1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

RUN DLLStart UP Issue

Discussion in 'Hardware' started by edunn1, Mar 22, 2015.

Thread Status:
Not open for further replies.
  1. edunn1

    edunn1 Thread Starter

    Joined:
    Mar 22, 2015
    Messages:
    1
    I am new to the forum and need some guidance...have a Lenovo laptop with Windows 8.1 PRO...been\ getting a RUN DLL error message at startup "C:|PROGRA~1\Common~1\System\SysMnu.dll"


    I really would like to get this issue behind me ...also to my knowledge, I have never have use an Epson printer or product on this computer.
    Listed below are the steps I have been instructed to follow:


    Ran a Farbar recovery Tool, see below ...appears to recommend "Hardware Update Wizard"...trying to run Download TSG SYSINFO


    Got this information:
    Tech Support Guy System Info Utility version 1.0.0.2
    OS Version: Microsoft Windows 8.1 Pro, 64 bit
    Processor: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz, Intel64 Family 6 Model 23 Stepping 10
    Processor Count: 2
    RAM: 4028 Mb
    Graphics Card: Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDDM 1.1)
    Hard Drives: C: Total - 476827 MB, Free - 13179 MB;
    Motherboard: LENOVO, NITU1
    Antivirus: AVG Internet Security 2014, Disabled





    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
    Ran by Ed (administrator) on EDDUNN on 22-03-2015 09:35:08
    Running from C:\Users\Ed\Downloads
    Loaded Profiles: Ed (Available profiles: Ed)
    Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
    ==================== Processes (Whitelisted) =================
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
    (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
    () C:\Program Files (x86)\Livedrive\VSSService.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Malwarebytes Secure Backup) C:\Program Files (x86)\Malwarebytes Secure Backup\SAgent.Service.exe
    (RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Secure Backup\mbsbscan.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
    (RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Microsoft Corporation) C:\Windows\System32\StikyNot.exe
    (Malwarebytes Secure Backup) C:\Program Files (x86)\Malwarebytes Secure Backup\SMessaging.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (YTDownloader) C:\Program Files (x86)\YTDownloader\YTDownloader.exe
    (Google) C:\Program Files\WindowsApps\GoogleInc.GoogleSearch_1.2.1.12_x64__yfg5n0ztvskxp\google-search.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\outlook.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (LastPass) C:\Users\Ed\AppData\LocalLow\LastPass\LastPassBroker.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
    (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicatorCom.exe

