Program Files\ESET
    2015-05-23 11:17 - 2015-05-23 11:18 - 00290304 _____ (Microsoft Corporation) C:\Windows\system32\subinacl.exe
    2015-05-23 11:17 - 2015-05-23 11:17 - 00000000 ____D C:\Program Files\Adware-Removal-Tool
    2015-05-23 11:16 - 2015-05-23 11:17 - 00001602 _____ C:\Users\Brewster\Desktop\Adware-Removal-Tool-v3.9.1.exe - Shortcut.lnk
    2015-05-23 11:14 - 2015-05-23 11:14 - 00753184 _____ C:\Users\Brewster\Downloads\Adware-Removal-Tool-v3.9.1.exe
    2015-05-22 12:27 - 2015-05-22 12:27 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BREWSTER-PUTER-Windows-7-Ultimate-(32-bit).dat
    2015-05-21 19:35 - 2015-06-08 18:38 - 00000000 ____D C:\Program Files\Zemana AntiMalware
    2015-05-21 19:35 - 2015-05-21 19:35 - 00000000 ____D C:\Users\Brewster\AppData\Local\Zemana
    2015-05-21 16:56 - 2015-05-21 16:58 - 11119633 _____ C:\Windows\REGBK00.ZIP
    2015-05-21 16:54 - 2015-05-21 17:08 - 00000056 _____ C:\Windows\Lic.xxx
    2015-05-21 16:53 - 2015-05-21 16:53 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\msvcr90.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00632064 _____ (Microsoft Corporation) C:\Windows\system32\msvcr80.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00572928 _____ (Microsoft Corporation) C:\Windows\system32\msvcp90.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00554240 _____ (Microsoft Corporation) C:\Windows\system32\msvcp80.dll
    2015-05-21 16:53 - 2015-05-21 16:53 - 00343456 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
    2015-05-21 16:53 - 2015-05-21 16:53 - 00156392 _____ (MicroWorld Technologies Inc.) C:\Windows\system32\eEmpty.exe
    2015-05-21 16:53 - 2015-05-21 16:53 - 00000000 ____D C:\ProgramData\MicroWorld
    2015-05-21 15:59 - 2015-05-27 09:44 - 00000000 ____D C:\Program Files\CCleaner
    2015-05-21 15:59 - 2015-05-21 15:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    2015-05-21 15:08 - 2015-05-29 15:26 - 00063544 _____ C:\Users\Brewster\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-05-21 15:07 - 2015-06-08 11:44 - 00000000 ____D C:\Program Files\System Ninja
    2015-05-21 14:29 - 2015-05-21 14:29 - 00546456 _____ (www.privacyroot.com) C:\Users\Brewster\Downloads\setup_wipe.exe
    2015-05-19 16:19 - 2015-05-19 16:19 - 00000000 ____D C:\Users\Brewster\Documents\Leawo
    2015-05-19 16:19 - 2015-05-19 16:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Leawo
    2015-05-19 16:19 - 2013-06-20 09:10 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\msvcp71.dll
    2015-05-19 16:19 - 2013-06-20 09:10 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll
    2015-05-19 16:18 - 2015-05-21 15:20 - 00000000 ____D C:\Program Files\K-Lite Codec Pack
    2015-05-19 16:18 - 2015-05-19 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
    2015-05-19 16:18 - 2012-06-09 18:21 - 00178688 _____ C:\Windows\system32\unrar.dll
    2015-05-19 16:17 - 2015-05-19 16:17 - 00000000 ____D C:\Program Files\Leawo
    2015-05-19 16:15 - 2015-05-19 16:16 - 42643064 _____ (Leawo Software Co.,Ltd. ) C:\Users\Brewster\Downloads\videoconverter_free.exe
    2015-05-19 11:24 - 2015-04-24 12:10 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
    2015-05-19 11:24 - 2015-04-24 12:10 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
    2015-05-19 11:24 - 2015-04-24 12:10 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
    2015-05-19 11:22 - 2015-04-24 12:10 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
    2015-05-19 11:19 - 2015-05-19 11:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
    2015-05-14 10:06 - 2015-05-14 10:06 - 00069312 _____ (SecureAge Technology) C:\Windows\system32\Drivers\sascan.sys
    2015-05-13 19:41 - 2015-05-01 14:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-05-13 19:10 - 2015-05-13 19:10 - 00000000 ____D C:\Users\Default
    2015-05-13 17:30 - 2015-05-14 13:21 - 00000000 ____D C:\Users\Brewster\Downloads\Cotton Malone Collection - Steve Berry [EPUB]
    2015-05-13 17:13 - 2015-04-27 20:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
    2015-05-13 17:13 - 2015-04-27 20:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-05-13 17:13 - 2015-04-27 20:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-05-13 17:13 - 2015-04-27 20:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-05-13 17:13 - 2015-04-27 20:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-05-13 17:13 - 2015-04-27 20:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-05-13 17:13 - 2015-04-27 20:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-05-13 17:13 - 2015-04-27 20:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-05-13 17:13 - 2015-04-27 20:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-05-13 17:13 - 2015-04-27 20:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
