1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

In Progress All browsers slow but good connection speed

Discussion in 'Virus & Other Malware Removal' started by Larrylowtech, Dec 13, 2015.

Thread Status:
Not open for further replies.
Advertisement
  1. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    Thanks for all your patient help in the past and, hopefully, this time.
    It was recommended that I post here after this thread.

    "I have a Windows 7 64 bit Home Premium computer between 2 and 3 years old.

    Internet Explorer is my preferred browser and I am up to date with IE 11. (I know)
    I also use Chrome and Firefox.
    For a while now, they all are very sluggish to non-responsive.

    I have Windstream DSL and it's 12 Mbs and runs fairly close to the stated speed most of the time.
    Some things I do that helps some but only temporarily are:
    Run Malwarebytes and it always comes up clean.
    Run Superantispyware and usually get several hundred adware things which I clean.
    I have run Ccleaner way more than I ever have.

    Examples of issues are:
    In IE, I get frequent page is not responding or just freezing up.

    I have just started "casting" from Chrome to my Chromecast.
    From my computer, the playback is jerky.
    From a different computer it plays fine.

    This is frustrating.
    Otherwise the computer functions fairly well.
    I keep it clean of garbage but still having this issue that has been terrible for about a week now"

    Tech Support Guy System Info Utility version 1.0.0.2
    OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
    Processor: Intel(R) Pentium(R) CPU G630 @ 2.70GHz, Intel64 Family 6 Model 42 Stepping 7
    Processor Count: 2
    RAM: 6050 Mb
    Graphics Card: Intel(R) HD Graphics Family, -1988 Mb
    Hard Drives: C: Total - 1418842 MB, Free - 512587 MB; D: Total - 11851 MB, Free - 1418 MB;
    Motherboard: PEGATRON CORPORATION, 2AC2
    Antivirus: Microsoft Security Essentials, Updated and Enabled
     
  2. askey127

    askey127 Malware Specialist

    Joined:
    Dec 22, 2006
    Messages:
    3,722
    Hi Larry,
    Don't ever use a Registry Cleaner/Optimizer/Helper/Fixer, no matter what suggestions you get.
    They are dangerous, and can trash your machine.
    That goes for CCleaner's Registry Cleaner, or anybody else's..
    -----------------------------------------------------------
    Slowdowns Related to the Windows 10 Update Process
    There is a lot of activity associated with Microsoft's attempts to convert everybody to Windows 10.
    The activity includes delivery of large downloads, machine scans, and sending resulting telemetry data to Microsoft.
    In some cases, the downloading and data collection processes can slow down a machine noticeably.

    -----------------------------------------------------------
    About Windows 10
    Windows 10 is OK to use and convenient, but very, very, VERY snoopy.
    All the software and installed programs on a Windows 10 machine are essentially under the control of Microsoft.
    ... and W10 does not allow many changes from what it decides.
    Most currently installed programs will probably work OK after a conversion, but a few may not.
    As has happened with other Windows versions, there has been some trouble with printers and scanners.

    -----------------------------------------------------------
    Run GWX Control Panel
    If Microsoft's attempts to force Windows 10 onto the machine are unwanted, you can download and Run GWX Control Panel
    http://ultimateoutsider.com/downloads/
    If you don't disable things with GWX Control Panel, and you are allowing Updates, Windows 10 will get installed automatically, without your permission, early next year.

    Utilizing GWX Control Panel will prevent most of the Windows 10 activities.
    You need to click on any of the four wide buttons that are not grayed out.
    Attempts by Microsoft to circumvent your wishes can be monitored by enabling the Monitor mode button.
    It's possible that you may need to download a newer version of GWX Control Panel later, if Microsoft doesn't get civilized about this.
    Barring sabotage by Microsoft, you should be able to use Windows 7 until 2020.

    We can run a full scan of your machine and pick out any other potential slowdown issues, if you wish.
    Let me know what are your wishes.
    askey127
     
  3. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    Thank you askey127.

    I guess I've been lucky with Ccleaner.
    Although I use the registry cleaner infrequently, I have been using the cleaner part a lot lately.

    I have avoided upgrading to Windows 10 so far because I'm not an early adopter.
    From what I've read, it's the best Microsoft has made in a very long time.
    But, the snoopiness is one thing that's held me back.
    Thanks for those resources.

    I'd like to find out the causes and fixes for these slow downs.
    If you have a scanning resource, I'd like to try to get to the bottom of this
     
  4. askey127

    askey127 Malware Specialist

    Joined:
    Dec 22, 2006
    Messages:
    3,722
    Larry,
    This defragmenter is far better than the one that comes with Windows 7.
    Best to run it right after you clean out the Temp files with CCleaner.
    (Just don't touch CCleaner's Registry button). :D
    -------------------------------------------------------------
    Download MyDefrag from here and Install it : http://filehippo.com/download_mydefrag/
    After Installation, run MyDefrag in System Disk Monthly Mode on the C: drive
    (Click System Disk Monthly and then check C: drive, click Run)
    Wait for it. It goes through 6 Zones.
    It may take as much as an hour or two, depending on how badly the HD is scrambled.
    The Window will be labeled Finished at the top when it is done.
    Going forward, you can run it in System Disk Daily mode, but once every week or two is sufficient.
    It will finish a lot faster in the ensuing runs.

    -----------------------------------------------------------
    Download and Run the Farbar Scan Tool
    • Download FRST64 and save to your Desktop.
    • Double click Frst64.exe to launch it.
    • FRST64 will start to run.
      • When the tool opens click Yes to disclaimer.
      • Press the Scan button.
      • When finished scanning, 2 logs will open on your Desktop, FRST.txt and Addition.txt
      • Please post them in your next reply.
    If you lose track of them, they will be saved in the same location as FRST64.exe
    Feel free to use separate replies if it's more convenient.

    askey127
     
  5. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    Thank you.
    I ran Defraggler the other day but will run this now.

    Edit:
    It gave me a warning when I tried to save FRST64
     
  6. askey127

    askey127 Malware Specialist

    Joined:
    Dec 22, 2006
    Messages:
    3,722
    Ignore the warning.
    Save it somewhere you can find it.
    If a problem, I can tell you how to use Firefox for all this online help and downloads.
     
  7. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    I did.
    Knew you wouldn't give me bad advice.
    Been on Zone 5 for a while now
     
  8. askey127

    askey127 Malware Specialist

    Joined:
    Dec 22, 2006
    Messages:
    3,722
    Let me know how it goes.
     
  9. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    It's still defragging.
    18 hours and at 90% of Zone 6
     
  10. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    I stopped the defrag at 90% of Zone 6 but will start it again tonight before I go to bed.
    Seems it only works while it's the active window.

    Here is FRST.txt:
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:14-12-2015
    Ran by Larry (administrator) on LARRY-HP (15-12-2015 09:20:21)
    Running from C:\Users\Larry\Desktop\FRST 64
    Loaded Profiles: Larry (Available Profiles: Larry)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
    (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
    (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
    () C:\Program Files\Everything\Everything.exe
    (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
    (Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.1.4\LavasoftTcpService.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
    () C:\Program Files (x86)\MoboRobo\MoboroboDeviceService.exe
    (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
    () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Microsoft Corporation) C:\Windows\ehome\ehrec.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Microsoft Corporation) C:\Windows\System32\vds.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_228_ActiveX.exe
    (Google) C:\Users\Larry\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2621240 2015-11-18] (Malwarebytes Corporation)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKLM\...\Policies\Explorer: [HideSCAHealth] 1
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Policies\Explorer: [HideSCAHealth] 1
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\MountPoints2: G - G:\autorun.exe
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\MountPoints2: {652caee2-28a8-11e4-bab9-3860779eebfc} - G:\Setup.exe
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\MountPoints2: {d35e050d-ef2c-11e3-b738-3860779eebfc} - G:\Setup.exe
    ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{02DA41EE-C29F-486F-BA8E-847C330C6B3B}: [NameServer] 8.8.8.8,8.8.4.4
    Tcpip\..\Interfaces\{02DA41EE-C29F-486F-BA8E-847C330C6B3B}: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{282C0FAD-98D3-4DC6-9A93-3801A7A30707}: [DhcpNameServer] 192.168.254.254

    Internet Explorer:
    ==================
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxp://msn.com/
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
    SearchScopes: HKLM-x32 -> {2F3A459B-7524-499E-8D7A-8FAEA68AF860} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
    BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2015-11-19] (Siber Systems Inc.)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
    BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
    BHO-x32: No Name -> {2018eb71-06b5-4438-abf4-e40df31e0be5} -> No File
    BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
    BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2015-11-19] (Siber Systems Inc.)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-17] (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-17] (Oracle Corporation)
    BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
    BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
    Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2015-11-19] (Siber Systems Inc.)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
    Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2015-11-19] (Siber Systems Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Toolbar: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2015-11-19] (Siber Systems Inc.)
    Toolbar: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
    IE Session Restore: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000 -> is enabled.
    DPF: HKLM-x32 {44C1E3A2-B594-401C-B27A-D1B4476E4797} hxxps://login.bradigans.com/XTSAC.cab
    DPF: HKLM-x32 {B79C81C0-7650-4CAB-8466-E14C6A31EBAD} hxxps://login.bradigans.com/SWTSC.cab
    DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2013-04-16] (Belarc, Inc.)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

