LandzDown Forum

Software & More => Internet => Topic started by: LindaEllis on December 23, 2015, 01:54:27 AM

Title: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 23, 2015, 01:54:27 AM
Hi.  I am using now a Windows 7 Dell Desk top computer, it is a 64 bit computer.  I had been using Windows XP for a long time before this.  I downloaded Firefox to my Windows 7 computer and was horrified that with every website I tried to access I kept getting a pop up message telling me that it is an untrusted website.  I was not able to use Firefox at all.  Please know that I am not a computer 'geek' and can only go so far to understand complex steps and instructions to 'fix' this.  Thank you.  I attached a screen print.
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 23, 2015, 02:49:31 AM
Hi, Linda.

It certainly would be strange that Firefox would find its own site untrusted.  I am wondering if the problem is due to the update 43.0.1 which was apparently released to "Prepare to use SHA-256 signing certificate for Windows builds, to meet new Microsoft signing requirement (1079858)".  Then, today, 43.0.2 was released to actually "Use a SHA-256 signing certificate for Windows builds, to meet new signing requirements".

Try updating Firefox to the latest version and see if that allows you to access the site.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 23, 2015, 03:00:52 AM
Hi Corrine,

I would have to reinstall Firefox as I uninstalled it.  I'll try to do that.  I don't really understand all of the 'nuts and bolts' of what you wrote about the SHA-256, but I'll try to install again.  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 23, 2015, 03:10:47 AM
It has to do with security -- and it is related specifically to security certificates, although it hasn't gone into effect yet.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 23, 2015, 04:07:57 AM
Hi again, well I installed the 64 bit version of Firefox on my computer this evening and though I had some hope when I got into Ebay and Find A Grave, however, it would not let me in at all into blogger.  I have a blog in blogger.  So, the untrusted site problem continues.  With no option to do any work around to access blogger. 

Any suggestions would be greatly appreciated. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 23, 2015, 09:01:06 PM
When I installed the 64 bit version, I found that some sites would not work with it and actually displayed a message that they didn't work the the 64 bit version of Firefox. If that isn't the issue here, have you installed any add-ons?  What firewall or other security software are you using that could it be blocking Firefox?

Do you have the same problem with other browsers?  How about Pale Moon?  http://www.palemoon.org/  It has its own ad-blocking software, other extensions (https://addons.palemoon.org/extensions/all-extensions/) and many of the Firefox extensions work with it as welol.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 23, 2015, 09:10:55 PM
Hi.  No, I do not see any other messages other than what you see on the image I shared here.  I don't know what kind of 'add-ons' you would be talking about.  I only have had the computer since December 4.  It came as a refurbished computer to me when I bought it.  I use ESETNOD32 and Malwarebytes and Winpatrol of course; the same programs I had been using for years on my Windows XP computer and I did not encounter these problems with Firefox; only now and after their update and on this Windows 7 64 bit computer. 

I have IE11 and also Chrome for browsers. 

With IE11 and Chrome, however, I have issues with a website I use quite a lot, familysearch.org, and I am not able to view document images on them, so I tried Firefox and I cannot bring Familysearch up in Firefox at all now. 

I do not have PaleMoon browser and no experience with it. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 24, 2015, 01:02:29 AM
Since I've switched to Pale Moon as my primary browser, I went ahead and updated Firefox to version 43.0.1 and had no problems going to https://familysearch.org/ or https://www.blogger.com.

On the few occasions where the Untrusted message has popped up, as long as I had no doubt the site was safe, I use the steps under "Bypassing the warning" at "This Connection is Untrusted" error message appears - What to do | Firefox Help (https://support.mozilla.org/en-US/kb/connection-untrusted-error-message?redirectlocale=en-US&redirectslug=This+connection+is+untrusted).
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 01:19:06 AM
I just looked and my Firefox is 43.0.2, so you are saying I should also install Pale Moon, make it my primary browser and then I have a chance I can get into these websites because you had no problems at all accessing them?  You did not get any warnings at all when trying to access those sites in Firefox? 

I found those steps, but still feel by reading all that I have that even though I feel I should not be having any doubt, but yet there still could be an underlying reason that I don't know about that keeps causing this problem for me:

"Bypassing the warning

You should only bypass the warning if you're confident in both the identity of the website and the integrity of your connection - even if you trust the site, someone could be tampering with your connection. Legitimate public sites will not ask you to add connection rule exceptions - an invalid certificate can be an indication of a web page that will defraud you or steal your identity."

I just can't ignore a warning that explicit!
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 01:54:39 AM
Can you see this image: 

https://familysearch.org/search/record/results?count=20&query=%2Bsurname%3ALimes%20%2Bresidence_place%3AOhio%20%2Bresidence_year%3A1940-1940~&offset=100

I am not able to view it.  Thank you.
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 24, 2015, 02:51:09 AM
Yes, with Pale Moon, Firefox and IE11 on Windows 7.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 03:36:18 AM
Thank you Corrine, for all of your replies and time.  This is so frustrating as I put off getting Windows 7 for so long and now it is so disappointing and frustrating! 

In Firefox, I went ahead with the familysearch.org and added it in that pop up box that comes up where you can add it. 

"Bypassing the warning"

"You should only bypass the warning if you're confident in both the identity of the website and the integrity of your connection - even if you trust the site, someone could be tampering with your connection. Legitimate public sites will not ask you to add connection rule exceptions - an invalid certificate can be an indication of a web page that will defraud you or steal your identity.

On the warning page, click I Understand the Risks.
Click Add Exception.... The Add Security Exception dialog will appear.
Read the text describing the problems with this site.
Click Confirm Security Exception if you want to trust the site."

I took the steps and added it.

However, that still didn't work as another goofy looking screen came up, and so I screen printed that and I am attaching it here. 