    2015-05-13 17:13 - 2015-04-27 20:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-05-13 17:13 - 2015-04-27 20:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-05-13 17:13 - 2015-04-27 19:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-05-13 17:13 - 2015-04-27 19:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-05-13 17:13 - 2015-04-27 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
    2015-05-13 17:13 - 2015-01-29 04:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
    2015-05-13 17:12 - 2015-05-05 02:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-05-13 17:12 - 2015-04-20 03:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-05-13 17:12 - 2015-04-20 03:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-05-13 17:12 - 2015-04-20 03:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-05-13 17:12 - 2015-04-18 03:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
    2015-05-13 17:11 - 2015-04-22 02:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-05-13 17:11 - 2015-04-21 17:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-05-13 17:11 - 2015-04-21 17:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-05-13 17:11 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-05-13 17:11 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-05-13 17:11 - 2015-04-21 17:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-05-13 17:11 - 2015-04-21 17:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-05-13 17:11 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-05-13 17:11 - 2015-04-21 17:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-05-13 17:11 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-05-13 17:11 - 2015-04-21 17:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-05-13 17:11 - 2015-04-21 17:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-05-13 17:11 - 2015-04-21 17:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-05-13 17:11 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-05-13 17:11 - 2015-04-21 16:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-05-13 17:11 - 2015-04-21 16:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-05-13 17:11 - 2015-04-21 16:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-05-13 17:11 - 2015-04-21 16:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-05-13 17:11 - 2015-04-21 16:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-05-13 17:11 - 2015-04-21 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-05-13 17:11 - 2015-04-21 16:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-05-13 17:11 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-05-13 17:11 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-05-13 17:11 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-05-13 17:11 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-05-13 17:11 - 2015-04-21 16:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-05-13 17:11 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-05-13 17:11 - 2015-04-21 16:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-05-13 17:11 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-05-13 17:11 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-05-13 17:11 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-05-13 17:11 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-05-13 17:11 - 2015-04-13 04:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
    2015-05-13 17:10 - 2015-04-08 04:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-05-13 17:10 - 2015-04-08 04:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-05-13 17:10 - 2015-03-04 05:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-05-13 17:10 - 2015-03-04 05:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-05-13 17:10 - 2015-03-04 05:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-05-13 17:10 - 2015-03-04 05:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-05-13 17:10 - 2015-02-18 08:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2015-05-12 04:54 - 2015-05-12 04:54 - 00201872 _____ (SecureAge Technology) C:\Windows\system32\Drivers\saappctl.sys
    2015-05-10 17:00 - 2015-05-10 17:00 - 00000000 ____D C:\Users\Brewster\Downloads\Campbell, Jack - Lost Stars 1-3 mobi
    2015-05-10 16:22 - 2015-05-10 16:22 - 00000000 ____D C:\Users\Brewster\Downloads\Tarnished Knight by Jack Campbell (The Lost Stars Book 1)
    2015-05-10 13:15 - 2015-05-10 13:16 - 00000000 ____D C:\Users\Brewster\Documents\Marg's Glasses Claim (HSF)