    ==================== Registry (Whitelisted) ==================
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
    HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2368736 2014-06-03] (Microsoft Corp.)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-02-13] (Apple Inc.)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-07-10] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [YTDownloader] => C:\Program Files (x86)\YTDownloader\YTDownloader.exe [1974120 2014-05-22] (YTDownloader)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM-x32\...\Run: [PerforMax Cleaner] => C:\Program Files (x86)\PerforMax Cleaner\PerforMax Cleaner.exe [1589760 2014-12-05] ()
    HKLM-x32\...\Run: [SOSUAUI] => C:\Program Files (x86)\Malwarebytes Secure Backup\sosuploadagent.exe [55704 2014-03-19] (Malwarebytes Secure Backup)
    HKLM-x32\...\Run: [SMessaging] => C:\Program Files (x86)\Malwarebytes Secure Backup\SMessaging.exe [65432 2014-03-19] (Malwarebytes Secure Backup)
    HKLM-x32\...\Run: [AccountCreatorRunner] => C:\Program Files (x86)\Malwarebytes Secure Backup\AccountCreatorRunner.exe [22424 2014-03-19] (Malwarebytes Secure Backup)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [HP Officejet Pro 8600 (NET) #2] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [Livedrive] => C:\Program Files (x86)\Livedrive\Livedrive.exe [1842840 2014-07-24] (Livedrive Internet Ltd)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [YTDownloader] => C:\Program Files (x86)\YTDownloader\YTDownloader.exe [1974120 2014-05-22] (YTDownloader)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk
    ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk
    ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
    Startup: C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
    ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
    Startup: C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk
    ShortcutTarget: EvernoteTray.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
    Startup: C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk
    ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
    SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
    SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
    ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ShellIconOverlayIdentifiers: [BackupOverlay] -> {B44A5D93-1351-41A1-BD91-5E92435D8ECD} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
    ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
    ShellIconOverlayIdentifiers: [LivedriveDownloadOverlay] -> {CBCDB610-6B68-4EE9-B7A2-1282FD0C9292} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
    ShellIconOverlayIdentifiers: [LivedriveSharedOverlay] -> {84CEF1E4-1356-4063-845F-05047F4DD52C} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
    ShellIconOverlayIdentifiers: [LivedriveSyncedOverlay] -> {42058329-2FBF-4B33-8E52-3BE5754DE0C1} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
    ShellIconOverlayIdentifiers: [LivedriveUploadOverlay] -> {39A1715A-E4CD-4F1E-B5C4-36B5DB80124E} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
    ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\WINDOWS\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    ==================== Internet (Whitelisted) ====================
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    ProxyServer: [S-1-5-21-290777973-3005558544-818371743-1001] => http=127.0.0.1:52068;https=127.0.0.1:52068
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?pc=BDT3&ocid=BDT3DHP
    HKU\S-1-5-21-290777973-3005558544-818371743-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://binkiland.com/results.php?f=...tDtD2QtN1B2Z1V1T1S1NzuyDtCyC&cr=1808050790&ir=
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://binkiland.com/results.php?f=...tDtD2QtN1B2Z1V1T1S1NzuyDtCyC&cr=1808050790&ir=
    SearchScopes: HKLM -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = http://vosteran.com/results.php?f=4...CtG0D0CtAtD0BzzyE0C0CzytDtD2Q&cr=254319005&ir=
    SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2516} URL = http://www.default-search.net/search?sid=516&aid=104&itype=n&ver=13539&tm=448&src=ds&p={searchTerms}
    SearchScopes: HKLM -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
    SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://astromenda.com/results.php?f...DtGtDtByC0AtCyCyC0EzzyB0FtD2Q&cr=170018456&ir=
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.safesear.ch/web/?type=20140727-165-sshome-ie-df&q={searchTerms}
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.safesear.ch/web/?type=20140727-165-sshome-ie-df&q={searchTerms}
    SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2516} URL = http://www.default-search.net/search?sid=516&aid=104&itype=n&ver=13539&tm=448&src=ds&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-290777973-3005558544-818371743-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://binkiland.com/results.php?f=...tDtD2QtN1B2Z1V1T1S1NzuyDtCyC&cr=1808050790&ir=
    SearchScopes: HKU\S-1-5-21-290777973-3005558544-818371743-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://binkiland.com/results.php?f=...tDtD2QtN1B2Z1V1T1S1NzuyDtCyC&cr=1808050790&ir=
    SearchScopes: HKU\S-1-5-21-290777973-3005558544-818371743-1001 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = http://vosteran.com/results.php?f=4...CtG0D0CtAtD0BzzyE0C0CzytDtD2Q&cr=254319005&ir=
    SearchScopes: HKU\S-1-5-21-290777973-3005558544-818371743-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://astromenda.com/results.php?f...DtGtDtByC0AtCyCyC0EzzyB0FtD2Q&cr=170018456&ir=
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-11-04] (Microsoft Corporation)
    BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-03-07] (LastPass)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-11-12] (Microsoft Corporation)
    BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-12] (Microsoft Corporation.)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-11-03] (Oracle Corporation)
    BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-11-05] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
    BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-03-07] (LastPass)
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-01-24] (Microsoft Corporation)
    BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-12] (Microsoft Corporation.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-11-03] (Oracle Corporation)
    Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-12] (Microsoft Corporation.)
    Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-03-07] (LastPass)
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-12] (Microsoft Corporation.)
    Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-03-07] (LastPass)
    Toolbar: HKU\S-1-5-21-290777973-3005558544-818371743-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2014-09-02] (Microsoft Corporation)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
    FireFox:
    ========
    FF ProfilePath: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default
    FF DefaultSearchEngine: Google
    FF SearchEngineOrder.1: default-search.net
    FF SelectedSearchEngine: Startpage HTTPS
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-04] ()
    FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-03-07] (LastPass)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-04] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
    FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-03] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-11-03] (Oracle Corporation)
    FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-03-07] (LastPass)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-07-19] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-09-17] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-09-17] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-290777973-3005558544-818371743-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Ed\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-09-05] (Citrix Online)
    FF user.js: detected! => C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\user.js [2014-09-15]
    FF SearchPlugin: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\searchplugins\duckduckgo.xml [2014-08-09]
    FF SearchPlugin: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\searchplugins\startpage-https.xml [2014-08-09]
    FF SearchPlugin: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\searchplugins\youtube-ssl.xml [2014-08-09]
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safesearch.xml [2014-07-27]
    FF Extension: fireformmozillaorg - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2014-08-18]
    FF Extension: iCloud Bookmarks - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2014-12-14]
    FF Extension: imagessnarkcoil - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2014-08-10]
    FF Extension: cosstminn - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2014-08-23]
    FF Extension: LastPass - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2015-03-07]
    FF Extension: cosstminn - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2014-08-07]
    FF Extension: SaveClicker - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\[email protected] [2014-08-17]
    FF Extension: Yahoo! Toolbar - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-12-14]
    FF Extension: SafeFinder Smartbar - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\06dwl2n7.default\Extensions\{815ee201-95b7-b036-b5bd-62bcc0db3594} [2014-08-11]
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
    Chrome:
    =======
    CHR HomePage: Default -> hxxp://binkiland.com/?f=1&a=&cd=&cr=&ir=
    CHR StartupUrls: Default -> "hxxp://binkiland.com/?f=7&a=&cd=&cr=&ir=", "hxxp://vosteran.com/?f=7&a=vst_secureddownload_15_04_ie&cd=2XzuyEtN2Y1L1QzutDtBtByDyDyC0Bzz0BtDyCyCtDyEtBtDtN0D0Tzu0StCtCtCyEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEyDtCzz0F0AyE0BtG0Dzy0DyBtG0ByDtCzztG0AzzyByBtGyCzyzytB0F0F0DzyyDyDtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0AzztDyE0C0F0AtG0C0AtC0EtGyEzy0A0CtGzzyCzy0CtG0D0CtAtD0BzzyE0C0CzytDtD2Q&cr=254319005&ir="
    CHR DefaultSearchKeyword: Default -> binkiland.com
    CHR DefaultSearchURL: Default -> http://binkiland.com/results.php?f=...tDtD2QtN1B2Z1V1T1S1NzuyDtCyC&cr=1808050790&ir=
    CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
    CHR Profile: C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Spotify - Music for every moment) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2014-11-23]
    CHR Extension: (500px) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\egpociadnldbkfkjpmjoaibnbcoeplja [2014-11-20]
    CHR Extension: (Word Online) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2014-11-23]
    CHR Extension: (LastPass: Free Password Manager) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-03-07]
    CHR Extension: (YourTemplateFinder) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\hecbmnihlbkndpgnnffcgejdkikdkgek [2015-02-06]
    CHR Extension: (WordCounter.net) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbmpgnfkmmcabkcikheplopibnejhcej [2014-11-23]
    CHR Extension: (Legal Pad) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkbfbjdncjnnfjilmlkmgdconballofj [2014-11-20]
    CHR Extension: (Evernote Web) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2014-11-23]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-07]
    CHR Extension: (OneDrive) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2014-11-20]
    CHR Extension: (Google Wallet) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-11]
    CHR Extension: (Ixquick Toolbar) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\peapgihmdalpoidoacdbfnjiabpdalob [2014-10-01]
    CHR Extension: (Evernote Web Clipper) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-11-20]
    CHR Extension: (Type Fu) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pofoighmmpljaikjiidkkfhldjndfdbk [2014-11-20]
    CHR HKLM\...\Chrome\Extension: [elggllhppljlljkgfeokjpehmdamkejk] - https://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - http://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-290777973-3005558544-818371743-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [elggllhppljlljkgfeokjpehmdamkejk] - https://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [elggllhppljlljkgfeokjpehmdamkejk] - https://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - http://clients2.google.com/service/update2/crx
    ==================== Services (Whitelisted) =================
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
    S2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1417160 2014-07-10] (AVG Technologies CZ, s.r.o.)
    S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-07-10] (AVG Technologies CZ, s.r.o.)
    S2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-07-10] (AVG Technologies CZ, s.r.o.)
    S2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173792 2014-06-03] (Microsoft Corp.)
    S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
    R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
    R2 LivedriveVSSService; C:\Program Files (x86)\Livedrive\VSSService.exe [210584 2014-07-24] ()
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
    R2 sagentservice; C:\Program Files (x86)\Malwarebytes Secure Backup\SAgent.Service.exe [41880 2014-03-19] (Malwarebytes Secure Backup)
    R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-03-11] (Enigma Software Group USA, LLC.)
    R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [161744 2015-03-11] (RaMMicHaeL)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
    ==================== Drivers (Whitelisted) ====================
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
    S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
    S1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
    S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
    S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [270104 2014-06-30] (AVG Technologies CZ, s.r.o.)
    R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63al.sys [5170176 2013-07-01] (Broadcom Corporation)
    R1 cbfs3; C:\WINDOWS\system32\drivers\cbfs3.sys [352008 2012-11-10] (EldoS Corporation)
    R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-03-11] (Enigma Software Group USA, LLC.)
    S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-03-11] ()
    S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [93400 2014-11-21] (Malwarebytes Corporation)
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-22] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
    R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-31] (NetFilterSDK.com)
    R2 sbmntr; C:\Program Files (x86)\YTDownloader\sbmntr.sys [58728 2014-05-22] (YTDownloader)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
    ==================== NetSvcs (Whitelisted) ===================
    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