I did download from Firefox to install it back on my computer their 64 bit download link that I saw on their website, was that the right thing to do? 
~~~~~~~~~~~~~~~~~~~~~~~~
Regarding my not seeing the .jpg images when in familysearch in either IE11 or Chrome:

I don't know what else to do with the familysearch.org documents since you are able to see them in all of your browsers; and I am still not able to see them in Chrome or IE11 (and of course can't even use Familysearch in Firefox). 

I will have to call Familysearch again as I have a ticket number, but as you might remember from my Winpatrol post, one of their tech people told me to install Java; she thought Java was the reason I could not see the photos.  I installed and still could not see the photos.  I even used a teamviewer with her; I got kicked up their tech chain to two other people who couldn't help either, and so I don't know if anyone at Familysearch can figure out why I cannot view their .jpg document images.  I mean I could still view them in Windows XP!  Per your recommendations, I did uninstall Java.

I think I am getting all out of ideas with these two problems, but I appreciate so much your patience with me here.  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 24, 2015, 03:42:46 AM
As I mentioned previously, some sites do not work with the 64-bit version.  If you are using the 64-bit version of Firefox, that is the problem.  You need to uninstall it and install the standard 32-bit version:  https://www.mozilla.org/en-US/firefox/new/
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 03:58:52 AM
Hi Corrine.  Okay, I'll do that.  I am not sure but the other two times I had Firefox, but to be honest I do not know what versions they were and I had the same problems.  Thank you for the proper link.  That helps to have that. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 04:31:17 AM
Okay, I uninstalled the 64 bit and the installed the 32 bit from the link you provided, Corrine, however, with familysearch.org, I got that goofy looking page; (not the one that has the untrusted warning).  I attached it again here. 

So, I guess Firefox on my machine for 32 or 64 bit does not like familysearch, nor my blog and blogger.  There could be more of course. 

Both 32 and 64 bit did open Facebook, Ebay, and Find A Grave, and Wordpress and my Wordpress blog.  Those were the only sites I tested on Firefox.

So, I welcome any other recommendations!  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: JDBush61 on December 24, 2015, 04:49:21 AM
Hi Linda,

Not sure if this will help you, or not, yet I checked Family Search as follows:

Browser 1) PaleMoon 25.8.1 (x86 en-US)
Browser 2) Mozilla Firefox 43.0.2 (x86 en-US)


Both browsers brought me to the official page (please see the attached photo).

My set-up: Windows 7 64 bit. Not sure if my browsers are 32 or 64 bit. Corrine will probably know.

Hope you get things worked out, and Happy Holidays.

John
Title: Re: Firefox Problems - Untrusted Websites
Post by: satrow on December 24, 2015, 10:37:30 AM
It looks like 'something' is running interference on your PC, Linda. The familysearch.org site is not correctly detecting/sniffing your browser and version, which appears to be fine for me using both Firefox and Pale Moon x64 versions.

What Extensions are installed ((Alt) > Tools > Add-ons > Extensions) in Firefox?

Is Page Style set to Basic ((Alt) > View > Page Style) not No Style?

What security/privacy software do you have installed and are they all set to their defaults?

I don't recall the last time a website suggested that I should switch to an x86 browser, if at all! The main problem with x64 browsers is that many 3rd party plugins are only written in an x86 version (current x64 browser market share is presumably too small for them to spend time/resources creating/testing x64 versions) - this would apply to a relatively small % of sites that rely on those plugins.

You do download your software from the makers site, not from some results from searching for them?

Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 02:13:58 PM
Wow, a lot to respond to here.  As far as software, the person who set up my refurbished computer put in Office 2007 by making a phone call and he put it on that way.  I had Office 2007 before that on my Windows XP and he set that up too and I was able to use Firefox on Windows XP, but not the most recent version since I changed compters to Windows 7 on Dec. 4.  I cannot find any add ons at all listed for Firefox.  I don't know about style.  I just installed Firefox and made no changes to it, so whatever its default is would be there.  I have ESETNOD32, malwarebytes and winpatrol.   I didn't change any settings so I assume they are at their defaults. With Firefox, I can bring up some websites that I use like Ebay, facebook, Wordpress Blog that I have, Find A Grave, but I cannot bring up my Blogger Blog or blogger or Familysearch.org at all in Firefox now. 

In IE11 and Chrome I can bring up familysearch but cannot view the documents that are there to view.  In IE11 and Chrome, I can bring up and use my blogger blog okay. 

So, I have problems with all of these browsers one way or another. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: JDBush61 on December 24, 2015, 03:12:33 PM
Quote from: satrow on December 24, 2015, 10:37:30 AM
I don't recall the last time a website suggested that I should switch to an x86 browser, if at all!

So, are you suggesting that I'm doing something wrong? On my Sony Vaio laptop (2010 model), both browsers state that they are "x86 en-US". My Sony is Win 7 64 bit. Something amiss, maybe? Should I change something?

Sorry for somewhat derailing this thread.

(typed from my MacBook Plus)
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 04:19:29 PM
Thanking everyone who responded so far with meaningful suggestions, please know how much I appreciate your suggestions and I am working on trying them all.  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 24, 2015, 05:47:52 PM
Linda,

Just so that you know that you are not alone, I have had this same problem at work with both Firefox and SeaMonkey (both browsers have the same underlying Gecko engine).  I never have been able to get it resolved.  At work we use Windows 7 and Internet Explorer 11 (IE 11), along with the McAfee Enterprise anti-everything suite.  I tried installing both Firefox and SeaMonkey.  I was able to install them (even though I did not have administrative power).  However I continually got that untrusted web site message for virtually every web site.  Even when I set exceptions that message would still return so I abandoned those browsers at work.  However both IE 11 and Google Chrome work with no problems.

At home I have Windows 7 on my mother's old laptop and both Firefox and SeaMonkey work just fine, as does Pale Moon.  So the issue seems to be situation specific, meaning that it is a matter of how everything is set up in any given situation.  Both your computer and my work situation apparently have some sort of problem, but there is no inherent problem between Firefox and Windows 7.

I am not the most knowledgeable person/helper here but here are some thoughts, and maybe these thoughts will trigger some ideas from more knowledgeable helpers.  I think that satrow has correctly identified the problem,


QuoteIt looks like 'something' is running interference on your PC, Linda. The familysearch.org site is not correctly detecting/sniffing your browser and version, which appears to be fine for me using both Firefox and Pale Moon x64 versions.


So the question is what is causing this problem.  Make sure that you are working from an administrator account on your computer

1.  Let's start with a clean slate, please download and install both the 32 bit version of Firefox and also of Pale Moon:  " https://www.mozilla.org/en-US/firefox/new/ " and " http://www.palemoon.org/ ".   (I am avoiding the 64 bit versions because of the additional issues that everyone else has raised.)

2.  What firewall are you using?  Depending on your answer examine in the firewall whether the two browsers are completely allowed or filtered or ? ? ?.  (You should probably do the same with IE 11 and Chrome.)  Report what you find.

3.  Using Firefox go to:  " https://get.adobe.com/flashplayer/ ".  Install the latest version of flash.  MAKE SURE THAT YOU UNCHECK THE OPTIONAL OFFER TO INSTALL THE "FREE MCAFEE SECURITY SCAN PLUS."  You do not need that.

This flash installation will work for both Firefox and Palemoon.

(By the way you should also go to this same page using both IE 11 and Chrome, and follow the same procedure.

4.  Using Firefox go to " https://get.adobe.com/shockwave/ " and download and install.

5.  When all of the above installations are complete, reboot your computer (just playing it safe, I do not know whether this is necessary or not).

6.  Perhaps again examine what your firewall says for each of your browsers, whether they are allowed, filtered, or ? ? ?, and report what you find.

7.  Another something to check is the time and date on your computer.  This should not be a problem in Windows 7 but there are some reports on the internet that this could be causing the same problem.  If necessary correct the time and date.

8.  Now using Firefox, Palemoon, IE 11, and Chrome try all the web sites that you want and report what happens.

9.  Patience and perseverance!

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: DR M on December 24, 2015, 06:14:39 PM
First of all, I'm not a technician, just a computer owner.

Maybe you could try what Mozilla says about the issue, particularly the paragraph under the title The certificate is not trusted because the issuer certificate is unknown :  https://support.mozilla.org/en-US/kb/connection-untrusted-error-message

Good luck, and Merry Christmas!  :)
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 06:53:54 PM
Thanks DR M and v_v for replying.  I hope I am writing in the correct box here to reply to you.  I will have to print out your instructions as there sure are a lot of them. 

I have no idea if I am running this computer as an administrator, so I would need steps on how to learn that.  Also, I use ESETNOD32 antivirus and Malwarebytes as well as Winpatrol. I guess you mean ESETNOD32.  I have no idea how to find out how it filters or doesn't filter browsers as I've never heard of it or done that.  That will take me some time to figure out.  I never had any of this kind of trouble with Windows XP since 2003!  I wonder also about my Gateway 2-Wire Router 1000SW that I got in 2003 that I am still using.  I wonder also about speeds if they are fast enough which could impact my viewing those images that don't come up. 

So, I have a lot to try to do yet. 

DR M, I did add in Familsearch in the box where you add it and that is when I got after that the goofy looking pop up I have posted here earlier; not the untrusted message but the one that looks like it is an outline or something, but still not the website itself.  Why some sites are working in Firefox apparently fine and others are not does baffle me.  So, I'll print everything out and see what I can do.  I am alone here trying to do this.  I don't have anyone else to help.  I appreciate it everyone's time so much.

v-v, I am sorry about your problems too, yes there is a comfort in knowing you are not alone.  A person shouldn't have to be so unhappy trying to use their computer! 

Merry Christmas to everyone here! 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 08:14:06 PM
I am adding a couple of new screen prints that may or may not shed light on my problem.  These are from Firefox.  Thank you.   
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 24, 2015, 10:06:08 PM
Linda,

1.  To determine the nature of your account take the following steps:

a.  Click the Start button in the bottom left hand corner of your desktop.  There will be a pop-up screen.
b.  On that screen click "Control Panel" (it is on the right side).
c.  On the next screen find and click "User Accts."
d.  This will give a screen that tells you what kind of account type you are using.  Report what you find.

In Windows 7 there seem to be "Administrator" and "Standard" accounts.  Standard accounts are more limited for security purposes.  It is usually recommended to use standard accounts for mostly everyday tasks and work.  But when changes, software installations, etc, are necessary then these changes, installations, etc, should be done using an administrator account.


2.  While still in the "Control Panel" find and click "Windows Firewall."  Report what the Windows Firewall screen says, including any "colors".


3.  I do not have ESET NOD32.  Are you using just the antivirus aspect only or do you have the suite which includes a personal firewall and other possible programs?  If you do not know you may need to click the Start button, find ESET amongst your programs, and open something that may serve as an ESET control center.  Something in that control center may be able to tell you whether you are using an ESET firewall or not.  I see little icons with an "E" on your taskbar at the bottom.  I suspect that by right-clicking on one of the icons you will be given a choice to open some kind of control center for ESET.


4.  The "familysearch certificate" that you posted has some interesting and probably useful information but I am not sure what to make of it.  It indicates that the certificate is issued by "ESET SSL Filter CA", but then Firefox is saying that this issuer is unknown.

On my Windows 7 computer when I pull up the certificate in Firefox, the certificate is issued by "DigiCert SHA2 High Assurance Server CA".  On that same screen the Organizational Unit (OU) is listed as "www.digicert.com".  In your posted image the Organizational Unit (OU) says "<Not Part of Certificate>.  I do not know what this all means.  But if I had to guess I would say that there is an issue here between ESET and Firefox for this particular web site.


5.  At some point what may become necessary is to de-activate ESET and to use some other anti.... software to experiment.  But I would not do so yet.  If and when that time comes you will need to use some other antivirus as a temporary replacement.


6.  Your Flash player plugin looks up to date.  But I see no entry for Shockwave.  Even though the Flash Player is labeled "Shockwave Flash" the Shockwave player is different.  The current version is 12.2.2.172.  So I would get the current version at:  " https://get.adobe.com/shockwave/ ".

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 24, 2015, 10:12:50 PM