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-09 13:56 - 2009-07-14 05:34 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-06-09 13:56 - 2009-07-14 05:34 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-06-09 13:47 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-06-08 16:57 - 2010-11-20 22:01 - 00778180 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-06-08 11:24 - 2015-03-05 11:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toolwiz Smart Defrag FREE
    2015-06-08 11:14 - 2014-09-24 11:06 - 00001925 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    2015-06-08 11:14 - 2014-06-13 11:57 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
    2015-06-08 11:11 - 2015-03-01 18:24 - 00000000 ____D C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
    2015-06-08 11:11 - 2014-06-02 16:53 - 00000000 ____D C:\Program Files\Common Files\Apple
    2015-06-08 10:35 - 2014-09-01 13:39 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
    2015-06-08 10:35 - 2014-09-01 13:39 - 00000929 _____ C:\Users\Public\Desktop\Audacity.lnk
    2015-06-08 10:35 - 2014-09-01 13:39 - 00000000 ____D C:\Program Files\Audacity
    2015-06-08 10:30 - 2014-04-09 13:02 - 00000000 ____D C:\Windows\ERUNT
    2015-06-07 15:24 - 2014-04-08 14:32 - 00000000 ____D C:\Users\Brewster\Documents\My Kindle Content
    2015-06-06 15:01 - 2014-05-21 12:39 - 00000000 ____D C:\Program Files\WinRAR
    2015-06-05 18:19 - 2014-04-07 15:14 - 00000000 ____D C:\Program Files\Calibre2
    2015-06-05 18:10 - 2014-04-07 11:23 - 00000796 _____ C:\Users\Brewster\AppData\Roaming\Microsoft\Windows\Start Menu\********.lnk
    2015-06-05 11:32 - 2015-04-25 16:13 - 00000000 ____D C:\Users\Brewster\Downloads\Star Trek Voyager Season 1, 2, 3, 4, 5, 6 & 7 + Extras DVDRip TSV
    2015-06-05 11:32 - 2015-04-10 13:06 - 00000000 ____D C:\Users\Brewster\Downloads\Mrs Brown's Boy's
    2015-06-05 11:32 - 2015-01-03 12:34 - 00000000 ____D C:\Users\Brewster\Downloads\Star.Trek.Deep.Space.Nine.All.Seasons.COMPLETE.DVDRip.XviD-ArenaBG
    2015-06-01 16:46 - 2014-04-07 15:08 - 00000000 ____D C:\Users\Brewster\Documents\ConvertXtoDVD
    2015-06-01 13:40 - 2009-07-14 05:53 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
    2015-05-29 18:37 - 2014-04-05 18:39 - 00000000 ____D C:\Users\Brewster\AppData\Local\calibre-cache
    2015-05-29 15:33 - 2015-03-04 15:26 - 00000000 ____D C:\Windows\pss
    2015-05-29 15:26 - 2009-07-14 05:33 - 00287616 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-05-29 15:24 - 2010-11-21 01:46 - 00000000 ____D C:\Windows\CSC
    2015-05-28 14:12 - 2014-04-07 18:08 - 00045056 _____ (Northern Codeworks) C:\Windows\NCUNINST.EXE
    2015-05-28 11:27 - 2014-04-06 16:38 - 00000000 ____D C:\ProgramData\AVAST Software
    2015-05-27 11:04 - 2015-01-18 12:18 - 00000000 ____D C:\Users\Brewster\AppData\Local\WinZip
    2015-05-24 13:05 - 2014-11-28 17:09 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-05-24 13:04 - 2014-11-28 17:09 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-05-24 12:55 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
    2015-05-24 12:48 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
    2015-05-24 12:39 - 2014-04-08 17:48 - 00000000 ____D C:\Users\Brewster\Documents\CCleaner
    2015-05-23 10:51 - 2009-07-14 03:04 - 00002009 _____ C:\Windows\system32\Drivers\etc\hosts.old
    2015-05-21 17:01 - 2009-07-14 03:04 - 00000922 _____ C:\Windows\win.ini
    2015-05-21 16:02 - 2015-01-20 12:17 - 00000000 ____D C:\ProgramData\VSO
    2015-05-21 16:00 - 2014-04-06 02:39 - 00000000 ____D C:\Windows\Panther
    2015-05-21 15:19 - 2014-10-08 13:35 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\dvdcss
    2015-05-19 11:20 - 2014-04-07 14:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
    2015-05-19 11:20 - 2014-04-07 14:33 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
    2015-05-19 11:19 - 2015-01-18 12:18 - 00002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
    2015-05-19 11:19 - 2015-01-18 12:18 - 00002241 _____ C:\Users\Public\Desktop\WinZip.lnk
    2015-05-19 11:19 - 2015-01-18 12:17 - 00000000 ____D C:\Program Files\WinZip
    2015-05-17 16:31 - 2014-04-15 11:48 - 00000000 ____D C:\Users\Brewster\AppData\Local\Adobe
    2015-05-17 16:23 - 2014-09-05 13:16 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2015-05-17 13:31 - 2014-11-28 17:09 - 00001024 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-05-17 13:31 - 2014-11-28 17:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-05-17 13:31 - 2014-07-26 10:33 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
    2015-05-15 13:08 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
    2015-05-15 12:36 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
    2015-05-15 12:06 - 2014-04-15 11:52 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
    2015-05-14 13:27 - 2010-11-21 01:46 - 00000000 ____D C:\Program Files\Windows Journal
    2015-05-14 11:06 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
    2015-05-13 19:40 - 2014-04-06 18:29 - 00000000 ____D C:\Windows\system32\MRT
    2015-05-13 19:20 - 2014-04-06 18:28 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-05-11 11:47 - 2015-05-04 15:57 - 00000000 ___RD C:\Users\Brewster\Documents\HP Photo Creations
    2015-05-11 11:46 - 2015-05-04 15:56 - 00000000 ____D C:\Users\Brewster\AppData\Roaming\HP Photo Creations