    ==================== One Month Created Files and Folders ========
    (If an entry is included in the fixlist, the file\folder will be moved.)
    2015-03-22 09:35 - 2015-03-22 09:35 - 00032370 _____ () C:\Users\Ed\Downloads\FRST.txt
    2015-03-22 09:34 - 2015-03-22 09:35 - 00000000 ___DC () C:\FRST
    2015-03-22 09:32 - 2015-03-22 09:32 - 02095616 _____ (Farbar) C:\Users\Ed\Downloads\FRST64.exe
    2015-03-21 13:50 - 2015-03-21 13:50 - 09021468 _____ () C:\Users\Ed\Desktop\videomarketer 3.21.zip
    2015-03-19 23:57 - 2015-03-19 23:57 - 00015674 _____ () C:\Users\Ed\Desktop\PLR Profit Secrets Straight Up From the Real Guys.htm
    2015-03-19 23:57 - 2015-03-19 23:57 - 00000000 ____D () C:\Users\Ed\Desktop\PLR Profit Secrets Straight Up From the Real Guys_files
    2015-03-19 09:02 - 2015-03-19 21:22 - 00000000 ____D () C:\WINDOWS\softwaredistribution.bak
    2015-03-19 06:45 - 2015-03-22 08:47 - 00000490 _____ () C:\WINDOWS\Tasks\Online Backup Update Notifier.job
    2015-03-19 06:45 - 2015-03-19 06:45 - 00003324 _____ () C:\WINDOWS\System32\Tasks\Online Backup Update Notifier
    2015-03-19 06:42 - 2015-03-19 06:42 - 00002017 _____ () C:\Users\Public\Desktop\Malwarebytes Secure Backup.lnk
    2015-03-19 06:42 - 2015-03-19 06:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2015-03-19 06:41 - 2015-03-19 06:41 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Secure Backup
    2015-03-19 06:38 - 2015-03-19 06:38 - 00000000 ____D () C:\WINDOWS\Downloaded Installations
    2015-03-18 22:18 - 2015-03-18 22:19 - 24551650 _____ () C:\Users\Ed\Downloads\First-Steps-LPT-SD staar.zip
    2015-03-18 22:18 - 2015-03-18 22:18 - 24551650 _____ () C:\Users\Ed\Downloads\First-Steps-LPT-SD.zip
    2015-03-18 05:15 - 2015-03-18 05:16 - 00005641 _____ () C:\Users\Ed\Downloads\Follow My Step-By-Step System On How To Have a 3 Page Website That Generates $300_Day (Even if you've never made a dime before).ics
    2015-03-17 08:39 - 2015-03-17 08:39 - 00027136 _____ () C:\Users\Ed\Desktop\NCAA 2015 WORKSHEET.msg
    2015-03-12 00:24 - 2015-03-16 09:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
    2015-03-11 12:27 - 2015-03-11 12:27 - 00000000 ____C () C:\autoexec.bat
    2015-03-11 12:26 - 2015-03-11 12:26 - 00003310 _____ () C:\WINDOWS\System32\Tasks\SpyHunter4Startup
    2015-03-11 12:26 - 2015-03-11 12:26 - 00001103 _____ () C:\Users\Ed\Desktop\SpyHunter.lnk
    2015-03-11 12:26 - 2015-03-11 12:26 - 00000000 ___DC () C:\sh4ldr
    2015-03-11 12:26 - 2015-03-11 12:26 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
    2015-03-11 12:26 - 2015-03-11 12:26 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\Enigma Software Group
    2015-03-11 12:25 - 2015-03-11 12:25 - 00022704 _____ () C:\WINDOWS\system32\Drivers\EsgScanner.sys
    2015-03-11 12:25 - 2015-03-11 12:25 - 00000000 ____D () C:\Program Files\Enigma Software Group
    2015-03-11 11:18 - 2015-03-04 17:24 - 00792032 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2015-03-11 11:18 - 2015-03-04 17:24 - 00178144 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2015-03-11 10:10 - 2015-02-20 21:16 - 25021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-03-11 10:10 - 2015-02-20 20:41 - 12827648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-03-11 10:10 - 2015-02-20 20:25 - 19720192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-03-11 10:10 - 2015-02-19 22:49 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2015-03-11 10:10 - 2015-02-19 22:48 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-03-11 10:10 - 2015-02-19 22:32 - 06035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2015-03-11 10:10 - 2015-02-19 22:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2015-03-11 10:10 - 2015-02-19 22:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2015-03-11 10:10 - 2015-02-19 22:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2015-03-11 10:10 - 2015-02-19 22:03 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-03-11 10:10 - 2015-02-19 21:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
    2015-03-11 10:10 - 2015-02-19 21:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2015-03-11 10:10 - 2015-02-19 21:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2015-03-11 10:10 - 2015-02-19 21:43 - 14398976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-03-11 10:10 - 2015-02-19 21:30 - 04300288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2015-03-11 10:10 - 2015-02-19 21:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