Quote6.  Your Flash player plugin looks up to date.  But I see no entry for Shockwave.  Even though the Flash Player is labeled "Shockwave Flash" the Shockwave player is different.  The current version is 12.2.2.172.  So I would get the current version at:  " https://get.adobe.com/shockwave/ ".

Personally, I wouldn't bother with Shockwave. It has never been installed on this computer.  It is very seldom used now and certainly wouldn't be needed for sites like FamilySearch.

Linda, if you would like to post logs, perhaps that will provide some insight.  If you do so, because they are so long, expect that you'll need to post two separate replies for the logs to post completely.  The instructions are as follows:

Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) (FRST) and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 24, 2015, 10:47:37 PM
Okay, wow, v_v and Corrine. 

I don't know how to normally post 'logs' as I don't know where to find them.  For me it is easier to post screen prints of what I see to reply to the requests here for the steps for me to be taking. 

I installed that Shockwave before I saw your comments, Corrine.  I am writing here using Chrome, so I will uninstall that.  I tried to do the Shockwave in Firefox and was taken to some 'creative marketing' site anyway, so I don't think that it was installed there.  So, now I guess I have to find the first one an uninstall it. 

I have a couple more screen prints here that I think will answer some of the questions regarding the administrator account and the firewall. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 12:13:08 AM
Hi Corrine,

Okay, I did that Farbar Recovery Scan tool and here are the results copied from it:

Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-12-2015
Ran by Customer (2015-12-24 19:10:49)
Running from C:\Users\Customer\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2009-10-27 22:42:09)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3311552913-1744306017-1404303799-500 - Administrator - Disabled)
Customer (S-1-5-21-3311552913-1744306017-1404303799-1001 - Administrator - Enabled) => C:\Users\Customer
Guest (S-1-5-21-3311552913-1744306017-1404303799-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3311552913-1744306017-1404303799-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET NOD32 Antivirus 9.0.318.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 9.0.318.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon MP280 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series) (Version:  - )
Canon MP280 series User Registration (HKLM-x32\...\Canon MP280 series User Registration) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
DisplayLink Core Software (HKLM\...\{C66D573C-A70D-4F11-AA1C-5423340B951F}) (Version: 7.0.43526.0 - DisplayLink Corp.)
DisplayLink Graphics (HKLM\...\{8F86C262-8746-415C-9E4D-CD0E2B42C61B}) (Version: 7.0.43577.0 - DisplayLink Corp.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 3.12.6 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.77 - Dropbox, Inc.) Hidden
ESET NOD32 Antivirus (HKLM\...\{60853F5E-E6F5-4A34-BBCD-C09D49BB5E64}) (Version: 9.0.318.0 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Mozilla Firefox 43.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.2 (x86 en-US)) (Version: 43.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.2 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 7 Essentials (HKLM-x32\...\{66EBD70F-A42C-475F-AEDF-277378151033}) (Version: 7.02.9491 - Nero AG)
Personal Ancestral File 5 (HKLM-x32\...\{D94A8E22-DF2B-4107-9E51-608A60A7671D}) (Version:  - )
Personal Ancestral File Companion 5.5 (HKLM-x32\...\{91AFACB3-CA46-4C1E-AF2D-F72EE0B112E4}) (Version: 5.5 - Intellectual Reserve Inc.)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
RootsMagic 6.3.3.2 (HKLM-x32\...\{94433E0D-764C-4964-AD0B-EC46BCA7E68E}_is1) (Version: RootsMagic 6.3.3.2 - RootsMagic, Inc.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
WinPatrol (HKLM-x32\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 33.6.2015.18 - Ruiware)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

15-12-2015 12:20:02 Windows Update
16-12-2015 15:45:12 RESTORE TO DECEBER 16 2015
18-12-2015 21:38:01 Windows Update
22-12-2015 18:06:31 Windows Update
22-12-2015 18:52:27 Removed Java 8 Update 66

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00924C49-F973-4840-BE95-6E95509A3AB8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-15] (Google Inc.)
Task: {11CA0F67-6FCF-4AF0-99B9-38E9B4B096D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-15] (Google Inc.)
Task: {1D751636-3208-457D-BEC2-F0CEAA3056B0} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-12-04] (Dropbox, Inc.)
Task: {35702DDA-50BF-41EB-80C4-F845EE254486} - System32\Tasks\{4D80020E-0891-4A5A-974F-A3F26942D980} => Firefox.exe
Task: {45B74B32-2DBA-499A-952C-3CDBA01843FA} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-12-04] (Dropbox, Inc.)
Task: {6325AD98-CA90-4010-A108-96ADEF3EA811} - System32\Tasks\Microsoft\Windows\MobilePC\DisplayLink TMM Control
Task: {896E5C73-799D-47E0-8478-B9E6A1F1E11E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-10] (Adobe Systems Incorporated)
Task: {DD7A6A7C-E102-4B05-A141-78C9886E0819} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-12-04 11:18 - 2010-04-05 14:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2015-12-04 16:12 - 2015-12-21 14:42 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2015-12-23 17:23 - 2015-12-21 14:42 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00022848 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Random.OSRNG.winrandom.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00023352 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Util._counter.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00042296 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Cipher._AES.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2015-12-04 16:12 - 2015-12-21 19:22 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00109520 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 01734984 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_python_x66cf7a7cx17a72769.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2015-12-08 19:58 - 2015-12-21 14:42 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00021320 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_xde9e4433x360333f0.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2015-12-08 19:58 - 2015-12-21 19:22 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2015-12-23 17:23 - 2015-12-21 14:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2015-12-23 17:23 - 2015-12-21 14:42 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00021304 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Util.strxor.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00084792 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2015-12-04 16:12 - 2015-12-21 19:22 - 01826608 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 03891504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 01950000 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00519984 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00133936 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00225080 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00486704 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00019920 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick.2\qtquick2plugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00786904 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00063448 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Window.2\windowplugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2015-12-24 14:12 - 2015-12-24 07:46 - 16792256 _____ () C:\Users\Customer\AppData\Local\Google\Chrome\User Data\PepperFlash\20.0.0.267\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Customer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.16.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: NBService => 3
MSCONFIG\Services: NMIndexingService => 3
MSCONFIG\Services: WerSvc => 3
MSCONFIG\Services: WMPNetworkSvc => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install Webroot FF RunOnce.lnk => C:\Windows\pss\Install Webroot FF RunOnce.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install Webroot IE RunOnce.lnk => C:\Windows\pss\Install Webroot IE RunOnce.lnk.CommonStartup
MSCONFIG\startupreg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D1C88B61-56D3-4976-BA66-A25546C123EC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{94C72EB5-F739-41B5-8BD8-42D4E2A14DDC}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{32183950-32E0-4F20-9998-9D3631BF4561}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8E07D87D-C70E-42DF-BEF6-2CC635BD7CFF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============

Name: PCI Serial Port
Description: PCI Serial Port
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/23/2015 06:16:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.18064, time stamp: 0x56042d8f
Faulting module name: ntdll.dll, version: 6.1.7601.19045, time stamp: 0x56259295
Exception code: 0xc0000005
Fault offset: 0x000000000004ac04
Faulting process id: 0x1e0
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3

Error: (12/07/2015 12:57:25 PM) (Source: MsiInstaller) (EventID: 1024) (User: LINDAJEANLIMESE)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F094E6F00}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error: (12/04/2015 12:00:44 PM) (Source: MsiInstaller) (EventID: 1024) (User: LINDAJEANLIMESE)
Description: Product: Compatibility Pack for the 2007 Office system - Update '{1D53FB73-9826-4541-B2E0-A239C6EBA718}' could not be installed. Error code 1642. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error: (12/04/2015 11:18:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (12/04/2015 11:18:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/28/2015 04:46:16 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB973688) -- Error 1935. An error occured during the installation of assembly component {7B2B4EA5-1028-B7E6-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9876.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/28/2015 02:36:12 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB954430) -- Error 1935. An error occured during the installation of assembly component {7B30B69B-0E6C-B7E0-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9870.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/27/2015 08:53:46 PM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB973688) -- Error 1935. An error occured during the installation of assembly component {7B2B4EA5-1028-B7E6-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9876.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/27/2015 08:07:33 PM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB954430) -- Error 1935. An error occured during the installation of assembly component {7B30B69B-0E6C-B7E0-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9870.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/27/2009 06:33:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.


System errors:
=============
Error: (12/24/2015 06:47:23 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.

Error: (12/24/2015 06:44:25 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.

Error: (12/24/2015 06:44:24 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.

Error: (12/24/2015 06:41:31 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 06:41:31 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:35 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:35 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:35 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:34 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:07:32 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU E4400 @ 2.00GHz
Percentage of memory in use: 75%
Total physical RAM: 3956.61 MB
Available physical RAM: 953.05 MB
Total Virtual: 7911.43 MB
Available Virtual: 4358.73 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:845.79 GB) NTFS
Drive e: () (Fixed) (Total:14.9 GB) (Free:7.9 GB) FAT32
Drive f: () (Removable) (Total:14.9 GB) (Free:8.69 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 41AB2316)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 2 (Size: 14.9 GB) (Disk ID: CBE4BC1A)
Partition 1: (Not Active) - (Size=14.9 GB) - (Type=0C)

==================== End of Addition.txt ============================
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 25, 2015, 12:15:09 AM
Linda,

So you are running an administrator account, and you are running the Windows Firewall.

For the moment we will leave Windows Firewall alone.  My guess is that it is doing its job satisfactorily.

Since IE 11 and Chrome do work for "familyresearch.org" on your computer, use each of those browsers and go to the web site.  Then just like you did with Firefox post screen shots of the certificates from IE 11 and Chrome.  Since these two browsers do work at the web site (without the .jpg images of course), a comparison of their certificates with those of Firefox might provide some useful data.

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 12:26:21 AM
I apologize to Corrine, I didn't get the first scan from the desktop, I had a hang up saving it there, but got it on the desktop and just ran a new scan, so please disregard the first scan.  Here are the results from the desktop:

Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-12-2015
Ran by Customer (2015-12-24 19:22:53)
Running from C:\Users\Customer\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2009-10-27 22:42:09)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3311552913-1744306017-1404303799-500 - Administrator - Disabled)
Customer (S-1-5-21-3311552913-1744306017-1404303799-1001 - Administrator - Enabled) => C:\Users\Customer
Guest (S-1-5-21-3311552913-1744306017-1404303799-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3311552913-1744306017-1404303799-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET NOD32 Antivirus 9.0.318.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 9.0.318.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon MP280 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series) (Version:  - )
Canon MP280 series User Registration (HKLM-x32\...\Canon MP280 series User Registration) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
DisplayLink Core Software (HKLM\...\{C66D573C-A70D-4F11-AA1C-5423340B951F}) (Version: 7.0.43526.0 - DisplayLink Corp.)
DisplayLink Graphics (HKLM\...\{8F86C262-8746-415C-9E4D-CD0E2B42C61B}) (Version: 7.0.43577.0 - DisplayLink Corp.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 3.12.6 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.77 - Dropbox, Inc.) Hidden
ESET NOD32 Antivirus (HKLM\...\{60853F5E-E6F5-4A34-BBCD-C09D49BB5E64}) (Version: 9.0.318.0 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Mozilla Firefox 43.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.2 (x86 en-US)) (Version: 43.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.2 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 7 Essentials (HKLM-x32\...\{66EBD70F-A42C-475F-AEDF-277378151033}) (Version: 7.02.9491 - Nero AG)
Personal Ancestral File 5 (HKLM-x32\...\{D94A8E22-DF2B-4107-9E51-608A60A7671D}) (Version:  - )
Personal Ancestral File Companion 5.5 (HKLM-x32\...\{91AFACB3-CA46-4C1E-AF2D-F72EE0B112E4}) (Version: 5.5 - Intellectual Reserve Inc.)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
RootsMagic 6.3.3.2 (HKLM-x32\...\{94433E0D-764C-4964-AD0B-EC46BCA7E68E}_is1) (Version: RootsMagic 6.3.3.2 - RootsMagic, Inc.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
WinPatrol (HKLM-x32\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 33.6.2015.18 - Ruiware)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

15-12-2015 12:20:02 Windows Update
16-12-2015 15:45:12 RESTORE TO DECEBER 16 2015
18-12-2015 21:38:01 Windows Update
22-12-2015 18:06:31 Windows Update
22-12-2015 18:52:27 Removed Java 8 Update 66

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00924C49-F973-4840-BE95-6E95509A3AB8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-15] (Google Inc.)
Task: {11CA0F67-6FCF-4AF0-99B9-38E9B4B096D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-15] (Google Inc.)
Task: {1D751636-3208-457D-BEC2-F0CEAA3056B0} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-12-04] (Dropbox, Inc.)
Task: {35702DDA-50BF-41EB-80C4-F845EE254486} - System32\Tasks\{4D80020E-0891-4A5A-974F-A3F26942D980} => Firefox.exe
Task: {45B74B32-2DBA-499A-952C-3CDBA01843FA} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-12-04] (Dropbox, Inc.)
Task: {6325AD98-CA90-4010-A108-96ADEF3EA811} - System32\Tasks\Microsoft\Windows\MobilePC\DisplayLink TMM Control
Task: {896E5C73-799D-47E0-8478-B9E6A1F1E11E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-10] (Adobe Systems Incorporated)
Task: {DD7A6A7C-E102-4B05-A141-78C9886E0819} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-12-04 11:18 - 2010-04-05 14:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2015-12-04 16:12 - 2015-12-21 14:42 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2015-12-23 17:23 - 2015-12-21 14:42 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00022848 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Random.OSRNG.winrandom.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00023352 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Util._counter.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00042296 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Cipher._AES.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2015-12-04 16:12 - 2015-12-21 19:22 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00109520 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 01734984 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_python_x66cf7a7cx17a72769.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2015-12-08 19:58 - 2015-12-21 14:42 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00021320 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_xde9e4433x360333f0.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2015-12-08 19:58 - 2015-12-21 19:22 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2015-12-23 17:23 - 2015-12-21 14:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2015-12-23 17:23 - 2015-12-21 14:42 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00021304 _____ () C:\Program Files (x86)\Dropbox\Client\Crypto.Util.strxor.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2015-12-23 17:23 - 2015-12-21 19:22 - 00084792 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2015-12-04 16:12 - 2015-12-21 19:22 - 01826608 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 03891504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 01950000 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00519984 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00133936 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00225080 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00486704 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2015-12-04 16:12 - 2015-12-21 19:22 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2015-12-04 16:12 - 2015-12-21 14:42 - 00019920 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick.2\qtquick2plugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00786904 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00063448 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Window.2\windowplugin.dll
2015-12-04 16:12 - 2015-12-21 14:42 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2015-12-24 14:12 - 2015-12-24 07:46 - 16792256 _____ () C:\Users\Customer\AppData\Local\Google\Chrome\User Data\PepperFlash\20.0.0.267\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Customer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.16.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: NBService => 3
MSCONFIG\Services: NMIndexingService => 3
MSCONFIG\Services: WerSvc => 3
MSCONFIG\Services: WMPNetworkSvc => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install Webroot FF RunOnce.lnk => C:\Windows\pss\Install Webroot FF RunOnce.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install Webroot IE RunOnce.lnk => C:\Windows\pss\Install Webroot IE RunOnce.lnk.CommonStartup
MSCONFIG\startupreg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D1C88B61-56D3-4976-BA66-A25546C123EC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{94C72EB5-F739-41B5-8BD8-42D4E2A14DDC}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{32183950-32E0-4F20-9998-9D3631BF4561}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8E07D87D-C70E-42DF-BEF6-2CC635BD7CFF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============

Name: PCI Serial Port
Description: PCI Serial Port
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/23/2015 06:16:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.18064, time stamp: 0x56042d8f
Faulting module name: ntdll.dll, version: 6.1.7601.19045, time stamp: 0x56259295
Exception code: 0xc0000005
Fault offset: 0x000000000004ac04
Faulting process id: 0x1e0
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3

Error: (12/07/2015 12:57:25 PM) (Source: MsiInstaller) (EventID: 1024) (User: LINDAJEANLIMESE)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F094E6F00}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error: (12/04/2015 12:00:44 PM) (Source: MsiInstaller) (EventID: 1024) (User: LINDAJEANLIMESE)
Description: Product: Compatibility Pack for the 2007 Office system - Update '{1D53FB73-9826-4541-B2E0-A239C6EBA718}' could not be installed. Error code 1642. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error: (12/04/2015 11:18:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (12/04/2015 11:18:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/28/2015 04:46:16 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB973688) -- Error 1935. An error occured during the installation of assembly component {7B2B4EA5-1028-B7E6-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9876.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/28/2015 02:36:12 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB954430) -- Error 1935. An error occured during the installation of assembly component {7B30B69B-0E6C-B7E0-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9870.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/27/2015 08:53:46 PM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB973688) -- Error 1935. An error occured during the installation of assembly component {7B2B4EA5-1028-B7E6-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9876.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/27/2015 08:07:33 PM) (Source: MsiInstaller) (EventID: 11935) (User: NT AUTHORITY)
Description: Product: MSXML 4.0 SP2 (KB954430) -- Error 1935. An error occured during the installation of assembly component {7B30B69B-0E6C-B7E0-A06B-D6B9ABF34537}. HRESULT: 0x80070BC9. assembly interface: IAssemblyCacheItem, function: Commit, assembly name: Microsoft.MSXML2,type="win32",version="4.20.9870.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"

Error: (10/27/2009 06:33:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.


System errors:
=============
Error: (12/24/2015 06:47:23 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.

Error: (12/24/2015 06:44:25 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.

Error: (12/24/2015 06:44:24 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.

Error: (12/24/2015 06:41:31 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 06:41:31 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:35 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:35 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:35 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:35:34 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Error: (12/24/2015 05:07:32 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU E4400 @ 2.00GHz
Percentage of memory in use: 77%
Total physical RAM: 3956.61 MB
Available physical RAM: 890.63 MB
Total Virtual: 7911.43 MB
Available Virtual: 4286.36 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:845.79 GB) NTFS
Drive e: () (Fixed) (Total:14.9 GB) (Free:7.9 GB) FAT32
Drive f: () (Removable) (Total:14.9 GB) (Free:8.69 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 41AB2316)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 2 (Size: 14.9 GB) (Disk ID: CBE4BC1A)
Partition 1: (Not Active) - (Size=14.9 GB) - (Type=0C)

==================== End of Addition.txt ============================
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 12:33:44 AM
Corrine, I am not a computer geek, but I can tell there certainly are a lot of errors and failures, etc.   I don't know what I should be doing next.  Thank you for the tool. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 12:40:23 AM
Hi, Linda. 

Yes, I saw those errors.  So far, my research is only showing older posts where people have the same error but I haven't found a solution yet.   In the meantime, the FRST.txt log is located in C:\Users\Customer\Downloads.  Please reopen that in Notepad and copy/paste it here as a reply.  It will likely take me a while to review the logs but v_v has assigned you another task anyway.  :D

Thanks.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 12:49:25 AM
Hi Corrine,

I did paste it the second time from the desktop, so this might be a repeat of it.  I obtained by accessing the C:\Users\Customer\Downloads:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-12-2015
Ran by Customer (administrator) on LINDAJEANLIMESE (24-12-2015 19:10:08)
Running from C:\Users\Customer\Downloads
Loaded Profiles: Customer (Available Profiles: Customer)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(TeamViewer GmbH) C:\Users\Customer\AppData\Local\Temp\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Ruiware) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(The Church of Jesus Christ of Latter-day Saints) C:\Program Files (x86)\FamilySearch\Paf5\paf5.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-24] (CANON INC.)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [24952376 2015-12-21] (Dropbox, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1216648 2015-08-05] (Ruiware)
HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\...\MountPoints2: E - E:\LaunchU3.exe -a
HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\...\MountPoints2: F - F:\LaunchU3.exe -a
HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\...\MountPoints2: {477cffee-a7ea-11e5-a835-001aa0e8b05d} - E:\LaunchU3.exe -a
HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\...\MountPoints2: {477cfff0-a7ea-11e5-a835-001aa0e8b05d} - F:\LaunchU3.exe -a
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-21] (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 172.16.0.1
Tcpip\..\Interfaces\{91412CAC-521D-4243-8AA3-F6E6A148B160}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{EACF0F70-B08B-4282-8C36-7F2FC28DA68B}: [DhcpNameServer] 172.16.0.1

Internet Explorer:
==================
HKU\S-1-5-21-3311552913-1744306017-1404303799-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?gws_rd=ssl
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll => No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll => No File
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll No File
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll No File
IE Session Restore: HKU\S-1-5-21-3311552913-1744306017-1404303799-1001 -> is enabled.

FireFox:
========
FF ProfilePath: C:\Users\Customer\AppData\Roaming\Mozilla\Firefox\Profiles\vsevnly1.default-1449953797411
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-08] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-08] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-14] (CANON INC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?ei={inputEncoding}&fr=crmas&p={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-15]
CHR Extension: (Google Docs) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-16]
CHR Extension: (Google Drive) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-16]
CHR Extension: (YouTube) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-16]
CHR Extension: (Google Search) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-16]
CHR Extension: (Google Sheets) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-15]
CHR Extension: (Google Docs Offline) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-15]
CHR Extension: (Gmail) - C:\Users\Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-16]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-12-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-12-04] (Dropbox, Inc.)
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [8979416 2012-11-20] (DisplayLink Corp.)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2505472 2015-10-09] (ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2007-06-01] (Nero AG)
R2 TeamViewer; c:\users\customer\appdata\local\temp\teamviewer\TeamViewer_Service.exe [5532432 2015-12-14] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 DisplayLinkUsbPort; C:\Windows\System32\DRIVERS\DisplayLinkUsbPort_7.0.41409.0.sys [17408 2015-11-16] (hxxp://libusb-win32.sourceforge.net)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264040 2015-07-30] (ESET)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [186784 2015-07-30] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [170792 2015-07-30] (ESET)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-24] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-24 19:10 - 2015-12-24 19:10 - 00014622 _____ C:\Users\Customer\Downloads\FRST.txt
2015-12-24 19:10 - 2015-12-24 19:10 - 00000000 ____D C:\FRST
2015-12-24 19:08 - 2015-12-24 19:08 - 02370560 _____ (Farbar) C:\Users\Customer\Downloads\FRST64.exe
2015-12-24 19:07 - 2015-12-24 19:07 - 01721856 _____ (Farbar) C:\Users\Customer\Downloads\FRST (1).exe
2015-12-24 19:06 - 2015-12-24 19:06 - 01721856 _____ (Farbar) C:\Users\Customer\Downloads\FRST.exe
2015-12-24 17:33 - 2015-12-24 17:33 - 05028296 _____ (Adobe Systems Inc.) C:\Users\Customer\Downloads\Shockwave_Installer_Slim (3).exe
2015-12-24 17:32 - 2015-12-24 17:33 - 05028296 _____ (Adobe Systems Inc.) C:\Users\Customer\Downloads\Shockwave_Installer_Slim (2).exe
2015-12-24 17:32 - 2015-12-24 17:33 - 05028296 _____ (Adobe Systems Inc.) C:\Users\Customer\Downloads\Shockwave_Installer_Slim (1).exe
2015-12-24 17:31 - 2015-12-24 17:32 - 05028296 _____ (Adobe Systems Inc.) C:\Users\Customer\Downloads\Shockwave_Installer_Slim.exe
2015-12-23 23:35 - 2015-12-23 23:35 - 00248632 _____ C:\Users\Customer\Downloads\Firefox Setup Stub 43.0.2 (2).exe
2015-12-23 23:27 - 2015-12-23 23:27 - 00248632 _____ C:\Users\Customer\Downloads\Firefox Setup Stub 43.0.2 (1).exe
2015-12-23 23:08 - 2015-12-23 23:08 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-23 23:08 - 2015-12-23 23:08 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-12-23 23:08 - 2015-12-23 23:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-23 23:08 - 2015-12-23 23:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-23 23:00 - 2015-12-23 23:00 - 00248632 _____ C:\Users\Customer\Downloads\Firefox Setup Stub 43.0.2.exe
2015-12-23 17:23 - 2015-12-23 17:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-12-23 16:47 - 2015-12-23 16:47 - 02546817 _____ C:\Users\Customer\Documents\HARMON LIMES & FAMILY - 12-23-2015.ged
2015-12-23 16:46 - 2015-12-23 23:58 - 02854912 _____ C:\Users\Customer\Documents\LINDA JEAN LIMES - DECEMBER 23 2015.paf
2015-12-23 16:42 - 2015-12-23 16:42 - 01564797 _____ C:\Users\Customer\Documents\LINDA JEAN LIMES - 12-23-2015 (2015-12-23).rmgb
2015-12-23 16:41 - 2015-12-23 16:45 - 04328448 _____ C:\Users\Customer\Documents\LINDA JEAN LIMES - 12-23-2015.rmgc
2015-12-22 22:45 - 2015-12-22 22:50 - 47305048 _____ C:\Users\Customer\Downloads\Firefox Setup 43.0.2.exe
2015-12-22 20:05 - 2015-12-22 20:07 - 21877232 _____ (Flickr) C:\Users\Customer\Downloads\FlickrUploadrInstallr.exe
2015-12-22 16:57 - 2015-12-22 16:58 - 06937888 _____ (TeamViewer) C:\Users\Customer\Downloads\TeamViewerQS_en-ckj (2).exe
2015-12-22 16:26 - 2015-12-22 16:27 - 06937888 _____ (TeamViewer) C:\Users\Customer\Downloads\TeamViewerQS_en-ckj (1).exe
2015-12-22 16:20 - 2015-12-22 16:20 - 00000000 ____D C:\Users\Customer\AppData\Roaming\Sun
2015-12-22 16:20 - 2015-12-22 16:20 - 00000000 ____D C:\Users\Customer\AppData\LocalLow\Sun
2015-12-22 16:20 - 2015-12-22 16:20 - 00000000 ____D C:\Users\Customer\.oracle_jre_usage
2015-12-22 16:19 - 2015-12-22 16:21 - 00000000 ____D C:\ProgramData\Oracle
2015-12-22 16:18 - 2015-12-22 16:18 - 00000000 ____D C:\Users\Customer\AppData\LocalLow\Oracle
2015-12-22 16:12 - 2015-12-22 16:18 - 50200160 _____ (Oracle Corporation) C:\Users\Customer\Downloads\jre-8u66-windows-i586.exe
2015-12-22 16:06 - 2015-12-22 16:06 - 00000000 ____D C:\Users\Customer\AppData\Roaming\TeamViewer
2015-12-22 16:04 - 2015-12-22 16:06 - 06937888 _____ (TeamViewer) C:\Users\Customer\Downloads\TeamViewerQS_en-ckj.exe
2015-12-21 22:10 - 2015-12-21 22:10 - 00024064 ___SH C:\Users\Customer\Thumbs.db
2015-12-21 19:14 - 2015-12-21 19:14 - 00249416 _____ C:\Users\Customer\Downloads\Firefox Setup Stub 43.0.1.exe
2015-12-21 19:14 - 2015-12-21 19:14 - 00249416 _____ C:\Users\Customer\Downloads\Firefox Setup Stub 43.0.1 (1).exe
2015-12-18 11:32 - 2015-12-18 11:32 - 00125206 _____ C:\Users\Customer\Downloads\Attachments_20151218.zip
2015-12-13 06:30 - 2015-12-13 06:30 - 00000000 ____D C:\Users\Customer\AppData\LocalLow\Temp
2015-12-12 22:07 - 2015-12-12 22:07 - 00000000 ____D C:\ProgramData\CanonIJ
2015-12-12 22:01 - 2015-12-12 22:01 - 00000000 ___HD C:\ProgramData\CanonIJScan
2015-12-12 21:59 - 2015-12-12 22:01 - 00000000 ____D C:\Users\Customer\AppData\Roaming\Canon
2015-12-11 22:58 - 2015-12-20 16:48 - 00000237 _____ C:\Users\Customer\Desktop\Tombstone Birthday calculator at Ancestor Search.url
2015-12-11 11:05 - 2015-12-11 11:05 - 00016519 _____ C:\Users\Customer\Documents\Wheaton-Bottles.xlsx
2015-12-09 16:04 - 2015-12-12 15:56 - 00000000 ____D C:\Users\Customer\Desktop\Old Firefox Data
2015-12-09 10:44 - 2015-11-11 16:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-12-09 10:44 - 2015-11-11 15:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-12-09 10:44 - 2015-11-11 11:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-09 10:44 - 2015-11-11 11:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-09 10:44 - 2015-11-11 10:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-12-09 10:44 - 2015-11-11 10:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-09 10:44 - 2015-11-11 10:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-09 10:44 - 2015-11-11 10:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-09 10:44 - 2015-11-11 09:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-09 10:44 - 2015-11-09 19:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-12-09 10:44 - 2015-11-09 19:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-09 10:44 - 2015-11-09 19:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-12-09 10:44 - 2015-11-09 19:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-12-09 10:44 - 2015-11-09 19:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-12-09 10:44 - 2015-11-09 19:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-12-09 10:44 - 2015-11-09 19:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-09 10:44 - 2015-11-09 19:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-12-09 10:44 - 2015-11-09 19:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-12-09 10:44 - 2015-11-09 19:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-12-09 10:44 - 2015-11-09 19:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-12-09 10:44 - 2015-11-09 19:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-09 10:44 - 2015-11-09 19:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-12-09 10:44 - 2015-11-09 18:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-12-09 10:44 - 2015-11-09 18:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-12-09 10:44 - 2015-11-09 18:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-09 10:44 - 2015-11-09 18:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-12-09 10:44 - 2015-11-09 18:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-12-09 10:44 - 2015-11-09 18:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-12-09 10:44 - 2015-11-09 18:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-09 10:44 - 2015-11-09 18:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-12-09 10:44 - 2015-11-09 18:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-09 10:44 - 2015-11-09 18:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-09 10:44 - 2015-11-09 18:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-12-09 10:44 - 2015-11-08 17:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-12-09 10:44 - 2015-11-08 17:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-12-09 10:44 - 2015-11-08 17:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-12-09 10:44 - 2015-11-08 17:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-09 10:44 - 2015-11-08 17:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-09 10:44 - 2015-11-08 17:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-12-09 10:44 - 2015-11-08 17:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-12-09 10:44 - 2015-11-08 17:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-12-09 10:44 - 2015-11-08 17:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-12-09 10:44 - 2015-11-08 17:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-12-09 10:44 - 2015-11-08 17:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-09 10:44 - 2015-11-08 17:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-12-09 10:44 - 2015-11-08 17:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-09 10:44 - 2015-11-08 17:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-12-09 10:44 - 2015-11-08 17:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-12-09 10:44 - 2015-11-08 17:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-12-09 10:44 - 2015-11-08 16:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-12-09 10:44 - 2015-11-08 16:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-12-09 10:44 - 2015-11-08 16:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-12-09 10:44 - 2015-11-08 16:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-12-09 10:44 - 2015-11-08 16:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-09 10:44 - 2015-11-08 16:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-12-09 10:44 - 2015-11-08 16:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-12-09 10:44 - 2015-11-08 16:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-09 10:44 - 2015-11-08 16:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-12-09 10:44 - 2015-11-08 16:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-09 10:44 - 2015-11-08 16:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-12-09 10:44 - 2015-11-08 16:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-09 10:44 - 2015-11-08 15:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-09 10:44 - 2015-11-08 15:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-09 10:44 - 2015-11-08 15:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-12-09 10:35 - 2015-11-10 13:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-09 10:35 - 2015-11-10 13:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-09 10:35 - 2015-11-10 13:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-09 10:35 - 2015-11-10 13:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-09 10:35 - 2015-11-10 13:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-09 10:35 - 2015-11-10 12:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-09 10:35 - 2015-11-05 14:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-12-09 10:35 - 2015-11-05 14:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-12-09 10:35 - 2015-11-03 14:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-12-09 10:35 - 2015-11-03 13:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2015-12-09 10:34 - 2015-11-11 13:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-09 10:34 - 2015-11-11 13:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-09 10:34 - 2015-11-11 13:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-09 10:34 - 2015-11-11 13:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-09 10:34 - 2015-11-05 14:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2015-12-09 10:34 - 2015-11-05 14:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2015-12-09 10:34 - 2015-11-05 04:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-09 10:30 - 2015-11-03 14:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-09 10:30 - 2015-11-03 13:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2015-12-08 22:42 - 2015-12-08 22:42 - 00002978 _____ C:\Windows\System32\Tasks\{4D80020E-0891-4A5A-974F-A3F26942D980}
2015-12-07 13:45 - 2015-12-07 13:45 - 00000000 ____D C:\Users\Customer\Documents\FamilySearch
2015-12-07 10:22 - 2015-12-07 10:22 - 00000000 ____D C:\Users\Customer\AppData\Local\ElevatedDiagnostics
2015-12-06 23:47 - 2015-12-06 23:47 - 00000000 ___RD C:\Users\Customer\Documents\Scanned Documents
2015-12-06 23:47 - 2015-12-06 23:47 - 00000000 ____D C:\Users\Customer\Documents\Fax
2015-12-06 20:36 - 2015-12-23 16:40 - 01542144 _____ C:\Users\Customer\Documents\WINDER FAMILY.rmgc
2015-12-06 20:36 - 2015-12-02 17:14 - 04326400 _____ C:\Users\Customer\Documents\LINDA JEAN LIMES - DECEMBER 2 2015.rmgc
2015-12-06 20:36 - 2014-11-18 16:06 - 00055596 _____ C:\Users\Customer\Documents\Medicare Part D Coverage Destermination.pdf
2015-12-06 20:36 - 2014-09-25 08:46 - 00342782 _____ C:\Users\Customer\Documents\WINDER FAMILY (2014-09-25).rmgb
2015-12-06 20:36 - 2014-03-12 09:27 - 01693696 _____ C:\Users\Customer\Documents\RAZEE FAMILY.rmgc
2015-12-06 20:36 - 2014-03-12 09:27 - 00382069 _____ C:\Users\Customer\Documents\RAZEE FAMILY (2014-03-12).rmgb
2015-12-06 20:36 - 2014-03-11 21:17 - 09022464 _____ C:\Users\Customer\Documents\CORY FAMILY.rmgc
2015-12-06 20:36 - 2014-02-25 16:22 - 00086846 _____ C:\Users\Customer\Documents\Linda Ellis XP to Windows 7 - 2-25-25.2014.mht
2015-12-06 20:36 - 2012-11-16 20:29 - 00421888 _____ C:\Users\Customer\Documents\RAZEE FAMILY FROM SONJA CHRISTOFFERSON.PAF
2015-12-06 20:33 - 2015-12-06 20:33 - 00000000 ____D C:\Users\Customer\Documents\LUMBAR SPINE XRAY - 12-4-2014
2015-12-06 20:29 - 2015-12-06 20:29 - 00000132 _____ C:\Users\Customer\AppData\default.pls
2015-12-06 15:22 - 2015-12-24 14:10 - 00000000 ____D C:\Users\Customer\Documents\MAIN DOCUMENTS LIBRARY
2015-12-06 15:18 - 2015-12-06 15:19 - 00000000 ____D C:\Users\Customer\Documents\2007 PHOTOS FROM KODAK CD
2015-12-05 16:31 - 2015-12-05 16:31 - 00000000 ____D C:\Users\Customer\AppData\LocalLow\Adobe
2015-12-05 16:31 - 2015-12-05 16:31 - 00000000 ____D C:\Users\Customer\AppData\Local\CEF
2015-12-05 16:25 - 2015-12-05 16:29 - 00000000 ____D C:\PCOMP5
2015-12-05 16:25 - 2015-12-05 16:25 - 00000583 _____ C:\Users\Public\Desktop\PAF Companion.lnk
2015-12-05 16:25 - 2015-12-05 16:25 - 00000000 ____D C:\Users\Customer\AppData\Local\Progeny
2015-12-05 16:25 - 2010-09-01 13:51 - 04218880 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\SysWOW64\cdintf400.dll
2015-12-05 09:50 - 2015-12-05 09:50 - 00000893 _____ C:\Users\Customer\Desktop\LINDA JEAN LIMES - DECEMBER 5 2015.paf - Shortcut.lnk
2015-12-05 09:49 - 2015-12-23 15:45 - 00881472 _____ C:\Users\Customer\Documents\LINDA JEAN LIMES - DECEMBER 5 2015.zip
2015-12-05 09:48 - 2015-12-23 16:46 - 02854912 _____ C:\Users\Customer\Documents\LINDA JEAN LIMES - DECEMBER 5 2015.paf
2015-12-05 09:37 - 2015-12-05 16:25 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-05 09:37 - 2015-12-05 16:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FamilySearch
2015-12-05 09:37 - 2015-12-05 09:37 - 00002018 _____ C:\Users\Public\Desktop\PAF 5.lnk
2015-12-05 09:37 - 2015-12-05 09:37 - 00000000 ____D C:\Program Files (x86)\FamilySearch
2015-12-05 09:16 - 2015-12-20 16:49 - 00001998 _____ C:\Users\Public\Desktop\Picasa 3.lnk
2015-12-05 09:15 - 2015-12-05 09:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
2015-12-05 07:11 - 2015-12-05 07:11 - 00000000 ____D C:\Users\Customer\AppData\Local\ESET
2015-12-04 21:45 - 2015-12-05 07:18 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-12-04 21:44 - 2015-12-07 12:57 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-04 21:44 - 2015-12-04 21:44 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-12-04 21:43 - 2015-12-04 21:43 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-12-04 17:40 - 2015-12-04 17:40 - 00001069 _____ C:\Users\Customer\Desktop\RootsMagic 6 To-Go.lnk
2015-12-04 17:40 - 2015-12-04 17:40 - 00001049 _____ C:\Users\Customer\Desktop\RootsMagic 6.lnk
2015-12-04 17:40 - 2015-12-04 17:40 - 00000000 ____D C:\Users\Customer\AppData\Roaming\RootsMagic
2015-12-04 17:40 - 2015-12-04 17:40 - 00000000 ____D C:\ProgramData\RootsMagic Shared
2015-12-04 17:40 - 2015-12-04 17:40 - 00000000 ____D C:\ProgramData\RootsMagic
2015-12-04 17:40 - 2015-12-04 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RootsMagic 6
2015-12-04 17:40 - 2015-12-04 17:40 - 00000000 ____D C:\Program Files (x86)\RootsMagic 6
2015-12-04 16:17 - 2015-12-24 07:57 - 00000000 ___RD C:\Users\Customer\Dropbox
2015-12-04 16:17 - 2015-12-04 16:17 - 00001230 _____ C:\Users\Customer\Desktop\Dropbox.lnk
2015-12-04 16:11 - 2015-12-04 16:11 - 00000000 ____D C:\Users\Customer\AppData\Roaming\Dropbox
2015-12-04 16:05 - 2015-12-24 19:10 - 00000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2015-12-04 16:05 - 2015-12-24 16:10 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2015-12-04 16:05 - 2015-12-24 07:57 - 00000000 ____D C:\Users\Customer\AppData\Local\Dropbox
2015-12-04 16:05 - 2015-12-23 17:23 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-12-04 16:05 - 2015-12-04 16:05 - 00003908 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2015-12-04 16:05 - 2015-12-04 16:05 - 00003656 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2015-12-04 16:05 - 2015-12-04 16:05 - 00000000 ____D C:\ProgramData\Dropbox
2015-12-04 15:19 - 2015-12-04 16:12 - 00000000 ____D C:\Users\Customer\AppData\Roaming\WinPatrol
2015-12-04 15:18 - 2015-12-04 15:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2015-12-04 15:18 - 2015-12-04 15:18 - 00000000 ____D C:\ProgramData\InstallMate
2015-12-04 15:18 - 2015-12-04 15:18 - 00000000 ____D C:\Program Files (x86)\Ruiware
2015-12-04 14:57 - 2015-12-04 14:57 - 00000000 ____D C:\Users\Customer\AppData\Local\Microsoft Games
2015-12-04 12:04 - 2015-12-04 12:04 - 00002693 _____ C:\Users\Customer\Desktop\Microsoft Office Word 2007.lnk
2015-12-04 12:04 - 2015-12-04 12:04 - 00002655 _____ C:\Users\Customer\Desktop\Microsoft Office Excel 2007.lnk
2015-12-04 11:57 - 2015-12-04 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-12-04 11:53 - 2015-12-04 11:53 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2015-12-04 11:52 - 2015-12-04 11:52 - 00000000 ____D C:\Windows\PCHEALTH
2015-12-04 11:47 - 2015-12-04 11:47 - 00000000 ____D C:\Program Files\Microsoft Office
2015-12-04 11:47 - 2015-12-04 11:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2015-12-04 11:46 - 2015-12-08 17:47 - 00000000 ____D C:\Users\Customer\AppData\Local\Microsoft Help
2015-12-04 11:33 - 2015-12-24 15:16 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-04 11:33 - 2015-12-04 11:33 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-04 11:33 - 2015-12-04 11:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-04 11:33 - 2015-12-04 11:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-04 11:33 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-04 11:33 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-04 11:33 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-04 11:22 - 2015-12-04 11:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-12-04 11:22 - 2015-12-04 11:22 - 00000000 ____D C:\ProgramData\ESET
2015-12-04 11:22 - 2015-12-04 11:22 - 00000000 ____D C:\Program Files\ESET
2015-12-04 11:21 - 2015-12-02 10:48 - 90342088 _____ (ESET) C:\eav_nt64_enu.exe
2015-12-04 11:18 - 2015-12-04 11:18 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenuEX
2015-12-04 11:18 - 2015-12-04 11:18 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
2015-12-04 11:18 - 2015-12-04 11:18 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2
2015-12-04 11:18 - 2015-12-04 11:18 - 00000000 ___HD C:\ProgramData\CanonEPP
2015-12-04 11:17 - 2015-12-12 22:07 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-12-04 11:17 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMAA.DLL
2015-12-04 11:16 - 2010-03-18 19:26 - 00348672 _____ (CANON INC.) C:\Windows\system32\CNC280L.dll
2015-12-04 11:16 - 2010-03-18 19:25 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC280L.dll
2015-12-04 11:16 - 2010-03-18 17:13 - 01354240 _____ (CANON INC.) C:\Windows\system32\CNC280C.dll
2015-12-04 11:16 - 2010-03-18 17:13 - 00112128 _____ (CANON INC.) C:\Windows\system32\CNC280I.dll
2015-12-04 11:16 - 2010-03-18 17:11 - 00106496 _____ (CANON INC.) C:\Windows\SysWOW64\CNC280U.dll
2015-12-04 11:16 - 2009-11-13 14:38 - 00012800 _____ C:\Windows\SysWOW64\CNC1746D.TBL
2015-12-04 11:16 - 2009-11-13 14:38 - 00012800 _____ C:\Windows\system32\CNC1746D.TBL
2015-12-04 11:16 - 2008-08-25 18:02 - 00017920 _____ (CANON INC.) C:\Windows\system32\CNHMCA6.dll
2015-12-04 11:16 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2015-12-04 11:09 - 2015-12-04 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP280 series User Registration
2015-12-04 11:09 - 2015-12-04 11:09 - 00000000 ____D C:\ProgramData\CanonIJMSetup
2015-12-04 11:08 - 2015-12-04 11:08 - 00002079 _____ C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
2015-12-04 11:08 - 2015-12-04 11:08 - 00000000 ____D C:\ProgramData\CanonIJWSpt
2015-12-04 11:08 - 2015-12-04 11:08 - 00000000 ____D C:\Program Files\Common Files\CANON
2015-12-04 11:07 - 2015-12-04 11:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-12-04 11:07 - 2015-12-04 11:07 - 00002358 _____ C:\Users\Public\Desktop\Canon MP280 series On-screen Manual.lnk
2015-12-04 11:07 - 2015-12-04 11:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP280 series Manual
2015-12-04 11:07 - 2015-12-04 11:07 - 00000000 ____D C:\Program Files\Canon
2015-12-04 11:06 - 2015-12-04 11:06 - 00000000 ___HD C:\Windows\system32\CanonIJ Uninstaller Information
2015-12-04 11:06 - 2015-12-04 11:06 - 00000000 ___HD C:\ProgramData\CanonBJ
2015-12-04 11:06 - 2015-12-04 11:06 - 00000000 ___HD C:\Program Files\CanonBJ
2015-12-04 11:06 - 2015-12-04 11:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP280 series
2015-12-04 11:06 - 2010-03-11 03:57 - 00248320 _____ (CANON INC.) C:\Windows\system32\CNMIUAA.DLL
2015-12-04 11:05 - 2015-12-04 11:09 - 00000000 ____D C:\Program Files (x86)\Canon
2015-12-03 19:02 - 2015-12-03 19:02 - 00001351 _____ C:\Users\Customer\Desktop\Sticky Notes.lnk
2015-12-03 19:02 - 2015-12-03 19:02 - 00001230 _____ C:\Users\Customer\Desktop\Calculator.lnk
2015-12-02 17:20 - 2015-12-02 17:20 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-12-02 17:20 - 2015-12-02 17:20 - 00000000 ___SD C:\Windows\system32\GWX
2015-12-02 17:20 - 2015-11-20 13:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-12-02 17:20 - 2015-11-20 13:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-12-02 17:20 - 2015-11-20 13:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-12-02 17:20 - 2015-11-20 13:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-12-02 17:20 - 2015-11-20 13:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-12-02 17:20 - 2015-11-20 13:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-12-02 17:20 - 2015-11-20 13:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-12-02 17:20 - 2015-11-20 13:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-12-02 17:20 - 2015-11-20 13:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-12-02 17:20 - 2015-10-08 18:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2015-12-02 17:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2015-12-02 17:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2015-12-02 17:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2015-12-02 17:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2015-12-02 17:20 - 2015-10-08 18:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2015-12-02 17:20 - 2015-10-08 18:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2015-12-02 17:20 - 2015-10-08 18:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2015-12-02 17:20 - 2015-10-08 14:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
2015-12-02 17:20 - 2015-10-08 13:52 - 00419928 _____ C:\Windows\system32\locale.nls
2015-12-02 17:18 - 2015-10-29 12:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-12-02 17:18 - 2015-10-29 12:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-12-02 17:18 - 2015-10-29 12:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-12-02 17:18 - 2015-10-29 12:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-12-02 17:18 - 2015-10-29 12:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-12-02 17:18 - 2015-10-29 12:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-12-02 17:18 - 2015-10-29 12:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-24 19:10 - 2009-07-13 22:20 - 00000000 ____D C:\Windows
2015-12-24 18:54 - 2015-11-15 20:01 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-24 18:26 - 2009-07-13 23:45 - 00019504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-24 18:26 - 2009-07-13 23:45 - 00019504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-24 18:15 - 2015-11-15 20:04 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-24 14:56 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2015-12-24 14:15 - 2009-07-14 00:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-24 14:15 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2015-12-24 11:15 - 2015-11-15 20:04 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-24 07:56 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-22 16:20 - 2009-10-27 17:42 - 00000000 ____D C:\Users\Customer
2015-12-16 16:18 - 2015-11-15 20:05 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-15 23:40 - 2015-11-15 20:04 - 00000000 ____D C:\Users\Customer\AppData\Local\Google
2015-12-10 10:58 - 2015-11-15 20:01 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-10 10:58 - 2015-11-15 20:00 - 00000000 ____D C:\Users\Customer\AppData\Local\Adobe
2015-12-10 10:57 - 2015-11-15 20:01 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-10 10:57 - 2015-11-15 20:01 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-09 23:28 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2015-12-09 11:09 - 2009-07-13 23:45 - 00409624 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-09 11:05 - 2015-10-28 08:17 - 00000000 ____D C:\Windows\system32\MRT
2015-12-09 11:00 - 2015-10-28 08:16 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-07 08:52 - 2009-07-14 00:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-12-06 20:29 - 2015-10-27 17:59 - 00000000 ____D C:\Users\Customer\AppData\Local\Ahead
2015-12-06 20:29 - 2015-10-27 17:54 - 00000000 ____D C:\Users\Customer\AppData\Roaming\Ahead
2015-12-05 16:31 - 2009-10-27 18:32 - 00000000 ____D C:\Users\Customer\AppData\Roaming\Adobe
2015-12-05 09:15 - 2015-11-15 20:04 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-05 08:47 - 2009-10-27 17:43 - 00000000 ____D C:\Users\Customer\AppData\Local\VirtualStore
2015-12-05 07:17 - 2015-10-28 11:12 - 00000000 ____D C:\ProgramData\Adobe
2015-12-04 12:03 - 2015-10-28 17:53 - 00109296 _____ C:\Users\Customer\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-04 12:00 - 2009-07-14 02:45 - 00000000 ____D C:\Windows\ShellNew
2015-12-04 12:00 - 2009-07-13 21:34 - 00000499 _____ C:\Windows\win.ini
2015-12-04 11:53 - 2015-10-28 11:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-12-04 11:53 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-12-04 11:51 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Help
2015-12-04 11:48 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-12-04 11:16 - 2009-07-13 22:20 - 00000000 __RSD C:\Windows\Media
2015-12-04 11:10 - 2015-11-15 20:04 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-04 11:10 - 2015-11-15 20:04 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-03 18:56 - 2015-11-15 19:56 - 00000000 ____D C:\Users\Customer\AppData\Local\lptmp1906871756
2015-12-02 13:18 - 2015-11-16 12:04 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2015-11-15 19:56 - 2015-11-15 19:56 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe

Some files in TEMP:
====================
C:\Users\Customer\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Customer\AppData\Local\Temp\ose00000.exe


Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\dlumd10.dll
C:\Windows\SysWOW64\dlumd11.dll
C:\Windows\SysWOW64\dlumd9.dll
C:\Windows\SysWOW64\dlumdfb10.dll
C:\Windows\SysWOW64\dlumdfb11.dll
C:\Windows\SysWOW64\dlumdfb9.dll
C:\Windows\System32\dlumd10.dll
C:\Windows\System32\dlumd11.dll
C:\Windows\System32\dlumd9.dll

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-12-20 12:32

==================== End of FRST.txt ============================
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 12:51:55 AM
Quote from: v_v on December 25, 2015, 12:15:09 AM
Linda,

So you are running an administrator account, and you are running the Windows Firewall.

For the moment we will leave Windows Firewall alone.  My guess is that it is doing its job satisfactorily.

Since IE 11 and Chrome do work for "familyresearch.org" on your computer, use each of those browsers and go to the web site.  Then just like you did with Firefox post screen shots of the certificates from IE 11 and Chrome.  Since these two browsers do work at the web site (without the .jpg images of course), a comparison of their certificates with those of Firefox might provide some useful data.

v_v

I'll try.  But I'm not sure how to get to finding the certificates if the sites work normally.  In Firefox the box popped up and I could see them. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 01:00:58 AM
To v_v for the certificate for Familysearch.org:

I found it on Chrome, and I have done a screen print. 

I went into IE11 and clicked in the same place I clicked in Chrome, but I didn't not see anything that would be for certificates????  So, here is only my screen print for Chrome with some certificate information.  If someone can tell me how to find the same information in IE11, I can try again.  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 01:11:44 AM
For v_v,

Okay, I went back into IE11 and left clicked on that gold lock icon I think it was and saw the words 'security report' so I found it and it looks to be the same as Chrome for Familysearch.org in Chrome.  So, here is the screen print for IE11. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 25, 2015, 01:21:12 AM
Linda,

[Edit:  I see that you have found both of them now.  So concentrate on the "Details" tab as indicated below.]

In both Chrome and IE 11 click on the lock that shows up in the address bar.  In IE 11 the pop up will say view certificates.  Click for the next screen and then click the "Details" tab.  In the top window find "Issuer" and just click to highlight it.  What will happen is that the details for that line will show in the bottom window.  Post the result.

In Chrome you have already done most of the work.  So now just click the tab "Details", find "Issuer" - click to highlight it, and then post the results.

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 01:26:56 AM
Hi, Linda.

The logs do look alike so it can be confusing -- to me as well if I'm not looking closely. 

1.  Anyway, I did find something about the certificates that relates to the error on IE and the image you posted from Chrome confirms it is an SSL Cert and not TLS:
Quote
A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10001.

Many of the errors were prior to the computer being set up for your account so nothing to worry about.  For the error above, I've copied the solution from schannel, eventID-36870 and security auditing eventID - 5061, they - Microsoft Community (http://answers.microsoft.com/en-us/ie/forum/ie8-windows_7/schannel-eventid-36870-and-security-auditing/9a2329de-105f-499b-8442-08722b91d844):

QuotesChannel uses TLS(Transport Layer Security) for security encryption. As long as the sites you visit do not use TLS.
 
Try these steps:
1. Open Internet Explorer.
2. Press the ALT key and then click Tools.
3. Click Internet Options.
4. Click Advanced tab.
5. Scroll down the list under Security, uncheck all the Use TLS options.
6. Click OK.
 
Now restart the computer and check if the issue still occurs.

That should take care of the errors in the Addition.txt log.

2.  Your log shows the a number of items disabled via MSConfig.  Since you use WinPatrol, I'm not sure why they were disabled that way.  From Using System Configuration (msconfig) - Windows Help (http://windows.microsoft.com/en-us/windows/using-system-configuration#1TC=windows-7):

QuoteSystem Configuration is a tool that can help identify problems that might prevent Windows from starting correctly. You can start Windows with common services and startup programs turned off and then turn them back on, one at a time. If a problem doesn't occur when a service is turned off, but does occur when that service is turned on, then the service could be the cause of the problem.

System Configuration is intended to find and isolate problems, but it's not meant as a startup management program. {Bold added}

In other words, MSConfig is useful for troubleshooting but not for managing startup programs.  Using MSConfig can lock malware in the registry, only to become apparent should it be restored to normal start up. In addition, there is no automated way of changing the setting.  Each has to be done manually, which is what I suggest that you do:  Click start, type msconfig in the search box, open msconfig, click on the start up tab. Put a check mark in each entry, reboot the computer.

3.  There are some leftover Webroot things we can take care of with FRST.  (Yes, I recall the discussion in the WinPatrol Facebook group about the A/V the computer person wanted to install :) )

Please do the following to run FRST:

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

start
CreateRestorePoint:
CloseProcesses:
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll => No File
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll => No File
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll No File
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll No File
C:\ProgramData\WRData
2015-11-15 19:56 - 2015-11-15 19:56 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
EmptyTemp:
end
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 01:33:58 AM
For v_v:

Okay, here are screen prints for IE11 and Chrome for the issuers. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 01:44:40 AM
Hi Corrine,

Thank you for all you have done.  It is going to take me a while to plow through all you have presented to me now.  And, yes, I am a bit fearful of making a mistake myself with all of these steps.   I probably won't get to all of this until maybe tomorrow, but being that this is Christmas Eve and tomorrow is Christmas, I'm sure you all need a break from this exchange; and I apologize that it has turned into such a lengthy and involved one. 

I did have a concern about:

"Channel uses TLS(Transport Layer Security) for security encryption. As long as the sites you visit do not use TLS."

Maybe I am not understanding the actual meaning for this statement, but if I visit a TLS site, then what would happen?

Yes, this Windows 7 is a refurbished computer; and now I think I'm beginning to see the pitfalls of getting one that isn't new.  It seems that there are a lot of 'left over' type elements, and yes that webroot is one.  I did see that Webroot is in IE11 and I wondered if it is just a part of it and you have to keep some of it or maybe something could malfunction is you got rid of every last bit of it on your computer?  I don't know.  Then I read somewhere how Webroot wouldn't interfere anyway with your antivirus. 

So much for me to comprehend and I have to go slow because if I somehow make a mistake then it is going to cost me to have to bring either the guy back who I bought this computer from or someone new.  I trust what all of you are telling me to do, but I am not that trustfull of myself that I might make a mistep in the process. 
 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 01:49:48 AM
Let's wait to see what v_v has to say before making the change in #1 and, by all means, take your time! 
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 25, 2015, 02:03:13 AM
Linda and Corrine,

No, don't wait on me.  So far I did not see any differences between the certificate details of Firefox on the one hand and IE 11 and Chrome on the other.  I was hoping to find something in the latter two that was not in Firefox.  But the images that Linda posted do not immediately show any glaring differences.  So why those two browsers work on the site but Firefox does not remains a mystery.

On the other hand I think that the images problem with IE 11 and Chrome is a different problem with a different source.

But by all means go ahead with whatever Corrine suggests would be useful.

Corrine, when you go to the web site in question with both Firefox and Pale Moon, and view your browser certificates for that site, what entity is the issuer for your two browsers?

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 02:27:33 AM
I'm re-thinking the change suggested in #1.  I guess it is worth trying and it could be changed back if it doesn't solve the problem. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 02:47:08 AM
Hi Corrine and v_v,

Thank you both so much.  Do you think it would be a good idea to do a restore point on my computer before I attempt anything else?  I am just fearful to some degree, at least, of making things worse.  At least most of the computer is working okay that I need.  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 25, 2015, 06:10:22 AM
Linda,

Okay, stop the presses!!!

No guarantees but I think that we are closer to a solution!  As I suspected there is a problem with ESET and Firefox, and ESET knows about it.  I did a search on "ESET certificates Firefox compatibility".  There are many informative links from this search.  Essentially paraphrasing what seems to be the issue, ESET may substitute its own certificates for the web sites true certificates.  This causes problems with some browsers primarily Firefox in your case.  This is why your certificates for that web site all appear to be from ESET whereas mine are from DigiCert Inc.

This first link will give you information:  " https://support.mozilla.org/en-US/questions/932033 ".  This is from 2012.

The second link gives similar info from May 2015:  " https://support.mozilla.org/en-US/questions/1064455 ".

These two links above are from Mozilla (Firefox) Support.

The third and fourth links below come from ESET Security Forum.

The third link points to a solution page:  " https://forum.eset.com/topic/1388-ssl-web-sites-do-not-open/ ".  This is from November 2013

The fourth link is the ESET solution page stating "KB Solution ID: KB3126 |Document ID: 14085|Last Revised: December 11, 2015":  " http://support.eset.com/kb3126/?viewlocale=en_US ".

In this fourth link solutions are presented with screen shots, plus there is a link to "contact ESET Customer Care."

I would read through the first three links just to get a better idea of what is going on before attempting the solution(s) in the fourth link.  Also feel free  to browse through some of the other links in the search if you feel that they would help you.  I thought that the four that I chose would be enough.

Certainly a restore point could be helpful and it would not hurt.

Even if this fixes your immediate problem you might still want to work with Corrine on the clean-up issues.

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 02:37:35 PM
You are quite the detective, v_v!  Good work. 

As to creating a restore point first, it is always a good idea before making any changes.  Linda, I suggest you do that and then follow the instructions in the ESET, December 11, 2015 KB3126 article.  FRST will create a restore point before removing the leftovers from Webroot.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 04:22:06 PM
Hi v_v and Corrine,

Thank you both, and I apologize for falling behind here in my reply to you both.  Christmas sort of took some time away from me so far today.  Yes, I did contact ESET Customer Care, and have a ticket number with them, but no reply yet from them.  At the time, I guess I did not do the searching as diligently as you have to find those links that you have so kindly shared with me here.  I am taking this one step at a time.  Yes, I am hearing this certificate issue is a problem, but of course I may have a few other 'glitches' beyond ESET to deal with. 

But, I am printing all of these instructions out from you both and going to work on more of them yet.  Thank you and hope you are having a great Christmas today.
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 04:54:09 PM
Take your time, Linda, and enjoy the day.  Merry Christmas!
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 06:08:15 PM
Thank you Corrine, and the same to you and your family.  Thank you for all of your time and help; so much!!  This is a fabulous helpful forum and I am so glad you pointed me to it. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 06:33:01 PM
This is for Corrine, and with regard to your #3 step about Webroot and FRST. 

I had saved these instructions earlier.  The person I bought the computer from just did the regular uninstall of Webroot.  I did not do anything further after that.  I did see some Webroot references like a tool bar I think in IE11 and thought if it is part of Internet Explorer maybe it would mess things up if I completely eradicated it from my computer, so with that thought in mind, I held off going any further to remove any traces of Webroot. 

But, here are the instructions I kept and I wondered should I try to remove what is left of webroot with the WRUpgradetool.exe before doing the FRSTsteps for it? 

"Trouble Installing or Uninstalling?"

"Most install or uninstall errors can be resolved by either uninstalling any previously installed Webroot security software or by running a couple of specialized cleanup utilities first and then reinstalling anew. The following are the recommended steps to follow:
1.   In Windows XP click on the Start button and open the Control Panel, select "Add or Remove Programs", and then select the 'Webroot' security product from the list and click 'Remove'. Restart your computer after the uninstall is complete.

In Windows Vista or Windows 7, click on the Start button and open the Control Panel. You will see either "Uninstall a Program" or "Programs and Features" - double-click whichever option you see. Select the 'Webroot' security product from the list and click 'Uninstall'. Restart your computer after the uninstall is complete.

Note: If you receive an error during this step, please proceed to Step 2; otherwise you may skip ahead to Step 5 below.
2.   Please note: It is highly recommend that you only perform Steps 3 through 6 after first creating a System Restore Point described in this step. Ensuring that the Windows built-in System Restore feature is enabled and that regular restore points are created can be very valuable in the event that restoring to an earlier time is needed.

o   To create a System Restore Point in Windows XP go to Start > All Programs > Accessories > System Tools > System Restore > Create a restore point.
o   In Windows Vista and Windows 7, go to Start > right-click on Computer > choose Properties > Select System protection from the left-hand panel > and choose Create.
3.   After you have created the recommended System Restore Point, download and Save the Webroot WRUpgradeTool.exe upgrade/cleanup tool to your Desktop by clicking here, or by copying and pasting the following URL into your Internet browser's address bar:
http://download.webroot.com/WRUpgradeTool.exe

Note: Running the WRUpgradeTool.exe utility can benefit those that had previously installed or attempted to install Webroot's security software, and may still have residual installed files that may be interfering with the current installation attempt.
4.   Double-click on the Webroot Upgrade/Cleanup tool WRUpgradeTool.exe to run, and follow the prompts to start the uninstall process. The cleanup tool is finished when the last line reads "Removal procedures have been completed." At this point you can click the Close button. If prompted by a dialog box that reads "To complete the cleanup process, you must reboot this computer. Click OK to reboot," please restart you computer now by clicking on the OK button now."

No hurry to answer today, Corrine.  Thanks! 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 06:49:54 PM
Your choice, Linda.  You can create a restore point and download the WRUpgradeTool.exe or go to Step #3 and copy the script and run it as instructed.  FRST will create a restore point, remove the Webroot leftovers and clear temp files.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 07:06:20 PM
Hi Corrine.  Thank you.  I remember what you wrote about programs like CCLeaner and I saved the information about not trusting them to 'clean up temp files' so you feel FRST is trustworthy for cleaning up the correct temp files? 

I did create a restore point about an hour ago.  Do you have to wait a day or no before making changes?  I am not sure when the restore will work; if there is a wait time before we know for sure that the computer will restore to that date and time.  Thank you. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 09:05:55 PM
The System Restore point is immediately available.  Plus, FRST will create a fresh restore point prior to removing the Webroot leftover files.  CCleaner is ok for cookies and temp files but it is not recommended for the registry.  Yes, I most definitely trust FRST for cleaning the correct Temp files, although it is not something I would recommend you attempt on your -- only with the instructions I have provided. 

To save you toggling back to the instructions, I've repeated them below:

Please do the following to run FRST:

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

start
CreateRestorePoint:
CloseProcesses:
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll => No File
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll => No File
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll No File
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll No File
C:\ProgramData\WRData
2015-11-15 19:56 - 2015-11-15 19:56 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
EmptyTemp:
end
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 09:20:24 PM
Hi Corrine.  I have a couple of questions regarding the FRST.exe, don't I first have to find where it is located on my computer before I can save the notepad file to the proper one where it is at?  It seems I only have FRST.exe either as a download or on my desk top.  I typed it in for a search and I am posting my results here.  So, right now I am not sure how to find the folder/directory that FRST is in.  So that is my first question.

So, am I to be running FRST first; or copy and pasting the test in Notepad?  Of course, I can't do that until I find where FRST is located on my computer.   The FRST is on my desktop. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 09:45:14 PM
Okay, I checked and the only place that the FRST was at was in the folder for the desktop, so I saved your code in the notepad by the proper name, etc. and then ran the Fix in the FRST, and the one thing that happened I was not expecting was that I had to do a restart, which I did, but it had asked me to close other files which I didn't know how to do without getting out of it.  So, did the restart, and it seemed to work okay as I am back here now.  Chrome had to be restarted and I lost the tabs that were up there.

So, it created a file and I opened it up and below is the contents from teh Fixlist.txt:

Fix result of Farbar Recovery Scan Tool (x64) Version:23-12-2015
Ran by Customer (2015-12-25 16:30:27) Run:1
Running from C:\Users\Customer\Desktop
Loaded Profiles: Customer (Available Profiles: Customer)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll => No File
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll => No File
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll No File
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll No File
C:\ProgramData\WRData
2015-11-15 19:56 - 2015-11-15 19:56 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
EmptyTemp:
end
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c8d5d964-2be8-4c5b-8cf5-6e975aa88504}" => key removed successfully
"HKCR\CLSID\{c8d5d964-2be8-4c5b-8cf5-6e975aa88504}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c8d5d964-2be8-4c5b-8cf5-6e975aa88504}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{c8d5d964-2be8-4c5b-8cf5-6e975aa88504}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{97ab88ef-346b-4179-a0b1-7445896547a5} => value removed successfully
"HKCR\CLSID\{97ab88ef-346b-4179-a0b1-7445896547a5}" => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{97ab88ef-346b-4179-a0b1-7445896547a5} => value removed successfully
"HKCR\Wow6432Node\CLSID\{97ab88ef-346b-4179-a0b1-7445896547a5}" => key removed successfully
"C:\ProgramData\WRData" => not found.
C:\Program Files (x86)\Common Files\wruninstall.exe => moved successfully
EmptyTemp: => 1.7 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 16:31:52 ====
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 25, 2015, 10:39:45 PM
For ESET:

Did all of these steps in ESET:

http://support.eset.com/kb3126/?viewlocale=en_US

Went into Firefox, and still no luck with either Family search or my blog. 

I am attaching a screen print showing what I saw when I tried to access my blog.  Familysearch.org isn't coming up either correctly, but it shows that goofy looking screen as before.  I hope ESET people contact me so I can tell them I took these steps now too, and they didn't help.  I also did a restart after I did them. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 25, 2015, 10:48:19 PM
Hi, Linda.

In addition to removing the leftover Webroot files, see what else FRST removed => 1.7 GB temporary data Removed!

Let's take care of removing the tools used:

Please download Delfix from here (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix).

Ensure the following boxes are checked:
The program will run for a few moments and then notepad will open with a log.   Please paste the log in your next reply.

With it being a holiday, I'm sure ESET support will get to you as quickly as they catch up.  After running Delfix, I think that you should stop at this point and not make any additional changes to your computer.  Then, after you have worked with ESET support, return and let us know the solution since it could help someone else. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 26, 2015, 12:06:56 AM
Hi Corrine,

So, I guess we are at the end of the line now with this.  I took all those steps.  Those temporary files, how do I keep them from building up in the future? 

By purging the restore points, does that mean that all of my restore points I had are gone?  Is that okay should I have a new problem now then I don't have an old restore point to go back to? 

Here are the results:

# DelFix v1.011 - Logfile created 25/12/2015 at 19:03:40
# Updated 18/08/2015 by Xplode
# Username : Customer - LINDAJEANLIMESE
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\Users\Customer\Desktop\Addition.txt
Deleted : C:\Users\Customer\Desktop\Fixlog.txt
Deleted : C:\Users\Customer\Desktop\FRST.txt
Deleted : C:\Users\Customer\Desktop\FRST64.exe
Deleted : C:\Users\Customer\Downloads\Addition.txt
Deleted : C:\Users\Customer\Downloads\FRST (1).exe
Deleted : C:\Users\Customer\Downloads\FRST.exe
Deleted : C:\Users\Customer\Downloads\FRST.txt
Deleted : C:\Users\Customer\Downloads\FRST64 (1).exe
Deleted : C:\Users\Customer\Downloads\FRST64.exe
Deleted : C:\Users\Customer\Documents\Downloads\dds(1).scr
Deleted : C:\Users\Customer\Documents\Downloads\SystemLook.exe
Deleted : C:\Users\Customer\Documents\Downloads\SystemLook.txt
Deleted : C:\Users\Customer\Documents\Downloads\TFC.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #30 [Windows Update | 12/15/2015 17:20:02]
Deleted : RP #31 [RESTORE TO DECEBER 16 2015 | 12/16/2015 20:45:12]
Deleted : RP #32 [Windows Update | 12/19/2015 02:38:01]
Deleted : RP #33 [Windows Update | 12/22/2015 23:06:31]
Deleted : RP #34 [Removed Java 8 Update 66 | 12/22/2015 23:52:27]
Deleted : RP #35 [Before Webroot removal | 12/25/2015 18:24:26]
Deleted : RP #37 [Restore Point Created by FRST | 12/25/2015 21:30:30]
Deleted : RP #38 [Windows Update | 12/25/2015 23:11:40]

New restore point created !

########## - EOF - ##########
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 26, 2015, 12:43:16 AM
Part of the process included:  New restore point created !

Temp files will build up but you can periodically (every couple weeks or so) run TFC, which works on Windows XP/Vista/7 and can run on both a 32-bit and 64-bit OS.  Following are the instructions. 

Download TFC (http://oldtimer.geekstogo.com/TFC.exe) to your desktop
Please let us know the results of your ESET support ticket.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 26, 2015, 12:58:56 AM
Hi Corrine,

Thank you.  I have bumped into this TFC cleaner before actually, but shied away from using it because of some of the comments about problems that others had including how extensions on their files were removed.  I know I spent quite a lot of time making sure the .doc, .docx, extensions were showing, so I would not want to lose those.  I think I'm going to hold off on doing anything with it for awhile since so many of these temp. files were cleaned out today.  I get confused as I see temporary internet files and other temp. files, so I wish I understood all of those better.  Thank you for sharing, Corrine.  Yes, I will report what ESET tells me.  I also posted in Firefox foums just now, but I do not think I will get too much help; surely not as much as I recieved here.   
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 26, 2015, 01:42:35 AM
TFC does not remove or change extensions.  It is very safe to use.  If someone saves .doc or .docx files in a temporary folder, the files would be removed but that would happen with any temp file cleaner. Following is what TFC does:

Before running, it will stop Explorer and all other running applications. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files.
-- TFC only cleans temp folders.
-- TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail.

TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 26, 2015, 02:11:32 AM
Hi Corrine,

Thank you.  I'll it a try.  I appreciate your help! 
Title: Re: Firefox Problems - Untrusted Websites
Post by: satrow on December 26, 2015, 10:36:08 AM
Great work Corrine and Linda  8)

v_v, you should be awarded the Order of the Silver Spade avatar in appreciation of your data digging abilities :)

Quote from: JDBush61 on December 24, 2015, 03:12:33 PM
Quote from: satrow on December 24, 2015, 10:37:30 AM
I don't recall the last time a website suggested that I should switch to an x86 browser, if at all!

So, are you suggesting that I'm doing something wrong? On my Sony Vaio laptop (2010 model), both browsers state that they are "x86 en-US". My Sony is Win 7 64 bit. Something amiss, maybe? Should I change something?
Nothing wrong there, JD, you are in the majority using default x86 browsers with an x64 OS. I was pointing out that websites are, or should be, essentially agnostic to the 'bitness' of the browser.
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 29, 2015, 12:15:00 AM
I am sorry that is a long time coming, but ESET just replied this afternoon.  I thought I had taken these steps earlier, but right now my mind is in a fog over all that was done; so I took the steps outlined below in the most current version of Firefox, IE11, and Chrome, and thank goodness the Familysearch.org site and my blog worked correctly in all 3 of them:

Update for Case #1387566 - "Untrusted website pop ups in Firefox -- cannot access"

An ESET Customer Care Representative has updated this case with the following information:

Hello,

Thank you for your reply.

We have had several reports of webpages not loading properly due to SSL filtering. This feature was disabled by default in version 8 but enabled in version 9.

Please follow the steps below to disabling SSL filtering in ESET NOD32 Antivirus version 9:

1. Open your ESET product.

2. Press F5 to enter Advanced setup.

3. Click Web and email, expand SSL/TLS, click the slider bar to disabled next to Enable SSL/TLS protocol filtering and then click OK.

You should now be able to access web pages that use SSL certificates without interference.

For illustrated instructions on this process, please follow steps #1 through #4 in the article below:

http://support.eset.com/kb3126/

If this does not resolve your issue, please contact us via chat support.

To expedite your service, ESET Customer Care agents are available via online chat from 5:15AM to 6:45PM Pacific time Monday-Friday. Click or copy/paste the link below into your web browser to visit the ESET Customer Care page. Complete the 'Issue Submission' section of the page and click 'Submit' to connect to an agent.

----------------------------------------------------------------
ESET North America Chat Support:
https://helpus.eset.com/
----------------------------------------------------------------

Thank you for using ESET security products,
ESET Customer Care
North America
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 29, 2015, 12:23:28 AM
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fwww.sysnative.com%2Fforums%2Fimages%2Fsmilies%2Fdance.gif&hash=71830305f0ce376017010140543acc31befd60b8)

I'm so glad it was resolved!
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 29, 2015, 12:29:34 AM
Hi Corrine,

Yes, so am I; and thank you hugely to you and v_v for all of your help.  It was definitely a learning experience for me too! 
Title: Re: Firefox Problems - Untrusted Websites
Post by: v_v on December 29, 2015, 12:35:59 AM
Linda,

There we go!  I had one other thought up my sleeve and then there was always the alternate solution of trying a different antivirus product.  But now that ESET has done their job, kudos to them for getting this fixed and also for answering you fairly quickly (considering the holidays and all).

Satrow,

It was your diagnosis that help me to zero in on my particular focus.  So you deserve some of that award too!  (Smile)


Fixed problems always bring good cheer!  A happy new year to all involved!!

v_v
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 29, 2015, 12:44:41 AM
Thanking everyone who helped me!  Happy New Year to everyone here; LandsDown is a wonderful forum and I am so glad I found it. 
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 29, 2015, 01:18:26 AM
As you've seen, we can do so much more here than in the WinPatrol Facebook group.  :)
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 29, 2015, 01:44:36 AM
Hi Corrine,

Yes, definitely, and I apologize for bothering you all there.  Thank you for all of your help here!
Title: Re: Firefox Problems - Untrusted Websites
Post by: Corrine on December 29, 2015, 02:32:59 PM
No bother, Linda.  Besides, it got you here!  :)
Title: Re: Firefox Problems - Untrusted Websites
Post by: LindaEllis on December 29, 2015, 04:04:36 PM
I believe I have posted here with other questions in the past, but not recently until this latest one.