    ==================== Files in the root of some directories =======

    2015-05-25 12:09 - 2015-06-01 16:47 - 0000671 _____ () C:\Users\Brewster\AppData\Roaming\vso_ts_preview.xml
    2015-05-29 15:09 - 2015-05-29 15:09 - 0007605 _____ () C:\Users\Brewster\AppData\Local\Resmon.ResmonCfg

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-06-04 15:21

    ==================== End of log ============================

    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 08-06-2015
    Ran by Brewster at 2015-06-09 13:59:45
    Running from C:\Users\Brewster\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-3299126282-3657997626-4182433575-500 - Administrator - Disabled)
    Brewster (S-1-5-21-3299126282-3657997626-4182433575-1000 - Administrator - Enabled) => C:\Users\Brewster
    Guest (S-1-5-21-3299126282-3657997626-4182433575-501 - Limited - Disabled)
    Margies (S-1-5-21-3299126282-3657997626-4182433575-1001 - Administrator - Enabled) => C:\Users\Margies
    Puter 1 (S-1-5-21-3299126282-3657997626-4182433575-1003 - Administrator - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: SecureAPlus Antivirus (Enabled - Up to date) {9BFA2AFA-9131-1E87-D290-6C0FAD7AF01D}
    AS: SecureAPlus (Enabled - Up to date) {209BCB1E-B70B-1109-E820-577DD6FDBAA0}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    ******** (HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\uTorrent) (Version: 3.4.3.40298 - ********** Inc.)
    Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
    Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.11) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
    Amazon Kindle (HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\Amazon Kindle) (Version: - Amazon)
    Apple Application Support (32-bit) (HKLM\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Audacity 2.1.0 (HKLM\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
    Auslogics DiskDefrag (HKLM\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 5.4.0.0 - Auslogics Labs Pty Ltd)
    Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
    BT Desktop Help (HKLM\...\BT Desktop Help) (Version: - )
    calibre (HKLM\...\{D28D6EE4-3319-49B7-BEE5-1D5B2AC3FF30}) (Version: 2.30.0 - Kovid Goyal)
    CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
    C-Media WDM Audio Driver (HKLM\...\C-Media Audio Driver) (Version: - )
    Cole2k Media - Codec Pack (Advanced) 8.0.2 (HKLM\...\Cole2k Media - Codec Pack) (Version: 8.0.2 - Cole2k Media)
    ConvertXtoDVD 3.3.2.100 (HKLM\...\{76C24F39-B161-498F-BD8B-C64789812D13}_is1) (Version: 3.3.2.100 - )
    Creatix V.9X DSP Data Fax Modem (HKLM\...\Creatix V.9X DSP Data Fax Modem) (Version: - )
    Crystal Security (HKLM\...\Crystal Security 3.5.0.129) (Version: 3.5.0.129 - Kardo Kristal)
    Crystal Security (Version: 3.5.0.129 - Kardo Kristal) Hidden
    DC-Bass Source 1.3.0 (HKLM\...\DC-Bass Source) (Version: - )
    DVD Decrypter (Remove Only) (HKLM\...\DVD Decrypter) (Version: - )
    DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version: - DVD Shrink)
    ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
    ffdshow v1.1.4399 [2012-03-22] (HKLM\...\ffdshow_is1) (Version: 1.1.4399.0 - )
    Free PDF to JPG Converter (HKLM\...\{ECD1BC70-A5FD-42D3-AEBA-B71FE88FDBF2}) (Version: 1.0.0 - Free PDF Solutions)
    Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
    GoToAssist Corporate (HKLM\...\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
    Haali Media Splitter (HKLM\...\HaaliMkx) (Version: - )
    HP FWUpdateEDO2 (HKLM\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
    HP Photo Creations (HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\...\HP Photo Creations) (Version: 1.0.0.18142 - HP)
    HP Photosmart 5510 series Basic Device Software (HKLM\...\{14AFF408-F4FB-4F71-B9A3-C6A1096802BF}) (Version: 24.0.342.0 - Hewlett-Packard Co.)
    HP Photosmart 5510 series Help (HKLM\...\{E02964EA-0E1B-4620-A26E-CBAB0341B1BB}) (Version: 140.0.2.2 - Hewlett Packard)
    HP Photosmart 5510 series Product Improvement Study (HKLM\...\{ED696A09-A237-4A29-95FF-95DC4AA8EA1A}) (Version: 24.0.342.0 - Hewlett-Packard Co.)
    HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
    HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
    Java 7 Update 65 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217065F0}) (Version: 7.0.650 - Oracle)
    Java 7 Update 80 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217080FF}) (Version: 7.0.800 - Oracle)
    Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
    Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
    K-Lite Codec Pack 9.4.0 (Basic) (HKLM\...\KLiteCodecPack_is1) (Version: 9.4.0 - )
    Lagarith Lossless Codec (1.3.27) (HKLM\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )
    LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - )
    Leawo Video Converter version 6.0.0.0 (HKLM\...\{331ED3CF-3A1B-467C-9A62-899E2D3B20C4}_is1) (Version: 6.0.0.0 - Leawo Software Co.,Ltd.)
    Malwarebytes Anti-Exploit version 1.06.1.1019 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.06.1.1019 - Malwarebytes)
    Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
    Microsoft Office 2000 Premium (HKLM\...\{00000409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
    Mozilla Firefox 38.0.5 (x86 en-US) (HKLM\...\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
    Nero 6 Ultra Edition (HKLM\...\Nero - Burning Rom!UninstallKey) (Version: - )
    QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
    Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
    RocketDock 1.3.5 (HKLM\...\RocketDock_is1) (Version: - Punk Software)
    SecureAPlus v3.3.5 (HKLM\...\SecureAPlus) (Version: 3.3.5 - SecureAge Technology)
    Sigil 0.7.4 (HKLM\...\Sigil_is1) (Version: - John Schember)
    Speccy (HKLM\...\Speccy) (Version: 1.26 - Piriform)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1194 - SUPERAntiSpyware.com)
    Toolwiz Smart Defrag 2011 (HKLM\...\Toolwiz Smart Defrag FREE_is1) (Version: 1.3.0.0 - Toolwiz.com.)
    TP-LINK Wireless Client Utility (HKLM\...\{1E03C8BE-0848-430F-BECA-7D7709401626}) (Version: 7.0 - TP-LINK)
    TreeSize Free V2.4 (HKLM\...\TreeSize Free_is1) (Version: 2.4 - JAM Software)
    Unknown Device Identifier 8.01 (HKLM\...\Unknown Device Identifier_is1) (Version: 8.01 - Huntersoft)
    VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
    VIA Rhine Family Fast Ethernet Adapter (HKLM\...\VN_VUIns_Rhine_VIA) (Version: - VIA Technologies, Inc.)
    WinRAR 5.21 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
    WinZip 19.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E6}) (Version: 19.0.11294 - WinZip Computing, S.L. )
    WinZip 19.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E8}) (Version: 19.5.11475 - WinZip Computing, S.L. )
    Xvid Video Codec (HKLM\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{49BBAA3C-C574-419E-8378-783C362E9C15}\InprocServer32 -> C:\Program Files\HP\Common\FWUpdateEDO2.dll (Hewlett-Packard Co.)
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> %SystemDrive%\Users\Brewster\AppData\Roaming\Microsoft\MSXML2\msxml4.dll No File
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{9356e2bb-6c9a-43c0-a771-5cacbdab6afe}\InprocServer32 -> C:\Users\Brewster\AppData\Roaming\HP Photo Creations\RLPNUpload.dll (RocketLife)
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{cc05a616-ddb3-4cc0-9a21-dc0e9962b444}\InprocServer32 -> C:\Users\Brewster\AppData\Roaming\HP Photo Creations\ContentMan.dll (RocketLife)
    CustomCLSID: HKU\S-1-5-21-3299126282-3657997626-4182433575-1000_Classes\CLSID\{ff280b55-14f1-49ae-b40f-15f5294ce630}\InprocServer32 -> C:\Users\Brewster\AppData\Roaming\HP Photo Creations\RocketEngine.dll (Visan inc.)

    ==================== Restore Points =========================

    09-06-2015 13:55:44 Windows Update

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-05-24 12:41 - 2015-06-08 11:36 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {24F8CBBC-666B-4BDA-A488-609A035BADD7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd)
    Task: {264881F8-72AE-4A51-A464-C97CAAE52FB4} - \Adobe Flash Player Updater No Task File <==== ATTENTION
    Task: {27979A2A-8C5B-4F5D-B3DF-E1B1E6F1B8DC} - \HP Photo Creations Communicator No Task File <==== ATTENTION
    Task: {4E03FDC6-9452-47D4-A38A-C925C57067FE} - \HPCustParticipation HP Photosmart 5510 series No Task File <==== ATTENTION
    Task: {533DC729-ABB0-4EAD-B38B-EA6D251804B6} - \{9431D8AA-4251-4929-A61C-77D7F05763F7} No Task File <==== ATTENTION
    Task: {6315A5ED-A71A-4432-92B5-8C43DA68EE33} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig No Task File <==== ATTENTION
    Task: {74D4CD44-98D6-4500-99F9-F0D6983C621A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    Task: {7D267275-6939-47CA-80DA-79F3449009E0} - \Apple\AppleSoftwareUpdate No Task File <==== ATTENTION
    Task: {80680B1C-75B5-4D24-8FDE-E94BEA2A09C7} - System32\Tasks\Trojan Remover => C:\Program Files\Loaris\Trojan Remover\ltr.exe [2015-06-05] (Loaris Inc.)
    Task: {82E0EC63-16B7-4BAE-BBE3-810A4E84032A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess No Task File <==== ATTENTION
    Task: {AC344371-414A-4CD1-B7AF-E9FCB4CF5481} - \HP Photo Creations Messager No Task File <==== ATTENTION
    Task: {CD831DED-AA3F-4D5C-AF3C-E5B9CEDEDFD4} - \Adobe Acrobat Update Task No Task File <==== ATTENTION
    Task: {DA32B882-B8D1-4EC4-9B6C-06800563E02D} - \{76DA891A-32C0-4E0C-BEA3-4BF381112203} No Task File <==== ATTENTION

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Loaded Modules (Whitelisted) ==============

    2001-07-31 11:17 - 2001-07-31 11:17 - 00094274 _____ () C:\Windows\System32\HPBHealr.dll
    2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-02-13 05:20 - 2015-02-13 05:20 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-08-06 03:31 - 2014-08-06 03:31 - 01048576 _____ () C:\Program Files\SecureAge\Everything\Everything.exe
    2014-04-07 15:22 - 2007-09-02 14:57 - 00069632 _____ () C:\Program Files\RocketDock\RocketDock.dll
    2014-08-14 08:45 - 2014-08-14 08:45 - 00069632 _____ () C:\Windows\system32\Everything32.dll
    2014-04-07 15:22 - 2007-09-02 14:58 - 00495616 _____ () C:\Program Files\RocketDock\RocketDock.exe
    2015-05-17 16:31 - 2015-05-17 16:31 - 16867504 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\saappsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\saappsvc => ""="Service"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-3299126282-3657997626-4182433575-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Brewster\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.254

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FAH.lnk => C:\Windows\pss\FAH.lnk.CommonStartup
    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
    MSCONFIG\startupfolder: C:^Users^Brewster^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk => C:\Windows\pss\Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk.Startup
    MSCONFIG\startupfolder: C:^Users^Brewster^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OptimizerProInstaller.lnk => C:\Windows\pss\OptimizerProInstaller.lnk.Startup
    MSCONFIG\startupfolder: C:^Users^Brewster^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Wipe Tray Agent.lnk => C:\Windows\pss\Wipe Tray Agent.lnk.Startup
    MSCONFIG\startupreg: btbb_McciTrayApp => "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
    MSCONFIG\startupreg: Everything => "C:\Program Files\SecureAge\Everything\Everything.exe" -config "C:\Program Files\SecureAge\Everything\Everything.ini" --startup
    MSCONFIG\startupreg: HP Photosmart 5510 series (NET) => "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1610B0LL05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1
    MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    MSCONFIG\startupreg: iSkysoft Helper Compact.exe => C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: NeroFilterCheck => C:\Windows\system32\NeroCheck.exe
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    MSCONFIG\startupreg: uTorrent => "C:\Users\Brewster\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
    MSCONFIG\startupreg: VIRIT LITE MONITOR => C:\VEXPLite\MONLITE.EXE
    MSCONFIG\startupreg: Wipe Maintance => "C:\Program Files\Wipe\net1.exe" windowsStartup
    MSCONFIG\startupreg: ZAM => "C:\Program Files\Zemana AntiMalware\ZAM.exe" /minimized

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{40C00742-B099-4F8C-AFB1-9A4E03011E04}C:\users\brewster\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\brewster\appdata\roaming\utorrent\utorrent.exe
    FirewallRules: [UDP Query User{6D47634B-DDAE-4A4E-82C5-BE5EE63369A7}C:\users\brewster\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\brewster\appdata\roaming\utorrent\utorrent.exe

    ==================== Faulty Device Manager Devices =============

    Name: ZAM Helper Driver
    Description: ZAM Helper Driver
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: ZAM
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.

    Name: ZAM Guard Driver
    Description: ZAM Guard Driver
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: ZAM_Guard
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (06/08/2015 11:14:20 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SuperAntiSpyware.exe, version: 6.0.0.1194, time stamp: 0x54f4c808
    Faulting module name: SuperAntiSpyware.exe, version: 6.0.0.1194, time stamp: 0x54f4c808
    Exception code: 0xc0000005
    Fault offset: 0x0006e06b
    Faulting process id: 0x7d0
    Faulting application start time: 0xSuperAntiSpyware.exe0
    Faulting application path: SuperAntiSpyware.exe1
    Faulting module path: SuperAntiSpyware.exe2
    Report Id: SuperAntiSpyware.exe3

    Error: (06/08/2015 11:04:17 AM) (Source: MsiInstaller) (EventID: 11326) (User: Brewster-Puter)
    Description: Product: Apple Application Support (32-bit) -- Error 1326. Error getting file security: C:\ProgramData\Apple\Apple Application Support\kdrl\ GetLastError: 5

    Error: (06/08/2015 11:03:37 AM) (Source: MsiInstaller) (EventID: 11704) (User: Brewster-Puter)
    Description: Product: Apple Application Support (32-bit) -- Error 1704. An installation for iTunes is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

    Error: (06/08/2015 10:54:51 AM) (Source: PerfNet) (EventID: 2004) (User: )
    Description:

    Error: (06/08/2015 10:47:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program PatchMyPC.exe version 3.0.2.5 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 6bc

    Start Time: 01d0a1ce1a0e7e2f

    Termination Time: 163

    Application Path: C:\Users\Brewster\Downloads\PatchMyPC.exe

    Report Id: 669c53b8-0dc3-11e5-b5dd-000c76847797

    Error: (06/08/2015 10:44:45 AM) (Source: MsiInstaller) (EventID: 11326) (User: Brewster-Puter)
    Description: Product: Apple Application Support (32-bit) -- Error 1326. Error getting file security: C:\ProgramData\Apple\Apple Application Support\kdrl\ GetLastError: 5

    Error: (06/08/2015 10:12:48 AM) (Source: PerfNet) (EventID: 2004) (User: )
    Description:

    Error: (06/07/2015 03:07:57 PM) (Source: PerfNet) (EventID: 2004) (User: )
    Description:

    Error: (06/06/2015 05:00:51 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: taskmgr.exe, version: 6.1.7601.17514, time stamp: 0x4ce78d21
    Faulting module name: ntdll.dll, version: 6.1.7601.18839, time stamp: 0x553e8801
    Exception code: 0x80000003
    Fault offset: 0x000639d6
    Faulting process id: 0x150c
    Faulting application start time: 0xtaskmgr.exe0
    Faulting application path: taskmgr.exe1
    Faulting module path: taskmgr.exe2
    Report Id: taskmgr.exe3

    Error: (06/06/2015 05:00:42 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: taskmgr.exe, version: 6.1.7601.17514, time stamp: 0x4ce78d21
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x003f1bb8
    Faulting process id: 0x150c
    Faulting application start time: 0xtaskmgr.exe0
    Faulting application path: taskmgr.exe1
    Faulting module path: taskmgr.exe2
    Report Id: taskmgr.exe3


    System errors:
    =============
    Error: (06/09/2015 01:47:53 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (06/09/2015 01:47:45 PM) (Source: NETLOGON) (EventID: 3095) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (06/09/2015 01:47:42 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\athExt.dll
    Error Code: 126

    Error: (06/08/2015 06:41:23 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
    Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

    Error: (06/08/2015 06:41:08 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (06/08/2015 06:40:59 PM) (Source: NETLOGON) (EventID: 3095) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.

    Error: (06/08/2015 06:40:57 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\athExt.dll
    Error Code: 126

    Error: (06/08/2015 06:40:37 PM) (Source: volsnap) (EventID: 25) (User: )
    Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

    Error: (06/08/2015 10:54:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D215781D-019E-4FA0-903D-0CDCDE13A4F5}{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

    Error: (06/08/2015 10:54:18 AM) (Source: NETLOGON) (EventID: 3095) (User: )
    Description: This computer is configured as a member of a workgroup, not as
    a member of a domain. The Netlogon service does not need to run in this
    configuration.


    Microsoft Office:
    =========================
    Error: (06/08/2015 11:14:20 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: SuperAntiSpyware.exe6.0.0.119454f4c808SuperAntiSpyware.exe6.0.0.119454f4c808c00000050006e06b7d001d0a1d3d3b0d83eC:\PatchMyPCUpdates\SuperAntiSpyware.exeC:\PatchMyPCUpdates\SuperAntiSpyware.exe1ffe7ff6-0dc7-11e5-8509-000c76847797

    Error: (06/08/2015 11:04:17 AM) (Source: MsiInstaller) (EventID: 11326) (User: Brewster-Puter)
    Description: Product: Apple Application Support (32-bit) -- Error 1326. Error getting file security: C:\ProgramData\Apple\Apple Application Support\kdrl\ GetLastError: 5(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (06/08/2015 11:03:37 AM) (Source: MsiInstaller) (EventID: 11704) (User: Brewster-Puter)
    Description: Product: Apple Application Support (32-bit) -- Error 1704. An installation for iTunes is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (06/08/2015 10:54:51 AM) (Source: PerfNet) (EventID: 2004) (User: )
    Description:

    Error: (06/08/2015 10:47:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: PatchMyPC.exe3.0.2.56bc01d0a1ce1a0e7e2f163C:\Users\Brewster\Downloads\PatchMyPC.exe669c53b8-0dc3-11e5-b5dd-000c76847797

    Error: (06/08/2015 10:44:45 AM) (Source: MsiInstaller) (EventID: 11326) (User: Brewster-Puter)
    Description: Product: Apple Application Support (32-bit) -- Error 1326. Error getting file security: C:\ProgramData\Apple\Apple Application Support\kdrl\ GetLastError: 5(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (06/08/2015 10:12:48 AM) (Source: PerfNet) (EventID: 2004) (User: )
    Description:

    Error: (06/07/2015 03:07:57 PM) (Source: PerfNet) (EventID: 2004) (User: )
    Description:

    Error: (06/06/2015 05:00:51 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: taskmgr.exe6.1.7601.175144ce78d21ntdll.dll6.1.7601.18839553e880180000003000639d6150c01d0a071dde1aa1bC:\Windows\System32\taskmgr.exeC:\Windows\SYSTEM32\ntdll.dll33df0597-0c65-11e5-8826-000c76847797

    Error: (06/06/2015 05:00:42 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: taskmgr.exe6.1.7601.175144ce78d21unknown0.0.0.000000000c0000005003f1bb8150c01d0a071dde1aa1bC:\Windows\System32\taskmgr.exeunknown2e6bf9a2-0c65-11e5-8826-000c76847797


    CodeIntegrity Errors:
    ===================================
    Date: 2015-06-08 11:30:52.952
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:52.654
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:52.291
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:51.898
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:51.601
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:51.317
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:51.004
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:50.589
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:50.154
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.

    Date: 2015-06-08 11:30:49.818
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Brewster\Downloads\ZemanaAntiMalware.exe because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz
    Percentage of memory in use: 49%
    Total physical RAM: 3327.55 MB
    Available physical RAM: 1668.05 MB
    Total Pagefile: 6651.36 MB
    Available Pagefile: 4644.41 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1917.32 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:149.04 GB) (Free:65.66 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    Drive f: () (Fixed) (Total:74.52 GB) (Free:36.41 GB) NTFS
    Drive h: () (Fixed) (Total:931.51 GB) (Free:310.28 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: D2A8D2A8)
    Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: E02AE02A)
    Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 57524F4B)
    Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

    ==================== End of log ============================
     
  4. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Download attached fixlist.txt file and save it to the Desktop.

    NOTE. It's important that both files, FRST/FRST64andfixlist.txt are in the same location or the fix will not work.

    NOTICE:This script was written specifically for this user,for use on that particular machine.Running this on another machine may cause damage to your operating system

    RunFRST/FRST64and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally.After that let the tool complete its run.When finished FRST will generate a log on the Desktop(Fixlog.txt).Please post it to your reply.
     

    Attached Files:

  5. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations!
    I think this is what you need............................
    Fix result of Farbar Recovery Scan Tool (x86) Version: 08-06-2015
    Ran by Brewster at 2015-06-10 11:21:57 Run:1
    Running from C:\Users\Brewster\Desktop
    Loaded Profiles: Brewster (Available Profiles: Brewster & Margies)
    Boot Mode: Normal

    ==============================================

    fixlist content:
    *****************
    Task: {7D267275-6939-47CA-80DA-79F3449009E0} - \Apple\AppleSoftwareUpdate No Task File <==== ATTENTION
    Task: {80680B1C-75B5-4D24-8FDE-E94BEA2A09C7} - System32\Tasks\Trojan Remover => C:\Program Files\Loaris\Trojan Remover\ltr.exe [2015-06-05] (Loaris Inc.)
    Task: {82E0EC63-16B7-4BAE-BBE3-810A4E84032A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess No Task File <==== ATTENTION
    Task: {AC344371-414A-4CD1-B7AF-E9FCB4CF5481} - \HP Photo Creations Messager No Task File <==== ATTENTION
    Task: {CD831DED-AA3F-4D5C-AF3C-E5B9CEDEDFD4} - \Adobe Acrobat Update Task No Task File <==== ATTENTION
    Task: {DA32B882-B8D1-4EC4-9B6C-06800563E02D} - \{76DA891A-32C0-4E0C-BEA3-4BF381112203} No Task File <==== ATTENTION
    Task: {264881F8-72AE-4A51-A464-C97CAAE52FB4} - \Adobe Flash Player Updater No Task File <==== ATTENTION
    Task: {27979A2A-8C5B-4F5D-B3DF-E1B1E6F1B8DC} - \HP Photo Creations Communicator No Task File <==== ATTENTION
    Task: {4E03FDC6-9452-47D4-A38A-C925C57067FE} - \HPCustParticipation HP Photosmart 5510 series No Task File <==== ATTENTION
    Task: {533DC729-ABB0-4EAD-B38B-EA6D251804B6} - \{9431D8AA-4251-4929-A61C-77D7F05763F7} No Task File <==== ATTENTION
    Task: {6315A5ED-A71A-4432-92B5-8C43DA68EE33} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig No Task File <==== ATTENTION
    *****************

    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D267275-6939-47CA-80DA-79F3449009E0}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D267275-6939-47CA-80DA-79F3449009E0}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple\AppleSoftwareUpdate" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{80680B1C-75B5-4D24-8FDE-E94BEA2A09C7}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80680B1C-75B5-4D24-8FDE-E94BEA2A09C7}" => key removed successfully.
    C:\Windows\System32\Tasks\Trojan Remover => moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Trojan Remover" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{82E0EC63-16B7-4BAE-BBE3-810A4E84032A}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82E0EC63-16B7-4BAE-BBE3-810A4E84032A}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC344371-414A-4CD1-B7AF-E9FCB4CF5481}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC344371-414A-4CD1-B7AF-E9FCB4CF5481}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP Photo Creations Messager" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CD831DED-AA3F-4D5C-AF3C-E5B9CEDEDFD4}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD831DED-AA3F-4D5C-AF3C-E5B9CEDEDFD4}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA32B882-B8D1-4EC4-9B6C-06800563E02D}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA32B882-B8D1-4EC4-9B6C-06800563E02D}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{76DA891A-32C0-4E0C-BEA3-4BF381112203}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{264881F8-72AE-4A51-A464-C97CAAE52FB4}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{264881F8-72AE-4A51-A464-C97CAAE52FB4}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27979A2A-8C5B-4F5D-B3DF-E1B1E6F1B8DC}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27979A2A-8C5B-4F5D-B3DF-E1B1E6F1B8DC}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP Photo Creations Communicator" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4E03FDC6-9452-47D4-A38A-C925C57067FE}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E03FDC6-9452-47D4-A38A-C925C57067FE}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPCustParticipation HP Photosmart 5510 series" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{533DC729-ABB0-4EAD-B38B-EA6D251804B6}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{533DC729-ABB0-4EAD-B38B-EA6D251804B6}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9431D8AA-4251-4929-A61C-77D7F05763F7}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6315A5ED-A71A-4432-92B5-8C43DA68EE33}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6315A5ED-A71A-4432-92B5-8C43DA68EE33}" => key removed successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully.

    ==== End of Fixlog 11:21:58 ====
     
  6. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    P.S. Greetings and Salutations!
    Thats got rid of the application error, but I'm still unable to upload unchecky - appararently there's an updated version on Reason Core Security, I've Uninstalled it, but still cannot load unchecky..................................................
     
  7. veeg

    veeg Live Long And Eat Bacon Moderator iHF Master Craftsman iHF Legend WCG Team Member

    Joined:
    May 7, 2014
    Messages:
    1,000
    Likes Received:
    382
    Trophy Points:
    93
    Yeah Reason Core Security comes bundled with unchecky,they bought the rights.
     
  8. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Maybe some parts of reason are still installed on your machine.....

    Download everything tool.
    http://www.voidtools.com/
    Type Reason into search window.
    Click Edit.
    Select All.
    Right Click, Copy full name to clipboard.
    Paste here in your next reply.
    Or you can maybe delete these items manually from with in the tool.
     
  9. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
    Another viable option is to re-install Core Security. Then disable the real time protection and scheduled scans, sine unchecky comes bundled with Reason....
    You would also have an extra on demand scanner that you could use whenever.
     
  10. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations!
    I hope this is right...................................
    H:\Books Calibre\Michael Kerr\01] A Reason to Kill (2956)
    H:\Books Calibre\Peter Robinson\05] Past Reason Hated (3732)
    H:\Books Calibre\Patrick O'brian\09] Treason's Harbour (4180)
    H:\Books Calibre\Matthew Iden\A Reason to Live (4135)
    H:\Books Calibre\Jack Coughlin\An Act of Treason (3358)
    H:\Books to be sorted\Clancy\Clancy, Tom\Call to Treason
    H:\Books Calibre\Tom Clancy\Call to Treason (845)
    H:\Books Calibre\Michael Kerr\01] A Reason to Kill (2956)\01] A Reason to Kill - Michael Kerr.mobi
    F:\My Music\Status Quo\Hello\03 Reason For Living.mp3
    F:\My Music\Status Quo\Status Quo - Aquostic (Stripped Bare) [Deluxe Version] 2014\05 - All The Reasons.mp3
    F:\My Music\Chris Rea\Wired to the Moon\05 Reasons.mp3
    H:\Books Calibre\Peter Robinson\05] Past Reason Hated (3732)\05] Past Reason Hated - Peter Robinson.mobi
    F:\My Music\Status Quo\Status Quo - Aquostic (Stripped Bare) [Deluxe Version] 2014\06 - Reason For Living.mp3
    F:\My Music\Status Quo\Piledriver\07 All The Reasons.mp3
    H:\Books Calibre\Patrick O'brian\09] Treason's Harbour (4180)\09] Treason's Harbour - Patrick O'Brian.mobi
    F:\My Music\Madness\Keep Moving\11 Give Me a Reason.mp3
    F:\Downloads\Little Goodies\Covers\1983 - Treason's Harbour.jpg
    H:\Books Calibre\Matthew Iden\A Reason to Live (4135)\A Reason to Live - Matthew Iden.azw3
    H:\Books Calibre\Jack Coughlin\An Act of Treason (3358)\An Act of Treason - Jack Coughlin.mobi
    H:\Books to be sorted\Clancy\Clancy, Tom\Call to Treason\Call to Treason - Tom Clancy.jpg
    H:\Books Calibre\Tom Clancy\Call to Treason (845)\Call to Treason - Tom Clancy.mobi
    H:\Books to be sorted\Clancy\Clancy, Tom\Call to Treason\Call to Treason - Tom Clancy.mobi
    H:\Books to be sorted\Clancy\Clancy, Tom\Call to Treason\Call to Treason - Tom Clancy.opf
    C:\Windows\System32\winevt\Logs\Reason.evtx
     
  11. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
  12. brewster393

    brewster393 Member iHF Regular

    Joined:
    May 14, 2014
    Messages:
    69
    Likes Received:
    7
    Trophy Points:
    18
    Greetings and Salutations!
    Hope a good weekend was had by all - tried that with reason core security, but unchecky still won't load.............................
     
  13. Malnutrition

    Malnutrition Still Hungry iHF Master Craftsman

    Joined:
    May 5, 2014
    Messages:
    1,501
    Likes Received:
    445
    Trophy Points:
    93
Loading...

Share This Page