    FireFox:
    ========
    FF ProfilePath: C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345
    FF DefaultSearchEngine: Bing
    FF DefaultSearchEngine.US: Search Provided by Yahoo
    FF SelectedSearchEngine: Bing
    FF Homepage: hxxp://www.msn.com/
    FF Keyword.URL:
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-09] ()
    FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\system32\npDeployJava1.dll [2013-09-11] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
    FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-17] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-17] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Larry\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-07-20] (Citrix Online)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Larry\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Larry\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @talk.google.com/O1DPlugin -> C:\Users\Larry\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Larry\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Larry\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\Larry\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-09-22] (Zoom Video Communications, Inc.)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: revtrax.com/RevTraxPrintMyCoupon -> C:\Users\Larry\AppData\Roaming\RevTrax\RevTraxPrintMyCoupon\1.0.0.0\npRevTraxPrintMyCoupon.dll [2014-10-15] (RevTrax)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: tokbox.com/OpenTokIE -> C:\Users\Larry\AppData\Roaming\TokBox\otiePluginMain\0.4.0.9\npotiePluginMain_0.4.0.9.dll [2014-12-09] (TokBox)
    FF Plugin HKU\S-1-5-21-1138511476-2251193118-4004913463-1000: tokbox.com/otiePluginInstaller -> C:\Users\Larry\AppData\Roaming\TokBox\otiePluginMain\0.4.0.9\npotiePluginInstaller_0.4.0.9.dll [2014-12-09] (TokBox)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-05-18] (Coupons, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Users\Larry\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
    FF Plugin ProgramFiles/Appdata: C:\Users\Larry\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
    FF Extension: RPNET Download Helper - C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\extensions\[email protected] [2015-07-08]
    FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\extensions\[email protected] [2015-12-07]
    FF Extension: Titan Quick Links - C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\Extensions\[email protected] [2015-02-19] [not signed]
    FF Extension: Video DownloadHelper - C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-10-31]
    FF Extension: Adblock Plus - C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-28]
    FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08]
    FF HKLM-x32\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
    FF Extension: No Name - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2015-11-19] [not signed]
    FF HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://www.google.com/
    CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP","hxxp://google.com/","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium"
    CHR Plugin: (Shockwave Flash) - C:\Users\Larry\AppData\Local\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll => No File
    CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\ppGoogleNaClPluginChrome.dll => No File
    CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\pdf.dll => No File
    CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
    CHR Plugin: (Java(TM) Platform SE 6 U32) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll => No File
    CHR Plugin: (Java Deployment Toolkit 6.0.320.5) - C:\Windows\SysWOW64\npdeployJava1.dll => No File
    CHR Plugin: (Windows Live? Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => No File
    CHR Profile: C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Drive) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-27]
    CHR Extension: (YouTube Center) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcegdpionpopahcglnfiiioapcclamdj [2014-04-04]
    CHR Extension: (Google Cast) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2015-12-12]
    CHR Extension: (Adblock Plus) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-11-25]
    CHR Extension: (APK Downloader) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgihflhdpokeobcfimliamffejfnmfii [2015-11-26]
    CHR Extension: (OneTab) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2014-05-29]
    CHR Extension: (Clear Cache) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cppjkneekbjaeellbfkmgnhonkkjfpdn [2015-03-30]
    CHR Extension: (MightyText - SMS from PC & Text from Computer) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkfhfaphfkopdgpbfkebjfcblcafcmpi [2015-05-07]
    CHR Extension: (Google Docs Offline) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-19]
    CHR Extension: (The Camelizer) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo [2015-10-30]
    CHR Extension: (SMS from Gmail ™ & Facebook™ (MightyText)) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\iffdacemhfpnchinokehhnppllonacfj [2015-11-10]
    CHR Extension: (kaboomly) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcfcepmchbjbeajhljchnbidaikddkif [2015-03-23]
    CHR Extension: (Skype Click to Call) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-10-25]
    CHR Extension: (SocialPinSniper) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\llfojbapbcelaoniflkhioicjmlpileg [2015-02-15]
    CHR Extension: (Video DownloadHelper) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2015-11-19]
    CHR Extension: (Handle for Gmail & Google Apps) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcnamloafopbialjjifhnjhddnnoiim [2015-12-08]
    CHR Extension: (Ghostery) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-09-24]
    CHR Extension: (Facebook UID Grabber) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenpijmfiblklegnjnalakcffmbbbdjg [2014-02-15]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]
    CHR Extension: (RoboForm Password Manager) - C:\Users\Larry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2015-11-10]
    CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-03-23]
    CHR HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Larry\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-08-20]
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
    CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-03-23]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-09-09] (SUPERAntiSpyware.com)
    S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-09-24] (Adobe Systems) [File not signed]
    R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
    S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
    S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [405208 2014-07-03] (BlueStack Systems, Inc.)
    R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384728 2014-07-03] (BlueStack Systems, Inc.)
    R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [773848 2014-07-03] (BlueStack Systems, Inc.)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
    R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37416 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
    R2 Everything; C:\Program Files\Everything\Everything.exe [1441792 2014-08-05] () [File not signed]
    R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.1.4\LavasoftTcpService.exe [1364392 2015-01-23] (Lavasoft Limited)
    R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [739640 2015-11-18] (Malwarebytes Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 MoboroboDeviceService; C:\Program Files (x86)\MoboRobo\MoboroboDeviceService.exe [72184 2014-07-31] ()
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
    R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
    R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-05] (PDF Complete Inc)
    R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
    S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-11-25] (Mister Group)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580144 2015-05-12] (WiseCleaner.com)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-07-03] (BlueStack Systems)
    S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
    S3 cqcpu; C:\Windows\System32\drivers\cqcpu.sys [24376 2010-03-01] ()
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-11-18] ()
    R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2014-12-15] ()
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
    S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader)
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
    R1 networx; C:\Windows\System32\drivers\networx.sys [70120 2015-08-06] (NetFilterSDK.com)
    R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 SIVDRIVER; C:\Windows\system32\Drivers\SIVX64.sys [57312 2008-06-14] (Ray Hinchliffe)
    S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2015-08-05] (wisecleaner.com)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-15 08:58 - 2015-12-15 08:58 - 00003118 _____ C:\Users\Larry\Downloads\2015Dec1-2015Dec14_CustomTransaction.csv
    2015-12-14 20:48 - 2015-12-14 20:48 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForLarry.job
    2015-12-14 16:00 - 2015-12-15 09:20 - 00000000 ____D C:\Users\Larry\Desktop\FRST 64
    2015-12-14 15:57 - 2015-12-15 00:28 - 00000000 ____D C:\Program Files\MyDefrag v4.3.1
    2015-12-14 15:57 - 2015-12-14 15:57 - 00004114 _____ C:\Windows\System32\Tasks\MyDefrag v4.3.1 Monthly
    2015-12-14 15:57 - 2015-12-14 15:57 - 00003434 _____ C:\Windows\System32\Tasks\MyDefrag v4.3.1 Daily
    2015-12-14 15:57 - 2015-12-14 15:57 - 00000865 _____ C:\Users\Public\Desktop\MyDefrag.lnk
    2015-12-14 15:57 - 2015-12-14 15:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyDefrag v4.3.1
    2015-12-14 15:57 - 2010-05-21 12:11 - 01147392 _____ (J.C. Kessels) C:\Windows\system32\MyDefragScreenSaver_v4.3.1.exe
    2015-12-14 15:57 - 2010-05-21 12:11 - 00485376 _____ (J.C. Kessels) C:\Windows\system32\MyDefragScreenSaver_v4.3.1.scr
    2015-12-13 19:09 - 2015-12-13 19:15 - 00509440 _____ (Tech Support Guy System) C:\Users\Larry\Desktop\SysInfo.exe
    2015-12-13 06:33 - 2015-12-13 06:33 - 00025766 _____ C:\Users\Larry\Desktop\cc_20151213_063310.reg
    2015-12-12 20:32 - 2015-12-12 20:33 - 00000000 ____D C:\dd7ca3d4954500010d4b64356434
    2015-12-12 19:49 - 2015-08-05 12:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
    2015-12-12 19:49 - 2015-08-05 12:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
    2015-12-10 21:40 - 2015-12-10 22:41 - 00000000 ____D C:\Users\Larry\Desktop\Build 1911
    2015-12-09 05:21 - 2015-11-05 14:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2015-12-09 05:21 - 2015-11-05 14:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-12-09 05:20 - 2015-11-20 13:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-12-09 05:20 - 2015-11-20 13:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-12-09 05:20 - 2015-11-20 13:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-12-09 05:20 - 2015-11-20 13:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-12-09 05:20 - 2015-11-20 13:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-12-09 05:20 - 2015-11-20 13:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-12-09 05:20 - 2015-11-20 13:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-12-09 05:20 - 2015-11-20 13:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-12-09 05:20 - 2015-11-11 15:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-12-09 05:20 - 2015-11-11 13:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
    2015-12-09 05:20 - 2015-11-11 13:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
    2015-12-09 05:20 - 2015-11-11 13:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
    2015-12-09 05:20 - 2015-11-11 13:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
    2015-12-09 05:20 - 2015-11-11 10:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-12-09 05:20 - 2015-11-11 10:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-12-09 05:20 - 2015-11-11 09:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-12-09 05:20 - 2015-11-10 13:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-12-09 05:20 - 2015-11-10 13:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-12-09 05:20 - 2015-11-10 13:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
    2015-12-09 05:20 - 2015-11-10 13:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2015-12-09 05:20 - 2015-11-10 13:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
    2015-12-09 05:20 - 2015-11-10 12:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-12-09 05:20 - 2015-11-09 19:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-12-09 05:20 - 2015-11-09 19:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-12-09 05:20 - 2015-11-09 19:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-12-09 05:20 - 2015-11-09 19:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-12-09 05:20 - 2015-11-09 19:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-12-09 05:20 - 2015-11-09 19:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-12-09 05:20 - 2015-11-09 18:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-12-09 05:20 - 2015-11-09 18:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-12-09 05:20 - 2015-11-09 18:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-12-09 05:20 - 2015-11-09 18:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-12-09 05:20 - 2015-11-09 18:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-12-09 05:20 - 2015-11-08 17:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-12-09 05:20 - 2015-11-08 17:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-12-09 05:20 - 2015-11-08 17:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-12-09 05:20 - 2015-11-08 17:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-12-09 05:20 - 2015-11-08 17:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-12-09 05:20 - 2015-11-08 16:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-12-09 05:20 - 2015-11-08 16:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-12-09 05:20 - 2015-11-08 16:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-12-09 05:20 - 2015-11-05 14:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
    2015-12-09 05:20 - 2015-11-05 14:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
    2015-12-09 05:20 - 2015-11-05 04:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
    2015-12-09 05:20 - 2015-11-03 14:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2015-12-09 05:20 - 2015-11-03 13:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
    2015-12-09 05:20 - 2015-10-08 18:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
    2015-12-09 05:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
    2015-12-09 05:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
    2015-12-09 05:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
    2015-12-09 05:20 - 2015-10-08 18:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
    2015-12-09 05:20 - 2015-10-08 18:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
    2015-12-09 05:20 - 2015-10-08 18:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
    2015-12-09 05:20 - 2015-10-08 18:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
    2015-12-09 05:20 - 2015-10-08 14:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
    2015-12-09 05:20 - 2015-10-08 13:52 - 00419928 _____ C:\Windows\system32\locale.nls
    2015-12-09 05:19 - 2015-11-11 16:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-12-09 05:19 - 2015-11-11 11:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-12-09 05:19 - 2015-11-11 11:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-12-09 05:19 - 2015-11-11 10:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-12-09 05:19 - 2015-11-11 10:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-12-09 05:19 - 2015-11-09 19:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-12-09 05:19 - 2015-11-09 19:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-12-09 05:19 - 2015-11-09 19:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-12-09 05:19 - 2015-11-09 19:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-12-09 05:19 - 2015-11-09 19:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-12-09 05:19 - 2015-11-09 19:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-12-09 05:19 - 2015-11-09 19:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-12-09 05:19 - 2015-11-09 18:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-12-09 05:19 - 2015-11-09 18:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-12-09 05:19 - 2015-11-09 18:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-12-09 05:19 - 2015-11-09 18:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-12-09 05:19 - 2015-11-09 18:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-12-09 05:19 - 2015-11-09 18:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-12-09 05:19 - 2015-11-08 17:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-12-09 05:19 - 2015-11-08 17:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-12-09 05:19 - 2015-11-08 17:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-12-09 05:19 - 2015-11-08 17:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-12-09 05:19 - 2015-11-08 17:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-12-09 05:19 - 2015-11-08 17:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-12-09 05:19 - 2015-11-08 17:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-12-09 05:19 - 2015-11-08 17:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-12-09 05:19 - 2015-11-08 17:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-12-09 05:19 - 2015-11-08 17:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-12-09 05:19 - 2015-11-08 17:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-12-09 05:19 - 2015-11-08 16:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-12-09 05:19 - 2015-11-08 16:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-12-09 05:19 - 2015-11-08 16:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-12-09 05:19 - 2015-11-08 16:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-12-09 05:19 - 2015-11-08 16:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-12-09 05:19 - 2015-11-08 16:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-12-09 05:19 - 2015-11-08 16:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-12-09 05:19 - 2015-11-08 16:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-12-09 05:19 - 2015-11-08 16:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-12-09 05:19 - 2015-11-08 15:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-12-09 05:19 - 2015-11-08 15:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-12-09 05:19 - 2015-11-08 15:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-12-09 05:17 - 2015-11-03 14:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
    2015-12-09 05:17 - 2015-11-03 13:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
    2015-12-08 11:39 - 2015-12-08 11:39 - 00186171 _____ C:\Users\Larry\Desktop\Live_Call_with_Dr_Jade_April_21_2014.pdf
    2015-12-07 23:47 - 2015-12-08 18:33 - 00000000 ____D C:\Users\Larry\Desktop\Metabokic Aftershock Jade
    2015-12-07 16:47 - 2015-12-07 16:47 - 00002262 _____ C:\Users\Larry\Documents\cc_20151207_164654.reg
    2015-12-07 09:14 - 2015-12-13 14:47 - 00000000 ____D C:\Users\Larry\Desktop\Cancer Answers Summit
    2015-12-04 19:29 - 2015-12-04 19:29 - 00000856 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d12ef3fce545c4.job
    2015-12-03 22:04 - 2015-12-03 23:47 - 00000000 ____D C:\Users\Larry\Desktop\Dr ritamarie
    2015-12-03 22:04 - 2015-12-03 22:04 - 1506286274 _____ C:\Users\Larry\Desktop\Dr ritamarie.avi
    2015-12-02 01:14 - 2015-12-02 01:14 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12cc8bf6779a8.job
    2015-12-01 19:39 - 2015-12-01 20:15 - 00000000 ____D C:\Users\Larry\Desktop\Product Sourcing course
    2015-12-01 19:38 - 2015-12-01 19:38 - 594970112 _____ C:\Users\Larry\Desktop\Product Sourcing course.avi
    2015-12-01 14:11 - 2015-12-01 14:11 - 00001994 _____ C:\Users\Larry\Documents\cc_20151201_141117.reg
    2015-11-29 10:36 - 2015-11-29 10:36 - 00001214 _____ C:\Users\Larry\Desktop\Chromecast.lnk
    2015-11-29 10:36 - 2015-11-29 10:36 - 00000000 ____D C:\Users\Larry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromecast
    2015-11-29 10:35 - 2015-11-29 10:35 - 00929872 _____ (Google Inc.) C:\Users\Larry\Desktop\chromecastinstaller.exe
    2015-11-28 10:59 - 2015-11-28 11:00 - 60656307 _____ C:\Users\Larry\Desktop\kodi-15.2-Isengard-armeabi-v7a.apk
    2015-11-28 10:37 - 2015-11-28 10:43 - 00000000 ____D C:\Users\Larry\Desktop\kodi-14.1-Helix-armeabi-v7a
    2015-11-28 10:34 - 2015-11-28 10:35 - 62742920 _____ C:\Users\Larry\Desktop\kodi-14.1-Helix-armeabi-v7a.zip
    2015-11-28 10:05 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
    2015-11-28 10:05 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
    2015-11-28 09:57 - 2015-11-28 09:57 - 00000000 ____D C:\Users\Larry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
    2015-11-28 09:55 - 2015-11-28 10:28 - 00000000 ____D C:\Users\Larry\Desktop\Kodi
    2015-11-28 09:41 - 2015-11-28 09:41 - 00000000 ____D C:\Users\Larry\Desktop\adbfw201
    2015-11-27 21:22 - 2015-11-27 21:22 - 00894618 _____ C:\Users\Larry\Desktop\DrRitamarie-BurnBellyFatWhileYouSleep.pdf
    2015-11-26 22:23 - 2015-11-26 22:28 - 66591701 _____ C:\Users\Larry\Desktop\kodi-15.2-Isengard.exe
    2015-11-26 21:44 - 2015-11-26 21:44 - 00000000 ____D C:\Users\Larry\.android
    2015-11-26 21:39 - 2015-11-26 21:39 - 00000000 ____D C:\Program Files\DIFX
    2015-11-26 21:37 - 2015-11-26 21:37 - 00000000 ____D C:\adb
    2015-11-26 21:36 - 2015-11-26 21:37 - 09560052 _____ () C:\Users\Larry\Desktop\adb-setup-1.3.exe
    2015-11-24 20:29 - 2015-11-25 11:59 - 00000000 ____D C:\Users\Larry\Desktop\Amazon shipments
    2015-11-24 15:00 - 2015-11-24 15:00 - 00000000 ____D C:\Users\Larry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
    2015-11-24 13:49 - 2015-11-24 13:49 - 00003556 _____ C:\Users\Larry\Desktop\112415canlister.xls
    2015-11-24 08:23 - 2015-11-24 08:23 - 00861370 _____ C:\Users\Larry\Desktop\DrRitamarie-TheMagicOfBurstTraining.pdf
    2015-11-19 09:44 - 2015-11-19 09:45 - 38867896 _____ (MightyText ) C:\Users\Larry\Downloads\MightyText-v2.20-Setup.exe
    2015-11-18 11:40 - 2015-11-18 11:46 - 407461359 _____ C:\Users\Larry\Desktop\Build Grow Scale Workshop 111715.mp4
    2015-11-15 08:45 - 2015-11-25 08:03 - 00000000 ____D C:\Users\Larry\Desktop\Fat Loss Summit