    2015-03-11 10:10 - 2015-02-19 21:28 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2015-03-11 10:10 - 2015-02-19 21:24 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2015-03-11 10:10 - 2015-02-19 21:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2015-03-11 10:10 - 2015-02-19 21:16 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2015-03-11 10:10 - 2015-02-19 21:01 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2015-03-11 10:10 - 2015-02-19 20:57 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2015-03-11 10:09 - 2015-02-20 20:27 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2015-03-11 10:09 - 2015-02-20 20:27 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2015-03-11 10:09 - 2015-02-20 19:58 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2015-03-11 10:09 - 2015-02-20 19:32 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2015-03-11 10:09 - 2015-02-19 23:03 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-03-11 10:09 - 2015-02-19 22:58 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-03-11 10:09 - 2015-02-19 22:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
    2015-03-11 10:09 - 2015-02-19 22:35 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-03-11 10:09 - 2015-02-19 22:34 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2015-03-11 10:09 - 2015-02-19 22:20 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-03-11 10:09 - 2015-02-19 22:15 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-03-11 10:09 - 2015-02-19 22:06 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
    2015-03-11 10:09 - 2015-02-19 21:56 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-03-11 10:09 - 2015-02-19 21:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2015-03-11 10:09 - 2015-02-19 21:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2015-03-11 10:09 - 2015-02-19 21:29 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
    2015-03-11 10:09 - 2015-02-19 21:26 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2015-03-11 10:09 - 2015-02-19 21:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2015-03-11 10:09 - 2015-02-19 20:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2015-03-11 10:09 - 2015-02-12 13:40 - 22291584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-03-11 10:09 - 2015-02-12 13:34 - 19731824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-03-11 10:09 - 2015-01-30 19:20 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2015-03-11 10:09 - 2015-01-29 14:45 - 01763352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
    2015-03-11 10:09 - 2015-01-29 14:34 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
    2015-03-11 10:09 - 2015-01-28 21:58 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
    2015-03-11 10:09 - 2015-01-28 21:29 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
    2015-03-11 10:09 - 2015-01-23 03:17 - 00723072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
    2015-03-11 10:09 - 2015-01-23 01:02 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
    2015-03-11 10:08 - 2015-03-05 22:53 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2015-03-11 10:08 - 2015-03-05 22:33 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2015-03-11 10:08 - 2015-02-25 19:26 - 04178944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-03-11 10:08 - 2015-02-06 19:09 - 00396419 _____ () C:\WINDOWS\system32\ApnDatabase.xml
    2015-03-11 10:08 - 2015-02-05 21:28 - 02257408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2015-03-11 10:08 - 2015-02-05 21:08 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2015-03-11 10:08 - 2015-02-05 16:24 - 01113920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2015-03-11 10:08 - 2015-02-03 19:58 - 00264000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
    2015-03-11 10:08 - 2015-02-03 19:58 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
    2015-03-11 10:08 - 2015-02-03 19:58 - 00044024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
    2015-03-11 10:08 - 2015-02-02 20:02 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
    2015-03-11 10:08 - 2015-02-02 19:53 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
    2015-03-11 10:08 - 2015-02-02 19:53 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
    2015-03-11 10:08 - 2015-01-30 19:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2015-03-11 10:08 - 2015-01-30 19:29 - 02484224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2015-03-11 10:08 - 2015-01-29 22:03 - 01488896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
    2015-03-11 10:08 - 2015-01-29 21:44 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42u.dll
    2015-03-11 10:08 - 2015-01-29 21:42 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42.dll
    2015-03-11 10:08 - 2015-01-28 21:11 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2015-03-11 10:08 - 2015-01-28 21:04 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2015-03-11 10:08 - 2015-01-28 21:04 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
    2015-03-11 10:08 - 2015-01-28 21:00 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2015-03-11 10:08 - 2015-01-28 20:59 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2015-03-11 10:08 - 2015-01-28 20:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
    2015-03-11 10:08 - 2015-01-28 20:50 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
    2015-03-11 10:08 - 2015-01-28 20:49 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2015-03-11 10:08 - 2015-01-28 11:41 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-03-11 10:08 - 2015-01-28 11:41 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2015-03-11 10:08 - 2015-01-28 11:41 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2015-03-11 10:08 - 2015-01-27 22:24 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
    2015-03-11 10:08 - 2015-01-27 21:47 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorageContextHandler.dll
    2015-03-11 10:08 - 2015-01-26 23:44 - 00933888 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
    2015-03-11 10:08 - 2015-01-23 21:51 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
    2015-03-11 10:07 - 2015-02-07 19:57 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
    2015-03-11 10:07 - 2015-02-07 19:49 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
    2015-03-11 10:07 - 2015-02-02 20:03 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
    2015-03-11 10:07 - 2015-01-29 23:01 - 00097792 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
    2015-03-11 10:07 - 2015-01-29 22:03 - 01464832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
    2015-03-11 10:07 - 2015-01-29 22:02 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
    2015-03-11 10:07 - 2015-01-29 21:40 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
    2015-03-11 10:07 - 2015-01-29 21:37 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
    2015-03-11 10:07 - 2015-01-29 21:29 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
    2015-03-11 10:07 - 2015-01-29 21:24 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
    2015-03-11 10:07 - 2015-01-29 21:24 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
    2015-03-11 10:07 - 2015-01-29 21:16 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
    2015-03-11 10:07 - 2015-01-29 21:08 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
    2015-03-11 10:07 - 2015-01-29 21:06 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
    2015-03-11 10:07 - 2015-01-27 21:31 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
    2015-03-11 10:07 - 2015-01-27 21:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
    2015-03-11 10:07 - 2015-01-27 19:47 - 02501368 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2015-03-11 10:07 - 2015-01-27 19:41 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2015-03-11 10:07 - 2015-01-27 00:22 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2015-03-11 10:07 - 2015-01-26 22:11 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2015-03-11 10:07 - 2015-01-21 01:54 - 01384712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
    2015-03-11 10:07 - 2015-01-21 01:15 - 01123848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
    2015-03-11 10:07 - 2014-12-11 01:36 - 00046456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
    2015-03-09 10:20 - 2015-03-09 10:27 - 123809984 _____ () C:\Users\Ed\Downloads\OJ8600_1315-1.exe
    2015-03-09 10:20 - 2015-03-09 10:22 - 05197824 _____ () C:\Users\Ed\Downloads\HPSupportSolutionsFramework-en-11.51.0048 (1).msi
    2015-03-09 10:17 - 2015-03-09 10:20 - 05197824 _____ () C:\Users\Ed\Downloads\HPSupportSolutionsFramework-en-11.51.0048.msi
    2015-03-08 09:17 - 2015-03-08 09:17 - 00000712 _____ () C:\Users\Ed\Downloads\event (2).ics
    2015-03-07 13:06 - 2015-03-19 12:42 - 00002024 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
    2015-03-07 13:04 - 2015-03-07 13:05 - 00000000 ____D () C:\Users\Ed\Desktop\MISCr
    2015-03-07 08:49 - 2015-03-07 08:49 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\LastPass
    2015-03-07 00:34 - 2015-03-07 00:34 - 03276707 _____ () C:\Users\Ed\Downloads\lastpass.safariextz
    2015-03-07 00:13 - 2015-03-07 12:15 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
    2015-03-07 00:13 - 2015-03-07 12:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
    2015-03-07 00:12 - 2015-03-07 12:16 - 00000000 ____D () C:\Program Files (x86)\LastPass
    2015-03-07 00:09 - 2015-03-07 00:31 - 14242360 _____ (LastPass) C:\Users\Ed\Downloads\lastpass_x64 (2).exe
    2015-03-07 00:08 - 2015-03-07 00:09 - 14242360 _____ (LastPass) C:\Users\Ed\Downloads\lastpass_x64 (1).exe
    2015-03-06 18:27 - 2015-03-06 20:17 - 14242360 _____ (LastPass) C:\Users\Ed\Downloads\lastpass_x64.exe.s61zalz.partial
    2015-03-05 10:46 - 2015-03-05 10:46 - 00000000 ____D () C:\Users\Ed\AppData\Local\PerforMax Cleaner
    2015-03-04 16:41 - 2015-03-04 16:41 - 00000000 ____D () C:\Users\Ed\Downloads\Autoruns
    2015-03-04 16:39 - 2015-03-04 16:39 - 00573697 _____ () C:\Users\Ed\Downloads\Autoruns.zip
    2015-03-03 13:57 - 2015-03-03 13:57 - 02667400 _____ (OneBit IT) C:\Users\Ed\Downloads\Setup (1).exe
    2015-03-01 08:28 - 2015-03-01 08:55 - 00000000 ____D () C:\Program Files\REGSERVO
    2015-03-01 08:28 - 2015-03-01 08:54 - 00000390 _____ () C:\WINDOWS\Tasks\REGSERVO.job
    2015-03-01 08:28 - 2015-03-01 08:54 - 00000000 ____D () C:\ProgramData\REGSERVO64
    2015-03-01 08:28 - 2015-03-01 08:28 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REGSERVO
    2015-02-28 08:09 - 2015-02-28 08:09 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\ParetoLogic
    2015-02-28 08:09 - 2015-02-28 08:09 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\DriverCure
    2015-02-28 08:08 - 2015-03-01 08:00 - 00000000 ____D () C:\ProgramData\ParetoLogic
    2015-02-26 05:42 - 2014-12-13 17:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls
    2015-02-26 05:42 - 2014-12-13 17:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls
    2015-02-24 07:22 - 2015-02-24 07:22 - 00001761 _____ () C:\Users\Ed\Downloads\startpage-simplify-customer-support-questions.htm
    2015-02-22 08:31 - 2015-02-22 08:31 - 00000010 _____ () C:\Users\Ed\AppData\Local\DSI.DAT
    2015-02-22 07:34 - 2015-02-22 08:31 - 00000000 ____D () C:\Users\Ed\AppData\Local\Binkiland
    2015-02-22 07:33 - 2015-02-22 07:33 - 00002423 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PerforMax Cleaner.lnk
    2015-02-22 07:33 - 2015-02-22 07:33 - 00000000 ____D () C:\Program Files (x86)\PerforMax Cleaner
    2015-02-22 07:32 - 2015-03-03 14:01 - 00000000 ____D () C:\ProgramData\Package Cache
    2015-02-22 07:31 - 2015-03-22 09:31 - 00000294 _____ () C:\WINDOWS\Tasks\Binkiland.job
    2015-02-22 07:31 - 2015-02-22 07:34 - 00001011 _____ () C:\WINDOWS\IE11_main.log
    2015-02-22 07:31 - 2015-02-22 07:31 - 00000000 ____D () C:\Users\Ed\AppData\Roaming\Binkiland
    2015-02-22 07:30 - 2015-02-22 07:47 - 00000000 ____D () C:\Program Files (x86)\WSE_Binkiland
    2015-02-22 07:30 - 2015-02-22 07:30 - 00000000 ____D () C:\ProgramData\Unchecky
    2015-02-22 07:30 - 2015-02-22 07:30 - 00000000 ____D () C:\Program Files (x86)\Unchecky
    2015-02-22 07:30 - 2015-02-22 07:28 - 31893640 _____ (Microsoft Corporation) C:\Users\Ed\Downloads\IE11-Windows6.1.exe
    2015-02-21 06:04 - 2015-02-21 06:04 - 00898151 _____ () C:\Users\Ed\Downloads\ninosemfreelandingpage.zip
    2015-02-21 01:59 - 2015-02-21 01:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2015-02-21 01:55 - 2015-02-21 01:58 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-02-21 01:55 - 2015-02-21 01:55 - 00000000 ____D () C:\Program Files\iPod
    ==================== One Month Modified Files and Folders =======
    (If an entry is included in the fixlist, the file\folder will be moved.)
    2015-03-22 09:37 - 2014-08-31 23:22 - 00000000 ____D () C:\Users\Ed\Documents\Outlook Files
    2015-03-22 09:23 - 2014-08-12 16:11 - 00000294 _____ () C:\WINDOWS\Tasks\UpdaterEX.job
    2015-03-22 09:19 - 2014-09-05 15:25 - 00000558 _____ () C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-290777973-3005558544-818371743-1001.job
    2015-03-22 09:18 - 2015-01-08 08:26 - 01823821 _____ () C:\WINDOWS\WindowsUpdate.log
    2015-03-22 09:00 - 2014-08-11 09:13 - 00000904 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2015-03-22 09:00 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\system32\sru
    2015-03-22 08:54 - 2014-07-26 04:04 - 00004954 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for EDDUNN-Ed EdDunn
    2015-03-22 08:54 - 2014-07-19 09:40 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2015-03-22 08:42 - 2014-07-18 15:59 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-290777973-3005558544-818371743-1001
    2015-03-22 08:38 - 2014-08-10 07:45 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-03-22 08:37 - 2014-08-11 09:13 - 00000900 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2015-03-22 08:37 - 2014-07-25 13:45 - 00000000 __RDO () C:\Users\Ed\OneDrive
    2015-03-22 07:12 - 2015-01-08 08:28 - 00000000 ____D () C:\Users\Ed
    2015-03-22 06:46 - 2015-01-27 00:24 - 00020578 _____ () C:\WINDOWS\setupact.log
    2015-03-22 06:46 - 2013-08-22 10:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
    2015-03-22 04:26 - 2014-07-25 14:01 - 00003906 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C0BEAF61-3358-4395-8A6A-38CC4806EE0C}
    2015-03-21 17:21 - 2014-07-18 15:19 - 00000000 ____D () C:\Users\Ed\AppData\Local\Packages
    2015-03-21 11:40 - 2014-09-24 03:17 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
    2015-03-21 11:38 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
    2015-03-21 10:50 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
    2015-03-20 10:29 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\registration
    2015-03-19 10:51 - 2014-12-02 13:31 - 00000000 ___RD () C:\Users\Ed\iCloudDrive
    2015-03-19 06:41 - 2014-07-26 08:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2015-03-18 09:47 - 2014-08-23 00:56 - 00000000 ____D () C:\Program Files (x86)\YTDownloader
    2015-03-16 19:19 - 2014-07-29 09:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2015-03-16 12:11 - 2014-09-05 15:25 - 00003548 _____ () C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-290777973-3005558544-818371743-1001
    2015-03-16 08:55 - 2014-07-20 10:52 - 00000000 ____D () C:\Users\Ed\AppData\Local\Apple Computer
    2015-03-15 11:57 - 2015-02-05 06:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
    2015-03-15 10:38 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\rescache
    2015-03-13 14:35 - 2014-08-04 11:33 - 00003086 _____ () C:\WINDOWS\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-290777973-3005558544-818371743-1001
    2015-03-11 11:17 - 2013-08-22 10:44 - 00495016 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
    2015-03-11 11:15 - 2014-09-24 03:03 - 00490706 _____ () C:\WINDOWS\PFRO.log
    2015-03-11 11:15 - 2013-08-22 09:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ___RD () C:\WINDOWS\ToastData
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\WinStore
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ____D () C:\Program Files\Windows Defender
    2015-03-11 11:09 - 2013-08-22 11:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
    2015-03-11 10:54 - 2012-07-26 03:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
    2015-03-10 16:27 - 2014-09-05 15:24 - 00000000 ____D () C:\Users\Ed\AppData\Local\Citrix
    2015-03-10 11:27 - 2014-09-07 11:32 - 00010558 _____ () C:\Users\Ed\.swfinfo
    2015-03-07 18:14 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
    2015-03-07 12:11 - 2014-07-19 05:13 - 00000000 ____D () C:\WINDOWS\system32\MRT
    2015-03-07 12:04 - 2014-07-19 05:13 - 122905848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2015-03-07 09:22 - 2014-07-23 18:43 - 00000000 ____D () C:\Users\Ed\Documents\Backup 2011-09-07 120954
    2015-03-06 20:54 - 2014-07-26 08:38 - 00000000 ____D () C:\ProgramData\TEMP
    2015-03-03 09:17 - 2014-07-19 05:01 - 00295552 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2015-03-02 13:19 - 2014-08-22 10:09 - 00000000 ____D () C:\Users\Ed\AppData\Local\LogMeIn Rescue Applet
    2015-02-27 11:59 - 2014-07-25 09:33 - 00000126 _____ () C:\Users\Ed\AppData\Roaming\WB.CFG
    2015-02-21 01:58 - 2014-10-21 07:34 - 00000000 ____D () C:\Program Files\iTunes
    2015-02-21 01:55 - 2014-07-23 18:17 - 00000000 ____D () C:\Program Files (x86)\iTunes
    2015-02-21 01:55 - 2014-07-23 18:13 - 00000000 ____D () C:\Program Files\Common Files\Apple
    ==================== Files in the root of some directories =======
    2015-03-07 00:14 - 2015-03-07 12:16 - 14242360 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
    2014-09-08 08:10 - 2014-09-20 17:03 - 0009352 _____ () C:\Users\Ed\AppData\Roaming\Comma Separated Values.EML
    2014-07-25 09:33 - 2015-02-27 11:59 - 0000126 _____ () C:\Users\Ed\AppData\Roaming\WB.CFG
    2015-02-22 08:31 - 2015-02-22 08:31 - 0000010 _____ () C:\Users\Ed\AppData\Local\DSI.DAT
    2014-09-11 05:51 - 2014-09-11 05:51 - 0000017 _____ () C:\Users\Ed\AppData\Local\resmon.resmoncfg
    2014-07-31 10:13 - 2014-07-31 10:13 - 0000057 _____ () C:\ProgramData\Ament.ini
    2014-08-17 16:07 - 2014-08-23 01:49 - 0000095 _____ () C:\ProgramData\suscan.txt
    Some content of TEMP:
    ====================
    C:\Users\Ed\AppData\Local\Temp\HPInstaller.exe
    C:\Users\Ed\AppData\Local\Temp\HPPSdr.exe

    ==================== Bamital & volsnap Check =================
    (There is no automatic fix for files that do not pass verification.)
    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2015-03-22 04:42
    ==================== End Of Log ============================
     
  2. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,688
    First Name:
    Frank
    Go here, then click the large blue "Download Now @ Bleeping Computer" button to download and save AdwCleaner.exe to your desktop.

    Close all open windows first, then double-click AdwCleaner.exe to load its main window.

    Click the "Scan" button, then allow the scanning process to finish.

    Click the "Logfile" button.

    When the log appears, save it.

    Return here to your thread, then copy-and-paste the ENTIRE log here.

    -------------------------------------------------------------------

    Download and save and then install the free version of

    Malwarebytes Anti-Malware 2.1.4.1018

    SUPERAntiSpyware 6.0.1170

    Make sure to update their definition files during the install process.

    Make sure to uncheck and decline to install any extras, such as toolbars and homepages, they may offer.

    Make sure to uncheck and decline to use the "Pro" or "Trial" version, if it's offered.

    After they're installed and updated, DON'T do anything else with them yet.

    -------------------------------------------------------------------
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1145262

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice