Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Websites loading slowly-- possible infection?


  • Please log in to reply
35 replies to this topic

#1 bourgja2

bourgja2

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 03 June 2016 - 05:37 PM

Hello, I just recently upgraded to Mozilla Firefox 46.01, after resisting for quite some time by staying with 43.0.4.  Since then, my websites have been loading noticeably slower.  Sometimes even my typing or scrolling is delayed one or two seconds.

 

It is hard for me to tell if this is because of the new browser, or if my computer caught some type of infection around the same time, so I wanted to test for the latter if possible.  Thank you in advance for any help.  My operating system is Windows 7 Pro.



BC AdBot (Login to Remove)

 


#2 RolandJS

RolandJS

  • Members
  • 4,552 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Austin TX metro area
  • Local time:10:11 AM

Posted 03 June 2016 - 07:28 PM

I also have Windows 7 Pro.  What happened when you rolled back to version 43?  Did you regain your normal browsing operations?  [If you haven't tried the rollback, I'm suggesting trying it; I've rolled back many a Firefox versions over the years!  After some time has passed, after the plugins, extensions, addons are recognized by the newest version [at the particular time] -- then I let the upgrade stand.  Sometimes in the past, an upgrade slowed me way down!  So, I rolled back to a previous version.  Presently, I'm at FF 39.x; using Chrome 95% of the time since last year.


Edited by RolandJS, 03 June 2016 - 08:11 PM.

"Take care of thy backups and thy restores shall take care of thee."  -- Ben Franklin revisited.

http://collegecafe.fr.yuku.com/forums/45/Computer-Technologies/

Backup, backup, backup! -- Lady Fitzgerald (w7forums)

Clone or Image often! Backup... -- RockE (WSL)


#3 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 04 June 2016 - 08:08 AM

Dear Roland, yes I did try the rollback and it was still slow.  That was what made me wonder if I had a virus or malware...



#4 RolandJS

RolandJS

  • Members
  • 4,552 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Austin TX metro area
  • Local time:10:11 AM

Posted 04 June 2016 - 08:16 AM

Dear Roland, yes I did try the rollback and it was still slow.  That was what made me wonder if I had a virus or malware...

How does your Chrome or Internet Explorer work?  If suddenly just as slow as FF, then as the malware team weighs in, I get out [and listen in only].


"Take care of thy backups and thy restores shall take care of thee."  -- Ben Franklin revisited.

http://collegecafe.fr.yuku.com/forums/45/Computer-Technologies/

Backup, backup, backup! -- Lady Fitzgerald (w7forums)

Clone or Image often! Backup... -- RockE (WSL)


#5 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 04 June 2016 - 09:11 AM

I don't use IE anymore, but I would say that Chrome is loading slower than usual as well.



#6 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 June 2016 - 04:19 PM

P.S.-- Here is a strange thing.  Today I was unable to open any PDF files, and discovered that my Adobe program file folder had been moved into my Anvsoft program folder.  I didn't do this and it is very worrisome.

 

P.P.S.-- Still waiting for malware team.  No need for others to respond.


Edited by bourgja2, 06 June 2016 - 04:20 PM.


#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:11 AM

Posted 09 June 2016 - 12:20 PM

Please run these scans

3Al62Pm.pngMiniToolBox
  • Please download MiniToolBox, save it to your desktop and run it.
  • Checkmark the following checkboxes:
    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List content of Hosts
    • List IP configuration
    • List Winsock Entries
    • List last 10 Event Viewer log
    • List Installed Programs
    • List Users, Partitions and Memory size.
  • Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
zcMPezJ.pngAdwCleaner
  • Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
lv0mVRW.pngJunkware Removal Tool
  • Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
cvMlKv6.pngESET Online Scanner
  • Click here to download the installer for ESET Online Scanner and save it to your Desktop.
  • Disable all your antivirus and antimalware software - see how to do that here.
  • Right click on esetsmartinstaller_enu.exe and select Run as Administrator.
  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.
>>>