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-15 09:20 - 2015-07-17 06:54 - 00000000 ____D C:\FRST
    2015-12-15 09:16 - 2014-06-17 18:16 - 04354048 ___SH C:\Users\Larry\Desktop\Thumbs.db
    2015-12-15 09:16 - 2009-07-14 00:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-15 09:16 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
    2015-12-15 09:14 - 2012-03-25 22:58 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-15 09:13 - 2015-08-05 06:01 - 00000000 ____D C:\Users\Larry\AppData\Roaming\Wise Care 365
    2015-12-15 09:13 - 2012-03-25 22:58 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-15 09:13 - 2011-12-02 13:23 - 00000000 ____D C:\ProgramData\PDFC
    2015-12-15 09:11 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-12-15 09:11 - 2009-07-13 22:20 - 00000000 ____D C:\Windows
    2015-12-15 08:44 - 2012-07-16 12:31 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-12-15 08:28 - 2014-02-04 13:58 - 00000538 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1138511476-2251193118-4004913463-1000.job
    2015-12-15 08:27 - 2012-09-29 14:28 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000UA.job
    2015-12-15 08:10 - 2013-03-24 22:05 - 00000928 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000UA.job
    2015-12-15 02:06 - 2014-08-24 01:00 - 00000000 ____D C:\Users\Larry\AppData\Local\Adobe
    2015-12-15 02:01 - 2012-03-24 21:29 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{D6BD5A3E-ADB2-4E43-92B1-A406C0CAC453}
    2015-12-14 23:10 - 2013-03-24 22:05 - 00000906 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core.job
    2015-12-14 21:55 - 2012-03-25 21:21 - 00000000 ____D C:\Users\Larry\Desktop\My Stuff
    2015-12-14 20:22 - 2012-03-26 12:59 - 00000000 ____D C:\Users\Larry\AppData\Roaming\HP Support Assistant
    2015-12-14 20:22 - 2012-03-25 22:35 - 00000000 ____D C:\Users\Larry\AppData\Roaming\HpUpdate
    2015-12-14 15:34 - 2015-06-27 20:14 - 00000000 ____D C:\Users\Larry\AppData\LocalLow\Adblock Plus for IE
    2015-12-14 09:27 - 2012-09-29 14:28 - 00000856 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core.job
    2015-12-14 08:55 - 2015-07-21 10:05 - 00000000 ____D C:\Users\Larry\Desktop\Peter Valley
    2015-12-13 19:23 - 2012-03-25 20:11 - 00000000 ____D C:\Users\Larry\Desktop\Dispatch
    2015-12-13 07:09 - 2014-06-26 02:48 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
    2015-12-13 06:54 - 2009-07-13 23:45 - 00024608 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-12-13 06:54 - 2009-07-13 23:45 - 00024608 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-12-12 20:47 - 2015-08-11 13:14 - 00399344 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-12-12 20:46 - 2013-03-12 15:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2015-12-12 20:46 - 2013-03-12 15:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-12-12 20:43 - 2015-04-06 09:47 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2015-12-12 20:43 - 2015-04-06 09:47 - 00000000 ___SD C:\Windows\system32\GWX
    2015-12-12 20:43 - 2014-12-10 15:40 - 00000000 ____D C:\Windows\system32\appraiser
    2015-12-12 20:43 - 2014-05-06 18:52 - 00000000 ___SD C:\Windows\system32\CompatTel
    2015-12-12 20:41 - 2012-03-25 22:33 - 00000000 ____D C:\ProgramData\Microsoft Help
    2015-12-12 20:36 - 2013-03-12 15:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-12-12 20:19 - 2013-08-28 11:57 - 00000000 ____D C:\Windows\system32\MRT
    2015-12-12 20:00 - 2011-02-11 12:15 - 00758700 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
    2015-12-12 19:56 - 2010-11-21 02:17 - 00000000 ____D C:\Program Files\Windows Journal
    2015-12-12 00:09 - 2012-04-03 07:17 - 00000000 ____D C:\Users\Larry\AppData\Local\CrashDumps
    2015-12-10 18:00 - 2009-07-13 22:20 - 00000000 ___RD C:\Users\Public\Libraries
    2015-12-09 02:44 - 2012-04-03 07:48 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-12-09 02:44 - 2011-12-02 13:21 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-12-08 22:39 - 2010-11-20 22:27 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2015-12-07 23:28 - 2015-05-30 22:28 - 00000634 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1138511476-2251193118-4004913463-1000.job
    2015-12-07 09:14 - 2015-11-09 09:11 - 00000000 ____D C:\Users\Larry\Desktop\Beyond Off Grid Summit
    2015-12-06 18:40 - 2014-06-22 09:14 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-12-04 19:29 - 2015-09-15 07:29 - 00000856 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d0efb21fc97637.job
    2015-12-03 23:47 - 2012-04-01 11:07 - 00040960 _____ C:\Users\Larry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2015-12-03 22:13 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\Downloaded Program Files
    2015-12-03 18:45 - 2013-10-21 10:46 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
    2015-12-02 01:14 - 2015-09-15 13:14 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0efe264e5aff9.job
    2015-11-29 10:36 - 2012-03-25 22:58 - 00000000 ____D C:\Users\Larry\AppData\Local\Google
    2015-11-28 10:02 - 2014-06-13 17:10 - 00000000 ____D C:\ProgramData\Package Cache
    2015-11-26 21:44 - 2012-03-24 21:21 - 00000000 ____D C:\Users\Larry
    2015-11-25 13:01 - 2014-06-26 02:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
    2015-11-25 12:53 - 2015-05-26 19:56 - 00000000 ____D C:\ScanLister
    2015-11-25 08:21 - 2015-06-03 07:48 - 00000000 ____D C:\Users\Larry\Desktop\My Amazon
    2015-11-24 15:00 - 2015-04-01 13:00 - 00000000 ____D C:\Users\Larry\AppData\Roaming\Zoom
    2015-11-23 22:15 - 2013-08-20 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
    2015-11-23 19:10 - 2012-03-25 07:20 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-11-23 19:02 - 2014-06-26 02:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
    2015-11-23 11:59 - 2015-08-07 15:55 - 00000696 _____ C:\Users\Larry\Desktop\To do Aug 8.txt
    2015-11-19 18:23 - 2012-03-25 19:47 - 00004320 _____ C:\Windows\System32\Tasks\Open URL by RoboForm
    2015-11-19 18:23 - 2012-03-25 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
    2015-11-19 18:23 - 2012-03-25 16:06 - 00003492 _____ C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon
    2015-11-19 09:53 - 2015-02-17 08:21 - 00000000 ____D C:\Program Files (x86)\MightyText
    2015-11-18 03:03 - 2012-09-13 11:35 - 00000000 ____D C:\Users\Larry\AppData\Roaming\Skype
    2015-11-17 19:46 - 2015-01-20 19:39 - 00000000 ____D C:\Users\Larry\Desktop\Diets and Health
    2015-11-17 19:42 - 2015-10-13 20:22 - 00000000 ____D C:\Users\Larry\Desktop\Cancer Truth Gobal Quest