51a46ae42d560-malwarebytes_anti_malware.Malwarebytes Anti-Malware
  • Download MalwareBytes Anti-Malware to your desktop.
  • Double-click mbam-setup-2.0.exe to start the installation of Malwarebytes Anti-Malware.
  • Follow the instructions on your screen to complete the installation. You can find the complete installation procedure here.
  • Click the Scan Now button, a threat scan will start automatically.
  • MalwareBytes Anti-Malware will now check for the latest updates. Click Update Now if new updates are available.
  • Your computer is now being scanned, please do not use your computer during the scan.
    • If no threats were found, click View detailed log.
      • Click Export and save the log as a .txt file on your Desktop or another location.
    • If the scan detected any threats, click Apply Actions.
      • To complete any actions taken you will be prompted to restart your computer...click on Yes.
      • After reboot, start Malwarebytes Anti-Malware again and click the History Tab at the top and select Application Logs.
      • Check the box next to Scan Log. Choose the most current scan and click View.
      • Click Export and save the log as a .txt file on your Desktop or another location.
  • Providing the MalwareBytes' Anti-Malware log file
    • Attach the log file you just saved to your next reply for further review.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 09 June 2016 - 04:07 PM

Okay, I am going to post these logs individually in the order that they were run.  Here is the MiniToolBox result (I have removed references to my name and added xxxxxxxxxxxxxxxxx instead):

 

MiniToolBox by Farbar  Version: 07-02-2016 01
Ran by  xxxxxxxxxxxxxxxxx (administrator) on 09-06-2016 at 17:00:28
Running from "C:\Users\xxxxxx\Documents\Downloaded program setups"
Microsoft Windows 7 Professional  Service Pack 1 (X64)
Model: HP Compaq Pro 6305 SFF Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================
========================= IP Configuration: ================================

Broadcom NetXtreme Gigabit Ethernet Plus = Local Area Connection (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

   Host Name . . . . . . . . . . . . : xxxxxxxxxxxxxxx
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : Belkin

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . : Belkin
   Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet Plus
   Physical Address. . . . . . . . . : F0-92-1C-F6-3D-42
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::b16b:5b99:97e4:e171%13(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.2.2(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Thursday, June 09, 2016 4:55:44 PM
   Lease Expires . . . . . . . . . . : Sunday, July 16, 2152 11:28:50 PM
   Default Gateway . . . . . . . . . : fe80::201:5cff:fe68:e246%13
                                       192.168.2.1
   DHCP Server . . . . . . . . . . . : 192.168.2.1
   DHCPv6 IAID . . . . . . . . . . . : 284201500
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1A-98-19-86-F0-92-1C-F6-3D-42
   DNS Servers . . . . . . . . . . . : 192.168.2.1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.Belkin:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 12:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft Teredo Tunneling Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  UnKnown
Address:  192.168.2.1

Name:    google.com
Addresses:  2607:f8b0:4009:808::200e
      216.58.216.206


Pinging google.com [172.217.4.110] with 32 bytes of data:
Request timed out.
Request timed out.

Ping statistics for 172.217.4.110:
    Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
Server:  UnKnown
Address:  192.168.2.1

Name:    yahoo.com
Addresses:  2001:4998:c:a06::2:4008
      2001:4998:58:c02::a9
      2001:4998:44:204::a7
      206.190.36.45
      98.139.183.24
      98.138.253.109


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=40ms TTL=45
Reply from 98.139.183.24: bytes=32 time=40ms TTL=45

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 40ms, Maximum = 40ms, Average = 40ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 13...f0 92 1c f6 3d 42 ......Broadcom NetXtreme Gigabit Ethernet Plus
  1...........................Software Loopback Interface 1
 14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 11...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 12...00 00 00 00 00 00 00 e0 Microsoft Teredo Tunneling Adapter
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.2.1      192.168.2.2     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.2.0    255.255.255.0         On-link       192.168.2.2    276
      192.168.2.2  255.255.255.255         On-link       192.168.2.2    276
    192.168.2.255  255.255.255.255         On-link       192.168.2.2    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.2.2    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.2.2    276
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 13    276 ::/0                     fe80::201:5cff:fe68:e246
  1    306 ::1/128                  On-link
 13    276 fe80::/64                On-link
 13    276 fe80::b16b:5b99:97e4:e171/128
                                    On-link
  1    306 ff00::/8                 On-link
 13    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/06/2016 05:25:00 PM) (Source: MsiInstaller) (User: xxxxxxxxxxxxxxxxxxxxxxxxxxxx)
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium.  The Windows installer cannot continue.

Error: (06/04/2016 03:43:52 PM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.4.19, time stamp: 0x540141f8
Faulting module name: MSVCR100.dll, version: 10.0.40219.325, time stamp: 0x4df2be1e
Exception code: 0xc0000005
Fault offset: 0x000101d0
Faulting process id: 0x89c
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3

Error: (05/28/2016 09:11:51 PM) (Source: Application Hang) (User: )
Description: The program esetonlinescanner_enu.exe version 2.0.8.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: fc8

Start Time: 01d1b93af0470261

Termination Time: 47

Application Path: C:\Users\xxxxxxxxxxxxxxxxxx\Downloads\esetonlinescanner_enu.exe

Report Id:

Error: (05/28/2016 07:43:46 PM) (Source: Application Error) (User: )
Description: Faulting application name: esetonlinescanner_enu.exe, version: 2.0.8.0, time stamp: 0x573dab40
Faulting module name: esetonlinescanner_enu.exe, version: 2.0.8.0, time stamp: 0x573dab40
Exception code: 0xc0000005
Fault offset: 0x001b6453
Faulting process id: 0x9ac
Faulting application start time: 0xesetonlinescanner_enu.exe0
Faulting application path: esetonlinescanner_enu.exe1
Faulting module path: esetonlinescanner_enu.exe2
Report Id: esetonlinescanner_enu.exe3

Error: (05/27/2016 10:08:43 PM) (Source: Application Hang) (User: )
Description: The program firefox.exe version 43.0.4.5848 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: e04

Start Time: 01d1b8828bdefd81

Termination Time: 46

Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Report Id:

Error: (05/22/2016 08:04:34 PM) (Source: Application Error) (User: )
Description: Faulting application name: rndlresolversvc.exe, version: 0.0.0.0, time stamp: 0x53ea5e45
Faulting module name: rndlresolversvc.exe, version: 0.0.0.0, time stamp: 0x53ea5e45
Exception code: 0xc0000005
Fault offset: 0x00003063
Faulting process id: 0x9c8
Faulting application start time: 0xrndlresolversvc.exe0
Faulting application path: rndlresolversvc.exe1
Faulting module path: rndlresolversvc.exe2
Report Id: rndlresolversvc.exe3

Error: (05/20/2016 07:38:26 AM) (Source: Application Error) (User: )
Description: Faulting application name: OUTLOOK.EXE, version: 14.0.4760.1000, time stamp: 0x4ba8fefd
Faulting module name: OUTLOOK.EXE, version: 14.0.4760.1000, time stamp: 0x4ba8fefd
Exception code: 0xc0000005
Fault offset: 0x000b2b4d
Faulting process id: 0x14c8
Faulting application start time: 0xOUTLOOK.EXE0
Faulting application path: OUTLOOK.EXE1
Faulting module path: OUTLOOK.EXE2
Report Id: OUTLOOK.EXE3

Error: (05/18/2016 07:02:14 PM) (Source: Application Hang) (User: )
Description: The program firefox.exe version 43.0.4.5848 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 824

Start Time: 01d1b159037e44a1

Termination Time: 80

Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Report Id: 88ffd592-1d4c-11e6-a5ae-f0921cf63d42

Error: (05/09/2016 08:26:18 PM) (Source: Application Hang) (User: )
Description: The program autoreg.exe version 4.20.201.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1634

Start Time: 01d1aa522297a66b

Termination Time: 16

Application Path: C:\Program Files (x86)\RFViewer\Support Files\autoreg.exe

Report Id: 9a55a2cf-1645-11e6-a3b2-f0921cf63d42

Error: (05/09/2016 08:17:28 PM) (Source: Application Hang) (User: )
Description: The program autoreg.exe version 4.20.201.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 10b4

Start Time: 01d1aa513071102d

Termination Time: 0

Application Path: C:\Program Files (x86)\RFViewer\Support Files\autoreg.exe

Report Id: 771b6db5-1644-11e6-a3b2-f0921cf63d42


System errors:
=============
Error: (06/09/2016 04:56:11 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%835

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: %%842

Error: (06/08/2016 09:47:52 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.223.810.0

    Update Source: %NT AUTHORITY59

    Update Stage: 3.0.8402.00

    Source Path: 3.0.8402.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (06/08/2016 09:30:46 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%835

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: %%842

Error: (06/08/2016 05:54:21 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.223.810.0

    Update Source: %NT AUTHORITY59

    Update Stage: 3.0.8402.00

    Source Path: 3.0.8402.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (06/08/2016 05:18:53 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%835

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: %%842

Error: (06/07/2016 05:03:49 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%835

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: %%842

Error: (06/06/2016 10:52:50 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.223.810.0

    Update Source: %NT AUTHORITY59

    Update Stage: 3.0.8402.00

    Source Path: 3.0.8402.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (06/06/2016 10:23:03 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%835

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: %%842

Error: (06/06/2016 07:40:07 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%835

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: %%842

Error: (06/06/2016 06:21:49 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.223.810.0

    Update Source: %NT AUTHORITY59

    Update Stage: 3.0.8402.00

    Source Path: 3.0.8402.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608


Microsoft Office Sessions:
=========================
Error: (06/06/2016 05:25:00 PM) (Source: MsiInstaller)(User: xxxxxxxxxxxxxxx)
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium.  The Windows installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (06/04/2016 03:43:52 PM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.4.19540141f8MSVCR100.dll10.0.40219.3254df2be1ec0000005000101d089c01d1be983cec9f62C:\Program Files (x86)\Real\RealPlayer\RealPlay.exeC:\Windows\system32\MSVCR100.dlla9a94efa-2a8c-11e6-840c-f0921cf63d42

Error: (05/28/2016 09:11:51 PM) (Source: Application Hang)(User: )
Description: esetonlinescanner_enu.exe2.0.8.0fc801d1b93af047026147C:\Users\xxxxxxxxxxxxxxxxx\Downloads\esetonlinescanner_enu.exe

Error: (05/28/2016 07:43:46 PM) (Source: Application Error)(User: )
Description: esetonlinescanner_enu.exe2.0.8.0573dab40esetonlinescanner_enu.exe2.0.8.0573dab40c0000005001b64539ac01d1b91c1b1d578cC:\Users\xxxxxxxxxxxxxxxxxxxxxxxxxxx\Downloads\esetonlinescanner_enu.exeC:\Users\xxxxxxxxxxxxxxx\Downloads\esetonlinescanner_enu.exe048f8599-252e-11e6-b22b-f0921cf63d42

Error: (05/27/2016 10:08:43 PM) (Source: Application Hang)(User: )
Description: firefox.exe43.0.4.5848e0401d1b8828bdefd8146C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Error: (05/22/2016 08:04:34 PM) (Source: Application Error)(User: )
Description: rndlresolversvc.exe0.0.0.053ea5e45rndlresolversvc.exe0.0.0.053ea5e45c0000005000030639c801d1b486a1d00300C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exeC:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exeee15be4c-2079-11e6-8873-f0921cf63d42

Error: (05/20/2016 07:38:26 AM) (Source: Application Error)(User: )
Description: OUTLOOK.EXE14.0.4760.10004ba8fefdOUTLOOK.EXE14.0.4760.10004ba8fefdc0000005000b2b4d14c801d1b28c1ec8c580C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXEC:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE5d5a9344-1e7f-11e6-a1f4-f0921cf63d42

Error: (05/18/2016 07:02:14 PM) (Source: Application Hang)(User: )
Description: firefox.exe43.0.4.584882401d1b159037e44a180C:\Program Files (x86)\Mozilla Firefox\firefox.exe88ffd592-1d4c-11e6-a5ae-f0921cf63d42

Error: (05/09/2016 08:26:18 PM) (Source: Application Hang)(User: )
Description: autoreg.exe4.20.201.0163401d1aa522297a66b16C:\Program Files (x86)\RFViewer\Support Files\autoreg.exe9a55a2cf-1645-11e6-a3b2-f0921cf63d42

Error: (05/09/2016 08:17:28 PM) (Source: Application Hang)(User: )
Description: autoreg.exe4.20.201.010b401d1aa513071102d0C:\Program Files (x86)\RFViewer\Support Files\autoreg.exe771b6db5-1644-11e6-a3b2-f0921cf63d42


CodeIntegrity Errors:
===================================
  Date: 2016-06-04 15:52:23.458
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.413
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOFeedb.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.369
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.311
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.234
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOFeedb.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.190
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.146
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.105
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOFeedb.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.058
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-04 15:52:23.018
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\ATI Technologies\HydraVision\HydraDMH64.dll because the set of per-page image hashes could not be found on the system.


=========================== Installed Programs ============================

Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Reader 9.4.0 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A94000000001}) (Version: 9.4.0 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{7F37CED5-7504-BC2B-600D-BFB4861271FE}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.4.2 - AppEx Networks)
Any Video Converter 5.8.8 (HKLM-x32\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
Broadcom NetXtreme-I Netlink Driver and Management Installer (HKLM\...\{916302F3-4586-40B0-BAE6-06C1347DBCB6}) (Version: 16.2.3.1 - Broadcom Corporation)
BufferChm (HKLM-x32\...\{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}) (Version: 130.0.327.000 - Hewlett-Packard) Hidden
Canon G.726 WMP-Decoder (HKLM-x32\...\Canon G.726 WMP-Decoder) (Version: 1.1.0.4 - Canon Inc.)
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 2.6.0.4 - Canon Inc.)
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\RAW Image Task) (Version: 0.9.3.9 - Canon Inc.)
Canon Utilities CameraWindow (HKLM-x32\...\CameraWindowLauncher) (Version: 7.1.0.2 - Canon Inc.)
Canon Utilities CameraWindow DC (HKLM-x32\...\CameraWindowDC) (Version: 7.1.0.7 - Canon Inc.)
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\...\CameraWindowDVC6) (Version: 6.4.2.16 - Canon Inc.)
Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 6.4.0.5 - Canon Inc.)
Canon Utilities MyCamera DC (HKLM-x32\...\MyCameraDC) (Version: 7.0.1.8 - Canon Inc.)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.7.1.9 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.1.0.20 - Canon Inc.)
Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\...\ZoomBrowser EX Memory Card Utility) (Version: 1.1.0.8 - Canon Inc.)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.3.3207 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (HKLM-x32\...\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DirectX for Managed Code Update (Summer 2004) (HKLM-x32\...\{E9E34215-82EF-4909-BE2F-F581F0DC9062}) (Version: 9.02.2904 - Microsoft) Hidden
DocProc (HKLM-x32\...\{9B362566-EC1B-4700-BB9C-EC661BDE2175}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.84 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.30.3 - Google Inc.) Hidden
GPBaseService2 (HKLM-x32\...\{63FF21C9-A810-464F-B60A-3111747B1A6D}) (Version: 130.0.367.000 - Hewlett-Packard) Hidden
Hewlett-Packard ACLM.NET v1.2.1.1 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 8.3.2.1744 - Hewlett-Packard Company)
HP Device Access Manager (HKLM\...\{DBE16A07-DDFF-4453-807A-212EF93916E0}) (Version: 8.3.2.0 - Hewlett-Packard Company)
HP File Sanitizer (HKLM-x32\...\{547607B0-3294-4ECA-8F5E-921404676CBB}) (Version: 8.4.13.1 - Hewlett-Packard Company)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Scanjet G3010 (HKLM\...\{3B3FA519-42F3-4534-B867-960481329CFC}) (Version: 13.0 - HP)
HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{49524B48-4FE9-4A62-A9FD-1F2258DF5489}) (Version: 3.4.12.0 - Hewlett-Packard Company)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP Theft Recovery (HKLM-x32\...\InstallShield_{BAC712C6-4061-4C9F-AB58-A5C53E76704A}) (Version: 8.3.0.5 - Hewlett-Packard Company)
HP Trust Circles (HKLM-x32\...\HP Trust Circles) (Version: 8.3.6.16976 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
hpg3010 (HKLM-x32\...\{11B47315-4D03-4684-AA7F-E962524C738E}) (Version: 14.0.0.0 - Hewlett-Packard) Hidden
HPProductAssistant (HKLM-x32\...\{C43326F5-F135-4551-8270-7F7ABA0462E1}) (Version: 130.0.367.000 - Hewlett-Packard) Hidden
HydraVision (HKLM-x32\...\{57136865-1C96-2131-3E17-3B7F6F95A568}) (Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Logitech MouseWare 9.42 .1 (HKLM-x32\...\{5809E7CF-4DCF-11D4-9875-00105ACE7734}) (Version:  - )
Logitech User's Guide (HKLM-x32\...\{CBE0FCA1-4E95-11D4-9875-00105ACE7734}) (Version:  - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2000 Premium (HKLM-x32\...\{00000409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Outlook Personal Folders Backup (HKLM-x32\...\{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}) (Version: 1.10.0.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 2.1.1116.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
opensource (HKLM-x32\...\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}) (Version: 1.0.14960.3876 - Your Company Name) Hidden
Personal Ancestral File (HKLM-x32\...\{09DE2F51-DF0A-11D3-9DBC-00C04F522588}) (Version:  - )
Phenotype Predictor for Cats 2 (HKLM-x32\...\Phenotype Predictor for Cats 2_is1) (Version: 2.03 - Tenset Technologies Ltd)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.140.248 - Google, Inc.)
PX Profile Update (HKLM-x32\...\{958DF817-8C06-5899-18D1-CDDA920A8B6F}) (Version: 1.00.1. - AMD) Hidden
RealDownloader (HKLM-x32\...\{6935C750-2D8C-4705-B4F9-052F550D225D}) (Version: 1.3.4 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.4 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.6704 - CyberLink Corp.) Hidden
Scan (HKLM-x32\...\{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
SolutionCenter (HKLM-x32\...\{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}) (Version: 130.0.369.000 - Hewlett-Packard) Hidden
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (HKLM-x32\...\{43CDF946-F5D9-4292-B006-BA0D92013021}) (Version: 130.0.128.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinZip (HKLM-x32\...\WinZip) (Version:  - )

========================= Memory info: ===================================

Percentage of memory in use: 59%
Total physical RAM: 3278.24 MB
Available physical RAM: 1315.65 MB
Total Virtual: 6554.68 MB
Available Virtual: 4660.66 MB

========================= Partitions: =====================================

1 Drive c: (OS) (Fixed) (Total:455.4 GB) (Free:368.24 GB) NTFS
2 Drive d: (HP_RECOVERY) (Fixed) (Total:10.16 GB) (Free:1.13 GB) NTFS
3 Drive e: (HP_TOOLS) (Fixed) (Total:0.09 GB) (Free:0.08 GB) FAT32

========================= Users: ========================================

User accounts for \\xxxxxxxxxxxxxxxxx

Administrator            Guest                    xxxxxxxxxxxxxxxxxxxxxxxxxxx        


**** End of log ****
 


Edited by bourgja2, 09 June 2016 - 04:09 PM.


#9 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 09 June 2016 - 04:14 PM

Here is the ADWCleaner report, again with my name xed out.

 

# AdwCleaner v5.119 - Logfile created 09/06/2016 at 17:11:18
# Updated 30/05/2016 by Xplode
# Database : 2016-06-07.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (X64)
# Username : xxxxxxxxxxxxxxxxxxxxxxx
# Running from : C:\Users\xxxxxxxxxxxxxx\Documents\Downloaded program setups\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLL ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\APN PIP
Key Found : HKU\S-1-5-21-1245932372-2556522807-345712701-1003\Software\APN PIP

***** [ Web browsers ] *****

[C:\Users\xxxxxxxxxxxxxx\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\xxxxxxxxxxxxxxxx\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [1599 bytes] - [28/05/2016 15:58:22]
C:\AdwCleaner\AdwCleaner[S2].txt - [1546 bytes] - [09/06/2016 17:11:18]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1619 bytes] ##########
 



#10 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 09 June 2016 - 04:21 PM

Here is the junkware log, with my name xxxed out:

 

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 7 Professional x64
Ran by xxxxxxxxxxxxxxxxxxxx (Administrator) on Thu 06/09/2016 at 17:16:40.36
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 33

Successfully deleted: C:\Program Files (x86)\GUT3294.tmp (File)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0ZUVMC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2FP1XCSQ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PBBUB4U (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B48MMZG3 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D4K2V67R (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I7V0I07H (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PFSK200L (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R3A7KLD6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RXLH037R (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T89P74V3 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W4RNQ9YX (Temporary Internet Files Folder)
Successfully deleted: C:\Users\xxxxxxxxxxxxxxxxxxxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XFYMACZN (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0ZUVMC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2FP1XCSQ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PBBUB4U (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B48MMZG3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D4K2V67R (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I7V0I07H (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PFSK200L (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R3A7KLD6 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RXLH037R (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T89P74V3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W4RNQ9YX (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XFYMACZN (Temporary Internet Files Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 06/09/2016 at 17:19:48.95
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#11 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 09 June 2016 - 05:30 PM

I have run ESET Online a few times recently before posting on this forum, and it has stopped running and frozen.  The same happened again while I tried it tonight.



#12 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 09 June 2016 - 08:07 PM

Finally here is my Malwarebytes log:

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/9/2016
Scan Time: 6:33 PM
Logfile: malwarebytes.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.06.09.06
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: xxxxxxxxxxxxx

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 300308
Time Elapsed: 12 min, 55 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)



#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:11 AM

Posted 10 June 2016 - 09:01 AM

Ok remove what ADW found
Please download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • The tool will start to update its database...please wait until complete.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a report (AdwCleaner[SX].txt) will open in Notepad (where the largest value of X represents the most recent report).
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[CX].txt) will open automatically (where the largest value of X represents the most recent report).
  • Copy and paste the contents of AdwCleaner[CX].txt in your next reply.
  • A copy of all logfiles are saved to C:\AdwCleaner.
Remove ESET as I see errors in your log.

Manual Uninstall: Run the ESET Online Scanner Uninstaller (filename: OnlineScannerUninstaller.exe) program, located in the C:/WINDOWS/SYSTEM32 directory on computers running 32-bit (x86) editions of Microsoft Windows and in the C:/WINDOWS/SYSWOW64 directory on computers running 64-bit (x64) editions of Microsoft Windows.

Now try it again
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#14 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 10 June 2016 - 12:34 PM

# AdwCleaner v5.119 - Logfile created 10/06/2016 at 13:31:09
# Updated 30/05/2016 by Xplode
# Database : 2016-06-07.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (X64)
# Username : xxxxxxxxxxxxxxxxxxxxx -
# Running from : C:\Users\xxxxxxxxxxxxxxxxxxxxx\Documents\Downloaded program setups\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key Deleted : HKCU\Software\APN PIP

***** [ Web browsers ] *****

[-] [C:\Users\xxxxxxxxxxxxxxxxxxxxx\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\xxxxxxxxxxxxxxxxxxxxx\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1524 bytes] - [10/06/2016 13:31:09]
C:\AdwCleaner\AdwCleaner[S1].txt - [1599 bytes] - [28/05/2016 15:58:22]
C:\AdwCleaner\AdwCleaner[S2].txt - [1698 bytes] - [09/06/2016 17:11:18]
C:\AdwCleaner\AdwCleaner[S3].txt - [1771 bytes] - [10/06/2016 13:29:13]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1816 bytes] ##########
 



#15 bourgja2

bourgja2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 10 June 2016 - 01:51 PM

ESET Online found no threats.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users