    ==================== Files in the root of some directories =======

    2012-04-01 11:07 - 2015-12-03 23:47 - 0040960 _____ () C:\Users\Larry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2013-02-03 20:51 - 2013-02-03 20:51 - 0000089 _____ () C:\Users\Larry\AppData\Local\msmathematics.qat.Larry
    2014-09-09 08:59 - 2014-09-09 08:59 - 0000017 _____ () C:\Users\Larry\AppData\Local\resmon.resmoncfg
    2015-10-28 08:18 - 2015-10-28 08:18 - 0000000 _____ () C:\Users\Larry\AppData\Local\{0285A168-D867-45DD-B8A6-2521C4C9E454}
    2014-07-25 08:05 - 2014-07-25 08:05 - 0012288 _____ () C:\Users\Larry\AppData\Local\{4D36E965-E325-11CE-BFC1-08002BE10318}.sav
    2014-10-15 14:27 - 2014-09-01 14:02 - 0067584 _____ (Genry) C:\ProgramData\ISTask.dll

    Files to move or delete:
    ====================
    C:\ProgramData\ISTask.dll


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-11-20 01:15

    ==================== End of FRST.txt ============================
     
  11. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    Here is Addition.txt

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:14-12-2015
    Ran by Larry (2015-12-15 09:22:00)
    Running from C:\Users\Larry\Desktop\FRST 64
    Windows 7 Home Premium Service Pack 1 (X64) (2012-03-25 02:21:35)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1138511476-2251193118-4004913463-500 - Administrator - Disabled)
    Guest (S-1-5-21-1138511476-2251193118-4004913463-501 - Administrator - Disabled)
    HomeGroupUser$ (S-1-5-21-1138511476-2251193118-4004913463-1002 - Administrator - Enabled)
    Larry (S-1-5-21-1138511476-2251193118-4004913463-1000 - Administrator - Enabled) => C:\Users\Larry

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
    AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Ad-Aware Web Companion (x32 Version: 1.1.862.1653 - Lavasoft) Hidden
    Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{0F347A49-E36C-4639-8D2E-003AD408B8B2}) (Version: 1.5 - Eyeo GmbH)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.144 - Adobe Systems Incorporated)
    Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
    Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
    Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
    Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
    Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
    Adobe Photoshop Elements 10 (HKLM-x32\...\Adobe Photoshop Elements 10) (Version: 10.0 - Adobe Systems Incorporated)
    Adobe Photoshop.com Inspiration Browser (HKLM-x32\...\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1) (Version: 3.07 - Adobe Systems Incorporated)
    AllMyNotes Organizer (HKLM-x32\...\AllMyNotes Organizer) (Version: 2.60 - Vladonai Software)
    Amazon Kindle (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Amazon Kindle) (Version: - Amazon)
    AM-DeadLink 4.6 (HKLM-x32\...\aignesamdeadlink_is1) (Version: 4.6 - www.aignes.com)
    Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version: - Audacity Team)
    Azon Insight (HKLM-x32\...\groinup.outsourcing.azoninsight) (Version: 1.0.3 - Web1 Syndication, Inc.)
    Azon Insight (x32 Version: 1.0.3 - Web1 Syndication, Inc.) Hidden
    Belarc Advisor 8.4 (HKLM-x32\...\Belarc Advisor) (Version: 8.4.0.0 - Belarc Inc.)
    BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.8.12.3119 - BlueStack Systems, Inc.)
    BlueStacks Notification Center (HKLM-x32\...\{1AFACC2A-9A60-43EF-ABDB-2CEECA5EA77F}) (Version: 0.8.12.3119 - BlueStack Systems, Inc.)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Brother MFL-Pro Suite MFC-J280W (HKLM-x32\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.13.0 - Brother Industries, Ltd.)
    CamStudio Lossless Codec (HKLM\...\camcodec) (Version: - )
    CamStudio OSS Desktop Recorder (HKLM-x32\...\{FD9C31B6-F572-414D-81E3-89368C97A125}_is1) (Version: 2.6 Beta r294 - CamStudio Open Source Dev Team)
    Camtasia Studio 3 (HKLM-x32\...\Camtasia Studio 3) (Version: 3.1 - TechSmith Corporation)
    CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
    ChromecastApp (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
    Cinescore Studio 1.0 (HKLM-x32\...\{4ADD98FA-1802-4429-9770-9A3D6E016413}) (Version: 1.0.81 - Sony)
    Citrix Online Launcher (HKLM-x32\...\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
    Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    ConvertHelper 2.2 (HKLM-x32\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version: - DownloadHelper)
    ConvertHelper 3.1.1 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version: - DownloadHelper)
    Cool Reader version 3.0.56 (HKLM-x32\...\{6219CB33-794D-4DF3-88D9-101A8AF76CA4}_is1) (Version: 3.0.56 - Download Freely, LLC)
    Coupon Printer for Windows (HKLM-x32\...\Coupon Printer for Windows5.0.1.6) (Version: 5.0.1.6 - Coupons.com Incorporated)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform)
    Duplicate Cleaner Free 3.2.6 (HKLM-x32\...\Duplicate Cleaner Free) (Version: 3.2.6 - DigitalVolcano Software Ltd) <==== ATTENTION
    EaseUS Todo Backup Free 8.0 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 8.0 - CHENGDU YIWO Tech Development Co., Ltd)
    Elements 10 Organizer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
    Everything 1.3.4.686 (x64) (HKLM\...\Everything) (Version: - )
    Ezvid (HKLM-x32\...\{F96D619D-99D6-4C9C-A393-0CD22DE1CA66}_is1) (Version: 0982 - Ezvid, inc.)
    Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
    FastStone Image Viewer 5.1 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.1 - FastStone Soft)
    focus booster (HKLM-x32\...\com.focusboosterapp.focusbooster.air) (Version: 1.3.1 - UNKNOWN)
    focus booster (x32 Version: 1.3.1 - UNKNOWN) Hidden
    Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.7.143.923 - Foxit Software Inc.)
    Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.2.0.722 - Foxit Software Inc.)
    FUJIFILM MyFinePix Studio 2.0 (HKLM-x32\...\FinePix Genie_is1) (Version: - )
    GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.71.5231 - Gretech Corporation)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.80 - Google Inc.)
    Google Drive (HKLM-x32\...\{1C3D2F92-D25E-4D98-B810-3F3B0857BF26}) (Version: 1.26.0707.2863 - Google, Inc.)
    Google Earth Pro (HKLM-x32\...\{35DAA04C-1720-4BE3-A920-A03731EC6A1D}) (Version: 7.1.5.1557 - Google)
    Google Photos Backup (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Google Photos Backup) (Version: 1.1.1.259 - Google, Inc.)
    Google Talk Plugin (HKLM-x32\...\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    GOTD Promotion version. version 3.8.0 (HKLM-x32\...\GOTD Promotion version._is1) (Version: 3.8.0 - Bytesignals)
    GoToMeeting 7.7.0.4062 (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\GoToMeeting) (Version: 7.7.0.4062 - CitrixOnline)
    HandBrake 0.9.9.1 (HKLM-x32\...\HandBrake) (Version: 0.9.9.1 - )
    Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    Hot Lead Finder v3.9.2 (HKLM-x32\...\HotProspector) (Version: 3.9.2 - UNKNOWN)
    Hot Lead Finder v3.9.2 (x32 Version: 3.9.2 - UNKNOWN) Hidden
    HP LinkUp (HKLM-x32\...\{DB3147AB-4024-4773-8EC0-A1FE5B44933D}) (Version: 2.01.028 - Hewlett-Packard)
    HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
    HP Setup (HKLM-x32\...\{D35B72B6-F0E4-462B-BDEB-E08032B3B681}) (Version: 8.7.4747.3786 - Hewlett-Packard Company)
    HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company)
    HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
    HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
    HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard)
    ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
    Infinit (remove only) (HKLM-x32\...\Infinit) (Version: - )
    Instant Local Leads (HKLM-x32\...\InstantLocalLeads) (Version: 1.0.1 - UNKNOWN)
    Instant Local Leads (x32 Version: 1.0.1 - UNKNOWN) Hidden
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation)
    Internet Explorer (Enable DEP) (HKLM\...\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version: - )
    IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.28 - Irfan Skiljan)
    iTunes (HKLM\...\{7FCDABCC-1A1E-4D61-909D-BA9495172774}) (Version: 11.0.3.42 - Apple Inc.)
    Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
    Jing (HKLM-x32\...\{AAF817C5-9B99-4025-A5C1-8D0DB5717F2C}) (Version: 2.0.9006 - TechSmith Corporation)
    join.me (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\JoinMe) (Version: 1.20.0.116 - LogMeIn, Inc.)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Kobo (HKLM-x32\...\Kobo) (Version: 1.6 - Kobo Inc.)
    Kodi (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\Kodi) (Version: - XBMC-Foundation)
    LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3925 - CyberLink Corp.)
    LabelPrint (x32 Version: 2.5.3925 - CyberLink Corp.) Hidden
    LavasoftTcpService (x32 Version: 2.3.1.4 - Lavasoft) Hidden
    Local Buyer Leads Machine (HKLM-x32\...\VALPACK) (Version: 1.2.0 - UNKNOWN)
    Local Buyer Leads Machine (x32 Version: 1.2.0 - UNKNOWN) Hidden
    Localizer Leads Tool (HKLM-x32\...\LocalizerLeadsTool) (Version: 3.4.1 - Viper Consulting, LLC)
    Localizer Leads Tool (x32 Version: 3.4.1 - Viper Consulting, LLC) Hidden
    Malwarebytes Anti-Exploit version 1.8.1.1045 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.8.1.1045 - Malwarebytes)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft Mathematics (HKLM-x32\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
    MightyText (HKLM-x32\...\{87B9BBD8-C449-4885-AD4F-97957734F734}_is1) (Version: 1.0 - MightyText)
    MoboRobo 2.1.8.215 (HKLM-x32\...\{02B934E4-C574-4605-842B-01CD16295185}_is1) (Version: 2.1.8.215 - MoboRobo Inc.)
    Motorola Mobile Drivers Installation 5.1.0 (HKLM\...\{581F6FB0-46E6-42DA-98CC-ABB001386520}) (Version: 5.1.0 - Motorola Inc.)
    Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
    MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
    MyDefrag v4.3.1 (HKLM\...\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
    NetWorx 5.4.1 (HKLM\...\NetWorx_is1) (Version: - Softperfect)
    Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
    Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
    OpenTok for IE (HKLM-x32\...\{B8A832F0-A938-46F4-9587-102BCEB15AE1}) (Version: 0.4.0.9 - TokBox)
    PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
    PC Plus (HKLM-x32\...\PC Plus) (Version: 1.0 - Anvisoft)
    PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.54 - PDF Complete, Inc)
    Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-132318649765}) (Version: 5.10.1217.0 - NewspaperDirect Inc.)
    PSE10 STI Installer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
    QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    RAF (HKLM-x32\...\{E6B43401-E818-4961-AFED-118DD8E87642}) (Version: 1.00.0001 - FUJIFILM Corporation)
    Ralink 802.11n Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 4.0.3.0 - Ralink)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6531 - Realtek Semiconductor Corp.)
    Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden
    Remote Graphics Receiver (HKLM-x32\...\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
    RER Video Converter (HKLM-x32\...\RER Video Converter_is1) (Version: 3.7.6.0419 - RER)
    RevTraxPrintMyCoupon (HKLM-x32\...\{19E8EBBF-55F3-41FB-AC8E-373BA0436939}) (Version: 1.0.0.0 - RevTrax) <==== ATTENTION
    RoboForm 7-9-16-7 (All Users) (HKLM-x32\...\AI RoboForm) (Version: 7-9-16-7 - Siber Systems)
    Sawbuck (HKLM-x32\...\{459BFE07-FCF3-4274-AC8B-8E8DDA7214BA}) (Version: 0.6.8.0 - Google Inc)
    Scale Factor Social Leads Tool (HKLM-x32\...\FacebookLeads) (Version: 0.0.0 - UNKNOWN)
    Scale Factor Social Leads Tool (x32 Version: 0.0.0 - UNKNOWN) Hidden
    ScanLister (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\ScanLister) (Version: - )
    Scansoft PDF Professional (x32 Version: - ) Hidden
    SeaTools for Windows (HKLM-x32\...\SeaTools for Windows) (Version: - Seagate Technology)
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
    Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
    Sony DVD Architect Studio 4.5 (HKLM-x32\...\{B7C7A59F-CF70-481E-A94F-7C2563AA5ADD}) (Version: 4.5.107 - Sony)
    Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1040 - SUPERAntiSpyware.com)
    System Explorer 5.9.1 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group)
    Tweaking.com - Windows Repair (All in One) (HKLM-x32\...\Tweaking.com - Windows Repair (All in One)) (Version: 2.7.5 - Tweaking.com)
    Uninstall Helper (HKLM-x32\...\Uninstall Helper 2.0.1.0) (Version: 2.0.1.0 - InstallX, LLC) <==== ATTENTION
    Uninstall Helper (x32 Version: 2.0.1.0 - InstallX, LLC) Hidden <==== ATTENTION
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    Vegas Movie Studio Platinum 9.0 (HKLM-x32\...\{F14F7FCF-6299-446A-A8F5-C5B791015692}) (Version: 9.0.55 - )
    Video Prospector Pro (HKLM-x32\...\{747232A9-CA27-4A5B-97F8-D44E96025255}) (Version: 2.0.2 - Mark Helton)
    VideoMakerFX (HKLM-x32\...\VideoMakerFX 1.04) (Version: 1.04 - Webvati)
    VideoMakerFX (x32 Version: 1.04 - Webvati) Hidden
    VideoMakerFX ProThemes May Addon 1.1 (HKLM-x32\...\{4753C1C3-821E-429F-8ED1-19B3DC37FECE}) (Version: 1.1 - Webvati)
    VideoMakerFX VideoProfitFX Add On 1.0 (HKLM-x32\...\{8F99303E-4E46-45DC-964D-649DBC72B717}) (Version: 1.0 - Webvati)
    Web Companion (HKLM-x32\...\{8BC95771-8634-499F-9EA5-1498A2701C7A}_WebCompanion) (Version: 1.1.862.1653 - Lavasoft)
    Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (01/27/2014 9.0.0000.00000) (HKLM\...\9CA77E2A8332A0824C54DA611BBE4CA24AB1F750) (Version: 01/27/2014 9.0.0000.00000 - Google, Inc.)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Wise Care 365 3.75 (HKLM-x32\...\Wise Care 365_is1) (Version: 3.75 - WiseCleaner.com, Inc.)
    XMind (HKLM-x32\...\XMind) (Version: 3.3.0 - XMind Ltd.)
    Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
    Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
    Zoom (HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\3911\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
    CustomCLSID: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Larry\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Larry\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll (Google Inc.)

    ==================== Restore Points =========================


    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 21:34 - 2015-10-21 11:16 - 00450639 ____R C:\Windows\system32\Drivers\etc\hosts

    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 www.1-2005-search.com
    127.0.0.1 1-2005-search.com
    127.0.0.1 123fporn.info
    127.0.0.1 www.123fporn.info
    127.0.0.1 123haustiereundmehr.com
    127.0.0.1 www.123haustiereundmehr.com
    127.0.0.1 123moviedownload.com
    127.0.0.1 www.123moviedownload.com

    There are 15459 more lines.


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {089E0998-B416-4D98-8EDE-6C8531303095} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {25C91C5D-48DC-4857-9924-A26A4277C016} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000UA => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {353744ED-B9F6-42AD-A9AD-0EB1D0302431} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {3A1FC3B8-77CF-44E4-B0FE-552594C5FAFB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1138511476-2251193118-4004913463-1000
    Task: {41C088F0-5D4E-4920-B32B-9BD5EF8AFCA8} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxp://www.roboform.com/test-pass.html?aaa=KICMOMJJOMOMJMKMJMLJCNKJOMOMMJCNLMMJOMJJCNGMLMNJKMCNIMNMIMNJJMJJKJHMLJMJGMGMJNJICMIMCNGMCNOMJMFMOMOMCNPMCNGMJMPMPMFMJMCNOMCNIMJMPMOMCNNMJNPICMOMFMEKMICNJJCKFMOMMMMMMMJNHICMMJBJKJLIMJJNBJCMDLOJNINIGIPNJLAJMILIKJNIJNKJCMDJOJNINIGIBNJJAJMILIKJNIPLIJCJOJGJDJBNMJAJCJJNNICMCJGJBJGJMIGJLIKJMICJOJLJKJKJOJMIGIBNMJAJCJJNDJCMKJBJJNMJCMOMFMOMMMIMOMFMPMJNFICMGJLJKJBJLIGJLIGJKJMIBNKJHIKJ"
    Task: {465095D5-D9E9-4C93-8F0C-0E65218800E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {4895BDEC-B6F6-45D4-B5EA-CEFCA798BE7F} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
    Task: {4A5CE016-59E3-42EB-8060-2B081F36BEA1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
    Task: {56D57AAB-89AA-4980-BA6A-4C38B606524B} - System32\Tasks\Go to RoboForm Install page => Rundll32.exe url.dll,FileProtocolHandler "hxxp://www.roboform.com/test-pass.html?aaa=KICMOMJJOMOMJMKMJMLJCNKJOMOMMJCNLMMJOMJJCNGMLMNJKMCNIMNMIMNJJMJJKJHMLJMJGMGMJNJICMJMCNOMPMCNNMFMGMCNPMCNHMOMOMNMFMJMCNOMCNIMJMPMOMCNNMJNPICMLMFMEKMICNJJCKFMPMJNHICMEKMICNJJCKJNBJCMDLOJNINIGIJNKJCMJNNICMJNDJCMKJBJ"
    Task: {6CBEE01B-49C9-4669-B387-83B087D10ABF} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2015-11-19] (Siber Systems)
    Task: {7151D1D5-1F61-4FB5-8362-AE51127A019F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-09] (Adobe Systems Incorporated)
    Task: {75D53C84-49BB-46C2-AD88-861770472597} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
    Task: {76E23CC6-455C-4027-AB38-B216F631A988} - System32\Tasks\{42A8B064-5015-46B3-BA4B-B8799A73ACFB} => pcalua.exe -a "C:\Users\Larry\Downloads\setup (1).exe" -d C:\Users\Larry\Downloads
    Task: {81791C77-C303-4A81-BCA0-5CDDBA3CAE20} - System32\Tasks\G2MUpdateTask-S-1-5-21-1138511476-2251193118-4004913463-1000 => C:\Users\Larry\AppData\Local\Citrix\GoToMeeting\1440\g2mupdate.exe [2014-06-07] (Citrix Online, a division of Citrix Systems, Inc.)
    Task: {846C9B9B-27F5-442C-9F70-5BE463328F3D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)
    Task: {898F47F9-ED5C-45B7-800F-4B0376618D61} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core => C:\Users\Larry\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-24] (Facebook Inc.)
    Task: {8CE36B0F-88ED-4E26-8691-6AD4E48095A5} - System32\Tasks\AdobeAAMUpdater-1.0-Larry-HP-Larry => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated)
    Task: {9B51BA3C-B2D5-4988-8A5C-7AD0D63CF645} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
    Task: {9DB6E6D8-0808-4FC3-AF8E-9BC786D010B8} - \Test TimeTrigger -> No File <==== ATTENTION
    Task: {A67F6894-152E-401B-B41B-DD7BEB9C1952} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-11-24] (HP Inc.)
    Task: {AC16686C-FF81-426E-9E50-F5A504CEE1D4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {C5C02A69-6CC2-4185-8063-C164266C989A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2015-10-22] (Hewlett-Packard)
    Task: {E818D654-2671-4443-9677-77DBA379D369} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000UA => C:\Users\Larry\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-24] (Facebook Inc.)
    Task: {F84DEE78-2CEA-4B1C-8EF5-CD4FAB246909} - System32\Tasks\{0374556C-DE7D-4138-B1AC-E93F11255C66} => pcalua.exe -a "C:\Users\Larry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1P1BWB9J\AdobeAIRInstaller.exe" -d C:\Users\Larry\Desktop

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core.job => C:\Users\Larry\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000UA.job => C:\Users\Larry\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1138511476-2251193118-4004913463-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\4062\g2mupdate.exe
    Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1138511476-2251193118-4004913463-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\4062\g2mupload.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cfebe1a8a1a726.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cfff4c11a03064.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04052d6f1d576.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d08f75c96ab6f7.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf4318453c45.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e222ef16181.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0efe264e5aff9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12cc8bf6779a8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1cfeac68e7d940d.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1cfff4df63ca12d.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d04054939b18b0.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d08ed8688f29ec.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d0bf3cc91efef9.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d0e17c47742dfc.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d0efb21fc97637.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000Core1d12ef3fce545c4.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138511476-2251193118-4004913463-1000UA.job => C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForLarry.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    Task: C:\Windows\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
    Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ShortcutWithArgument: C:\Users\Public\Desktop\Discover HP webOS.lnk -> C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe () -> hxxp://redirect.hp.com/svs/rdr?locale=en_us&bd=pavilion&c=none&pf=cndt&s=hp_palm&tp=dticon_webOS&TYPE=4 <==== ATTENTION

    ==================== Loaded Modules (Whitelisted) ==============

    2014-11-17 12:00 - 2014-08-05 20:04 - 01441792 _____ () C:\Program Files\Everything\Everything.exe
    2014-10-15 14:27 - 2014-07-31 15:51 - 00072184 _____ () C:\Program Files (x86)\MoboRobo\MoboroboDeviceService.exe
    2015-01-01 09:47 - 2014-12-15 01:03 - 00241704 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
    2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00098856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CodeLog.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00031272 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckTool.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 01296424 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00060968 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00017448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CompressFile.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00088616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll
    2015-01-01 09:46 - 2014-12-15 00:53 - 00107560 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActivationOnline.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\logsys.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00030248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DiskSearchImg.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00068136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\MountImg.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00158248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ImgFile.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00280104 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DsImgFile.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00072232 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckImg.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00139816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\vhdvmdk.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00037416 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\BootDriver.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00754728 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ExImage.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00193064 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBackupSize.dll
    2015-01-01 09:46 - 2014-12-15 00:53 - 00407080 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidImage.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00148008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumDisk.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00076840 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FatLib.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00207912 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSLib.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00024616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\GetDriverInfo.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00020520 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CorrectMbr.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00032296 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumTapeDevice.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00034856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbTapeBrowse.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00064040 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\RegLib.dll
    2015-01-01 09:46 - 2014-12-15 00:53 - 00022568 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AccountManager.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00115752 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NasOperator.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00194088 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBrowser.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudOperator.dll
    2015-01-01 09:46 - 2014-12-15 00:53 - 00037928 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActiveOnline.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00135720 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\VMConfig.dll
    2015-01-01 09:46 - 2014-12-15 00:53 - 00020008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00043048 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbDataSwap.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00096808 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBFireWall.dll
    2014-10-15 14:27 - 2014-07-31 15:54 - 00941632 _____ () C:\Program Files (x86)\MoboRobo\DriverInstall.dll
    2015-01-01 09:47 - 2014-12-15 00:53 - 00223784 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SmartBackup.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
    IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
    IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
    IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

    There are 7864 more sites.

    IE trusted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\appspot.com -> hxxps://mighty-app.appspot.com
    IE trusted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\bmyers.com -> hxxps://bmyers.com
    IE trusted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\mightytext.net -> hxxps://mightytext.net
    IE trusted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\mysilentteam.com -> hxxps://mysilentteam.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\...\123simsen.com -> www.123simsen.com

    There are 7864 more sites.


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Larry\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 8.8.8.8 - 8.8.4.4
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupfolder: C:^Users^Larry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk => C:\Windows\pss\Adobe Gamma.lnk.Startup
    MSCONFIG\startupfolder: C:^Users^Larry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MightyText Notifier.lnk => C:\Windows\pss\MightyText Notifier.lnk.Startup
    MSCONFIG\startupfolder: C:^Users^Larry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => C:\Windows\pss\OpenOffice.org 3.1.lnk.Startup
    MSCONFIG\startupreg: Adobe Photo Downloader => "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe"
    MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    MSCONFIG\startupreg: Bench Communicator Watcher => C:\Program Files (x86)\Bench\Proxy\pwdg.exe
    MSCONFIG\startupreg: Bench Settings Cleaner => C:\Program Files (x86)\Bench\Proxy\cl.exe
    MSCONFIG\startupreg: BFHP => C:\Users\Larry\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.17.9\BFHP.exe
    MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
    MSCONFIG\startupreg: BrowserSafeguard => "C:\Program Files (x86)\Browsersafeguard\BrowserSafeguard.exe"
    MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
    MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
    MSCONFIG\startupreg: cdloader => "C:\Users\Larry\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
    MSCONFIG\startupreg: ControlCenter4 => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
    MSCONFIG\startupreg: Daily Fitness Center Home Page Guard 64 bit => "C:\PROGRA~2\DAILYF~2\bar\1.bin\AppIntegrator64.exe"
    MSCONFIG\startupreg: EaseUS TB Tray Agent => "C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe"
    MSCONFIG\startupreg: Everything => "C:\Program Files\Everything\Everything.exe" -startup
    MSCONFIG\startupreg: Facebook Update => "C:\Users\Larry\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
    MSCONFIG\startupreg: Google Update => "C:\Users\Larry\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    MSCONFIG\startupreg: Google+ Auto Backup => "C:\Users\Larry\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart
    MSCONFIG\startupreg: GoogleChromeAutoLaunch_B76987D57E7CB83C2FE99DE261136C7F => "C:\Users\Larry\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
    MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
    MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
    MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    MSCONFIG\startupreg: hpsysdrv => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
    MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
    MSCONFIG\startupreg: IndexSearch => "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"
    MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: Jing => C:\Program Files (x86)\TechSmith\Jing\Jing.exe
    MSCONFIG\startupreg: Malwarebytes Anti-Exploit => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
    MSCONFIG\startupreg: MightyText => "C:\Program Files (x86)\MightyText\startup.bat" "C:\Program Files (x86)\MightyText"
    MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
    MSCONFIG\startupreg: NetWorx => "C:\Program Files\NetWorx\networx.exe" /auto
    MSCONFIG\startupreg: PaperPort PTD => "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"
    MSCONFIG\startupreg: pcreg => C:\Program Files\pcmax\service.exe
    MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe
    MSCONFIG\startupreg: PDF5 Registry Controller => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
    MSCONFIG\startupreg: PDFHook => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe
    MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
    MSCONFIG\startupreg: PPort12reminder => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    MSCONFIG\startupreg: RoboForm => "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
    MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    MSCONFIG\startupreg: SmartToDo => "C:\Users\Larry\Desktop\To-Do Lists\SmartToDo\Smart To-Do\SmartToDo.exe" minimize
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    MSCONFIG\startupreg: SystemExplorerAutoStart => "C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
    MSCONFIG\startupreg: Web Companion => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
    MSCONFIG\startupreg: Zoom =>

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{6D1AED56-30C6-460C-9508-C1D1B2CEAA13}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [UDP Query User{FFEBD51D-907B-4207-829A-37C977109CCD}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [{5666A60A-0B7E-421A-9EE8-70F4789EB66C}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
    FirewallRules: [{86223CAE-9FE0-4054-B0F1-20FE282F6C65}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{19161B4D-4A2B-4ED5-8B21-82A378E1E83E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{72A1E91F-FB7B-46AF-85C8-452EBD4DEBF3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{90AB6D03-34B4-42C7-887D-17E3B96DF4AE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{E73FAD7D-EAC4-4BD3-9CAB-E0992D9B2EE5}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
    FirewallRules: [{F81AE435-0D5A-4913-8440-08366F0E85DA}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [TCP Query User{667FAD2E-C181-485B-8524-37CCEB22E787}C:\users\larry\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Block) C:\users\larry\appdata\local\facebook\video\skype\facebookvideocalling.exe
    FirewallRules: [UDP Query User{CB697A9B-5412-4DFA-8B04-1B7DF08C118F}C:\users\larry\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Block) C:\users\larry\appdata\local\facebook\video\skype\facebookvideocalling.exe
    FirewallRules: [TCP Query User{97F93FF1-85CE-499F-B86B-A9119781C2BF}C:\users\larry\lead kahuna\images\phantomjs.exe] => (Allow) C:\users\larry\lead kahuna\images\phantomjs.exe
    FirewallRules: [UDP Query User{C6BA6817-0A27-4640-86B5-EAC93FF36776}C:\users\larry\lead kahuna\images\phantomjs.exe] => (Allow) C:\users\larry\lead kahuna\images\phantomjs.exe
    FirewallRules: [{85E7ACD8-F93D-4785-AF9D-A10DF808F095}] => (Allow) c:\program files\pcmax\service.exe
    FirewallRules: [{E349C756-BBFB-4801-A268-2B7B85FC3715}] => (Allow) c:\program files\pcmax\service.exe
    FirewallRules: [{7A44EA53-E110-48B3-8536-416391A5606F}] => (Allow) C:\Users\Larry\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
    FirewallRules: [{23031E8F-7C75-4380-9A56-F08FF273D5F8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
    FirewallRules: [{5A6224A5-3559-47AC-8A24-AF3DD8588BCF}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
    FirewallRules: [{C2082967-C578-4FF3-A0E9-38BE53BE2231}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
    FirewallRules: [{BDF0F66F-851F-46CB-AAF9-C79D36B532CC}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
    FirewallRules: [{1C6ED2BD-AD9E-4C9A-9494-160407804080}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
    FirewallRules: [{6DB274EF-922F-4ADE-90B1-7D01FBE8CF0B}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
    FirewallRules: [{95660C41-89D7-4666-B114-7148050140E0}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
    FirewallRules: [{C2571990-A7DF-45E5-911E-6A6A520C1B01}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
    FirewallRules: [{9CA0C456-1992-4D92-BE74-E708D32E90B7}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
    FirewallRules: [TCP Query User{5F9D4B4F-C7BA-4C51-ADE6-304BE4FAB2E7}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
    FirewallRules: [UDP Query User{3A70A3E9-12A7-4939-BA3C-CF77FEC1E495}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
    FirewallRules: [TCP Query User{EE8C2367-7311-4F30-9734-E52A9BCEDC2C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
    FirewallRules: [UDP Query User{C924810A-F62A-4CF6-AA2A-6254FF66C789}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
    FirewallRules: [{C1848E96-B1F0-40B6-B271-0A1D58208268}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{8DF31F6F-DDF5-4AD9-B682-97B05B9D5CFC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{6D85EC08-C3BA-43BA-9928-915A9E137324}] => (Allow) C:\Program Files\NetWorx\networx.exe
    FirewallRules: [{0A845AC0-6FFF-4732-9CD2-8597DFC3966C}] => (Allow) C:\Program Files (x86)\MoboRobo\Moborobo PC Suite.exe
    FirewallRules: [{DD73BE69-D3AA-4606-AB41-08B67960693C}] => (Allow) C:\Program Files (x86)\MoboRobo\Moborobo PC Suite.exe
    FirewallRules: [{09CAE155-ACAD-4CD6-BE44-FB23A6DDCF75}] => (Allow) C:\Users\Larry\AppData\Local\Chromium\Application\chrome.exe
    FirewallRules: [{5D86DCD6-BB22-4AC1-8599-D85B4E4505C2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{8162A813-1803-4AE1-AE7B-DCFDD3478C4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{1ECE113B-7232-4AF3-BF02-F26E9733FEBB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
    FirewallRules: [{19AB3C1A-DDF6-46B1-855E-2ED9D0695208}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/15/2015 09:13:45 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (12/13/2015 06:46:18 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (12/13/2015 06:35:57 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (12/13/2015 06:29:05 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (12/12/2015 08:48:46 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (12/12/2015 08:33:48 PM) (Source: MsiInstaller) (EventID: 10997) (User: Larry-HP)
    Description: Product: Microsoft .NET Framework 4.5.2 -- Error 997. Error 997. Overlapped I/O operation is in progress.
    (NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (12/12/2015 08:33:46 PM) (Source: MsiInstaller) (EventID: 10997) (User: Larry-HP)
    Description: Product: Microsoft .NET Framework 4.5.2 -- Error 997. Overlapped I/O operation is in progress.
    (NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (12/12/2015 07:07:14 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (12/12/2015 07:07:06 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
    Description: The index cannot be initialized.

    Details:
    The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)

    Error: (12/12/2015 07:07:06 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
    Description: The application cannot be initialized.

    Context: Windows Application

    Details:
    The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)


    System errors:
    =============
    Error: (12/15/2015 09:25:43 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
    Description: The ScRegSetValueExW call failed for FailureCommand with the following error:
    %%5

    Error: (12/15/2015 09:21:41 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
    Description: The ScRegSetValueExW call failed for Start with the following error:
    %%5

    Error: (12/15/2015 09:13:49 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
    %%-2147467259

    Error: (12/15/2015 09:13:49 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Function Discovery Resource Publication service terminated with the following error:
    %%-2147467259

    Error: (12/15/2015 09:13:49 AM) (Source: VDS Basic Provider) (EventID: 1) (User: )
    Description: Unexpected failure. Error code: [email protected]

    Error: (12/15/2015 09:13:45 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The BlueStacks Android Service service terminated with the following error:
    %%1064

    Error: (12/15/2015 09:12:12 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Function Discovery Resource Publication service terminated with the following error:
    %%-2147467259

    Error: (12/15/2015 09:09:33 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the EaseUS Agent service.

    Error: (12/13/2015 06:46:36 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
    %%-2147467259

    Error: (12/13/2015 06:46:36 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Function Discovery Resource Publication service terminated with the following error:
    %%-2147467259


    CodeIntegrity:
    ===================================
    Date: 2014-10-15 15:28:14.747
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\MoboRobo\MoboroboAssDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2014-10-15 15:28:14.624
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\MoboRobo\MoboroboAssDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: Intel(R) Pentium(R) CPU G630 @ 2.70GHz
    Percentage of memory in use: 52%
    Total physical RAM: 6050.53 MB
    Available physical RAM: 2871.32 MB
    Total Virtual: 12099.26 MB
    Available Virtual: 8826.68 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:1385.59 GB) (Free:500.11 GB) NTFS ==>[system with boot components (obtained from drive)]
    Drive d: (HP_RECOVERY) (Fixed) (Total:11.57 GB) (Free:1.39 GB) NTFS ==>[system with boot components (obtained from drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1397.3 GB) (Disk ID: BA59389F)
    Partition 1: (Active) - (Size=98 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=1385.6 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=11.6 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================
     
  12. askey127

    askey127 Malware Specialist

    Joined:
    Dec 22, 2006
    Messages:
    3,722
    Larry,
    A few notes...
    You definitely need to get rid of Yahoo Search on all browsers, later.
    The fixes below will help.

    I hope the Wise Care didn't screw up the Registry (fingers crossed)

    There may be some issues with the file indexing on the drive.
    That would make Defragging a long proposition.
    If MyDefrag is not finished, I would proceed with all the following first:
    ------------------------------------------------
    Remove Programs Using Control Panel
    From Start, Control Panel, click on Programs and Features
    Click each Entry, as follows, one by one, if it exists, choose Uninstall, and give permission to Continue:

    Ad-Aware Web Companion
    Coupon Printer for Windows
    Duplicate Cleaner Free 3.2.6
    Java 8 Update 45
    Web Companion
    Wise Care 365 3.75

    Take extra care in answering questions posed by any Uninstaller.
    -----------------------------------------------------------
    REBOOT (RESTART) Your Machine

    -----------------------------------------
    Check hard Drive for Errors
    Open Notepad... then copy and paste the following line into Notepad:
    (Notepad is in Start, Programs, Accessories)
    Code:
    cmd  /c  chkdsk  c:  |find  /v  "percent"  >> "%userprofile%\desktop\checkhd.txt"
    Now Save the NotePad file like this:
    • Click on File from the top menu bar.
    • Select Save As, use Filename: testhd.bat and Save As Type: All Files.
    • Choose Desktop as the location
    • Click Save.
    Right click on testhd.bat on your desktop and select Run As Administrator to run it. OK the UAC.
    A Command Prompt box will pop up, then close after a couple minutes.
    Please post the contents of the checkhd.txt file from your desktop.
    If the file is very long, just copy and paste the LAST 20 or 30 lines into your reply.
    --------------------------------------------------------
    Run A Fix With FRST
    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both the program FRST64.exe and Fixlist.txt be in the same location, or the fix will not work.
    (Both on the Desktop is OK, or both in the same folder elsewhere)

    Run FRST64 and press the FIX button just once, and wait. DO NOT PRESS THE SCAN BUTTON.
    If for some reason the tool needs a restart, please make sure you let the system restart normally.
    The tool may start automatically and complete its work after the system restart. Let the tool complete its run.
    When finished, FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents in your reply.

    askey127
     

    Attached Files:

    Last edited: Dec 15, 2015
  13. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    Here is checkhd.txt.

    Will run FRST Fix next

    The type of the file system is NTFS.
    Volume label is OS.

    WARNING! F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    File verification completed.
    13234 large file records processed.

    0 bad file records processed.

    0 EA records processed.

    46 reparse records processed.

    CHKDSK is verifying indexes (stage 2 of 3)...
    Index verification completed.
    0 unindexed files recovered.

    CHKDSK is verifying security descriptors (stage 3 of 3)...
    Security descriptor verification completed.
    56503 data files processed.

    CHKDSK is verifying Usn Journal...
    Usn Journal verification completed.
    Windows has checked the file system and found no problems.

    1452894502 KB total disk space.
    928935344 KB in 328410 files.
    182176 KB in 56504 indexes.
    0 KB in bad sectors.
    569722 KB in use by the system.
    65536 KB occupied by the log file.
    523207260 KB available on disk.

    4096 bytes in each allocation unit.
    363223625 total allocation units on disk.
    130801815 allocation units available on disk.
    The type of the file system is NTFS.
    Volume label is OS.

    WARNING! F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    File verification completed.
    13234 large file records processed.

    0 bad file records processed.

    0 EA records processed.

    46 reparse records processed.

    CHKDSK is verifying indexes (stage 2 of 3)...
    Index verification completed.
    0 unindexed files recovered.

    CHKDSK is verifying security descriptors (stage 3 of 3)...
    Security descriptor verification completed.
    56503 data files processed.

    CHKDSK is verifying Usn Journal...
    Usn Journal verification completed.
    Windows has checked the file system and found no problems.

    1452894502 KB total disk space.
    929144404 KB in 328406 files.
    182172 KB in 56504 indexes.
    0 KB in bad sectors.
    569786 KB in use by the system.
    65536 KB occupied by the log file.
    522998140 KB available on disk.

    4096 bytes in each allocation unit.
    363223625 total allocation units on disk.
    130749535 allocation units available on disk.
     
  14. askey127

    askey127 Malware Specialist

    Joined:
    Dec 22, 2006
    Messages:
    3,722
    That part is a good result, Larry.
    HD looks OK.
     
  15. Larrylowtech

    Larrylowtech Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    530
    Here is the fixlog.txt


    Fix result of Farbar Recovery Scan Tool (x64) Version:14-12-2015
    Ran by Larry (2015-12-15 16:34:20) Run:2
    Running from C:\Users\Larry\Desktop\FRST 64
    Loaded Profiles: Larry (Available Profiles: Larry)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    CreateRestorePoint:
    CloseProcesses:
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
    SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1138511476-2251193118-4004913463-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
    FF DefaultSearchEngine.US: Search Provided by Yahoo
    FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-17] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-17] (Oracle Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-05-18] (Coupons, Inc.)
    FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\extensions\[email protected] [2015-12-07]
    CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP","hxxp://google.com/","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_43&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CzztCtCtBzzyE0CyDyEyDtAzzyCyBtN0D0Tzu0StCtAzzzytN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StAyDzyzzzz0C0FyEtGyCyEzzyCtG0ByB0E0CtGtDyCtDzztGtD0E0ByDyC0ByC0EtBtCzz0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzyBtDyE0A0F0FtAtG0EtAyE0EtGyEzy0C0BtG0BtDtAyDtG0AyByDyEzytBzz0ByDtB0CyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D2044784012%26a%3Dwbf_gmmedply_15_43%26os%3DWindows%2B7%2BHome%2BPremium"
    CHR Plugin: (Java(TM) Platform SE 6 U32) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll => No File
    R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.1.4\LavasoftTcpService.exe [1364392 2015-01-23] (Lavasoft Limited)
    C:\Program Files (x86)\Lavasoft
    C:\ProgramData\Package Cache
    LavasoftTcpService (x32 Version: 2.3.1.4 - Lavasoft) Hidden
    Task: {9DB6E6D8-0808-4FC3-AF8E-9BC786D010B8} - \Test TimeTrigger -> No File <==== ATTENTION
    Task: C:\Windows\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
    Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
    C:\Program Files (x86)\Spybot - Search & Destroy 2
    C:\PROGRA~2\DAILYF~2
    C:\Program Files (x86)\Browsersafeguard
    C:\Program Files (x86)\Bench
    EmptyTemp:
    Cmd: ipconfig /flushdns

    *****************

    Restore point was successfully created.
    Processes closed successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" => key removed successfully
    HKCR\Wow6432Node\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found.
    HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
    HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
    HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
    "HKU\S-1-5-21-1138511476-2251193118-4004913463-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
    Firefox DefaultSearchEngine.US removed successfully
    HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.45.2 => key not found.
    C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll => not found.
    HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2 => key not found.
    C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll => not found.
    "C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll" => not found.
    C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\extensions\[email protected] => moved successfully
    C:\Users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\kfar9z60.default-1398365315345\extensions\[email protected] => path removed successfully
    Chrome StartupUrls => removed successfully
    C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll => not found.
    LavasoftTcpService => service not found.
    "C:\Program Files (x86)\Lavasoft" => not found.
    C:\ProgramData\Package Cache => moved successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\SystemComponent => value not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9DB6E6D8-0808-4FC3-AF8E-9BC786D010B8}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DB6E6D8-0808-4FC3-AF8E-9BC786D010B8}" => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Test TimeTrigger => key not found.
    C:\Windows\Tasks\Wise Care 365.job => moved successfully
    C:\Windows\Tasks\Wise Turbo Checker.job => moved successfully
    C:\Program Files (x86)\Spybot - Search & Destroy 2 => moved successfully
    "C:\PROGRA~2\DAILYF~2" => not found.
    "C:\Program Files (x86)\Browsersafeguard" => not found.
    "C:\Program Files (x86)\Bench" => not found.

    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========

    EmptyTemp: => 486.4 MB temporary data Removed.


    The system needed a reboot.

    ==== End of Fixlog 16:36:53 ====
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1162222

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice