This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Freezing and stalling out, really slow computer [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Came on suddenly,  computer keeps stalling. Things will disappear and re appear on the screen. Typing suddenly stops then starts again. Slightly better after restart, but not for long. Please help, I need this computer to do my job. Thanks

:welcome:

 

Run this scanner and post both logs so I can see whats going on. It looks like you will need the 64 bit version, post both the FRST64 and Additions logs please

 

 

Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • I freed up some memory and that helped a lot. But still having issues with "unresponsive script" errors that state Chrome files and Shockwave files when I'm on the internet. But I don't currently have Chrome installed. And still stalling, but not as bad, and still going unresponsive, but not as often.  Thanks so much for your help.

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
    Ran by [removed] (administrator) on OWNER-PC (08-04-2016 12:32:56)
    Running from C:\Users\[removed]\Downloads
    [removed]
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    () C:\Program Files (x86)\Backblaze\bzserv.exe
    (SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
    (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
    () C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.3.0\ToolbarUpdater.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    () C:\Program Files (x86)\Backblaze\bzbui.exe
    () C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe
    (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIH5A.EXE
    ( ) C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility.exe
    (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    () C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
    (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
    (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
    () C:\Program Files (x86)\OpenOffice.org 3\program\swriter.exe
    (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    () C:\Program Files (x86)\Backblaze\bzfilelist.exe
    () C:\Program Files (x86)\Backblaze\x64\bztransmit64.exe
     
     
    ==================== Registry (Whitelisted) ===========================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM\…\Run: [LaCie Desktop Manager Launcher] => "C:\Program Files\LaCie\Desktop Manager\lacie_launcherd.exe"
    HKLM-x32\…\Run: [Adobe_ID0ENQBO] => C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe [378224 2008-08-15] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
    HKLM-x32\…\Run: [AppleSyncNotifier] => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
    HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
    HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3862440 2016-03-02] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2662472 2016-03-24] ()
    HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
    HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
    HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM-x32\…\Run: [LTCM Client] => C:\Program Files (x86)\LTCM Client\ltcmClient.exe [1596096 2009-08-05] (Leader Technologies Inc.)
    HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
    HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25577864 2016-03-11] (Dropbox, Inc.)
    HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-03-23] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
    HKLM-x32\…\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OUFWRlJFRS1WMEtNQy1FOVZVVy1FVzBWQS1VVTNYTC1GRVc5Ny1PVTZF"&"inst=NzctNTkwNjcxMzQzLUZQOSs2LUJBUjlHKzEtVEI5KzItRkwrOS1YTzM2 (the data entry has 114 more characters).
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [MobileDocuments] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [490176 2015-05-15] ()
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [LaCie Desktop Manager Startup] => C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe [3461120 2013-09-19] ()
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIH5A.EXE [241280 2012-07-12] (SEIKO EPSON CORPORATION)
    HKU\S-1-5-18\…\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [490176 2015-05-15] ()
    ShellExecuteHooks:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
    ShellExecuteHooks-x32:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
    ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk [2010-01-13]
    ShortcutTarget: Event Reminder.lnk -> C:\Program Files (x86)\The Print Shop 23\Remind.exe (Broderbund Properties LLC)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SpyderUtility.lnk [2015-02-08]
    ShortcutTarget: SpyderUtility.lnk -> C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility.exe ( )
    BootExecute: autocheck autochk * sdnclean64.exe
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    Tcpip\Parameters: [DhcpNameServer] 208.67.220.220 208.67.222.222
    Tcpip\..\Interfaces\{17B740FD-50B3-466B-9C7E-FF70A987A694}: [DhcpNameServer] 208.67.220.220 208.67.222.222
     
    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=dsites0103&cd;=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyD0C0DtAtAtDzyzy0FzytN0D0Tzu0SyByBtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr;=247969105&ir;=
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=dsites0103&cd;=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyD0C0DtAtAtDzyzy0FzytN0D0Tzu0SyByBtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr;=247969105&ir;=
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com?cid={790A72CB-6978-488D-9CF9-10520B39F1BF}∣=630211b429d9aee1044df38e7ee15776-b74c710d51f3a15f62457a829c732ba7d5e81276⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=≺=fr&d;=2014-02-06 02:36:06&v;=19.3.0.491&pid;=safeguard&sg;=0&sap;=hp
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.dogpile.com/search/preferences
    URLSearchHook: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 - (No Name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - No File
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dsites0103&cd;=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyD0C0DtAtAtDzyzy0FzytN0D0Tzu0SyByBtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr;=247969105&ir;=
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dsites0103&cd;=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyD0C0DtAtAtDzyzy0FzytN0D0Tzu0SyByBtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr;=247969105&ir;=
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dsites0103&cd;=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyD0C0DtAtAtDzyzy0FzytN0D0Tzu0SyByBtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr;=247969105&ir;=
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dsites0103&cd;=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyD0C0DtAtAtDzyzy0FzytN0D0Tzu0SyByBtCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr;=247969105&ir;=
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> {199FD135-276C-4B01-99A4-3B99D0184995} URL = hxxp://www.search.ask.com/web?tpid=ORJ&o;=100000031&pf;=V5&p2;=%5ETV%5EOSJ000%5EYY%5EUS&gct;=&itbv;=12.10.3.24&apn;_uid=E62039E8-D851-457B-861B-21D8DB6ABC4C&apn;_ptnrs=%5ETV&apn;_dtid=%5EOSJ000%5EYY%5EUS&apn;_dbr=ff_15.0&doi;=2013-08-21&trgb;=IE&q;={searchTerms}&psv;=
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={790A72CB-6978-488D-9CF9-10520B39F1BF}∣=630211b429d9aee1044df38e7ee15776-b74c710d51f3a15f62457a829c732ba7d5e81276⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=≺=fr&d;=2014-02-06 02:36:06&v;=17.3.1.204&pid;=safeguard&sg;=0&sap;=dsp&q;={searchTerms}
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> {F550C12C-7B50-4627-A73A-0C413E234B4E} URL = hxxp://search.avg.com/route/?d=4c6a307c&v;=6.10.6.4&i;=23&tp;=chrome&q;={searchTerms}&lng;={language}&iy;=&ychte;=us
    BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
    BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-04-02] (RealPlayer)
    BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssie.dll => No File
    BHO-x32: Javaâ„¢ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-08] (Oracle Corporation)
    BHO-x32: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG SafeGuard toolbar\19.3.0.491\AVG SafeGuard toolbar_toolbar.dll [2016-03-24] (AVG Secure Search)
    BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
    BHO-x32: Javaâ„¢ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-08] (Oracle Corporation)
    BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
    Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
    Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\19.3.0.491\AVG SafeGuard toolbar_toolbar.dll [2016-03-24] (AVG Secure Search)
    Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
    Toolbar: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
    DPF: HKLM-x32 {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
    Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\19.3.0\ViProtocol.dll [2016-03-24] (AVG Secure Search)
     
    FireFox:
    ========
    FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4mwe4u9r.default-1392587359105
    FF Homepage: hxxp://www.dogpile.com/
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
    FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-08] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_31\bin\new_plugin\npjp2.dll [No File]
    FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-08] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
    FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\19.3.0\\npsitesafety.dll [No File]
    FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
    FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll [2008-10-15] (CANON INC.)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-06-06] (Google, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-08] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-08] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
    FF Plugin-x32: @real.com/nppl3260;version=12.0.1.633 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprjplug;version=12.0.1.633 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.633 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.633 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
    FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-02-27] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-02-27] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF SearchPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4mwe4u9r.default-1392587359105\searchplugins\avg-secure-search.xml [2016-03-24]
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml [2016-03-24]
    FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-02-18] [not signed]
    FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-20] [not signed]
    FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
    FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-04-02] [not signed]
    FF HKLM-x32\…\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\19.0.0.10 => not found
     
    Chrome: 
    =======
    CHR HKLM-x32\…\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2011-04-02]
     
    ==================== Services (Whitelisted) ========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    S4 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
    S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [604144 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3934184 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1074448 2016-03-23] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [561104 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R2 bzserv; C:\Program Files (x86)\Backblaze\bzserv.exe [235712 2015-05-15] ()
    S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-07-21] (Dropbox, Inc.)
    S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-07-21] (Dropbox, Inc.)
    R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
    R2 LaCieDesktopManagerService; C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe [1380352 2013-09-19] () [File not signed]
    S4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG)
    S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
    S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
    S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
    R2 vToolbarUpdater19.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.3.0\ToolbarUpdater.exe [1888328 2016-03-24] (AVG Secure Search)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
     
    ===================== Drivers (Whitelisted) ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2016-01-26] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [272304 2016-01-26] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378288 2016-02-03] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [269232 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)
    R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)
    S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    S3 Spyder4; C:\Windows\System32\DRIVERS\dccmtr.sys [15360 2011-06-02] (Datacolor)
    S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
    U3 aswMBR; \??\C:\Users\Owner\AppData\Local\Temp\aswMBR.sys [X]
    U3 aswVmm; \??\C:\Users\Owner\AppData\Local\Temp\aswVmm.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== One Month Created files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-04-08 12:32 - 2016-04-08 12:35 - 00030162 _____ C:\Users\Owner\Downloads\FRST.txt
    2016-04-08 01:48 - 2016-04-08 01:57 - 00000000 ____D C:\Users\Owner\Desktop\Printer Stuff
    2016-04-07 21:12 - 2016-04-08 12:32 - 00000000 ____D C:\FRST
    2016-04-07 21:09 - 2016-04-07 21:10 - 02374144 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
    2016-04-07 21:05 - 2016-04-07 21:05 - 01725440 _____ (Farbar) C:\Users\Owner\Downloads\FRST.exe
    2016-04-07 20:57 - 2016-04-07 20:57 - 00002108 _____ C:\Users\Owner\Desktop\aswMBR.txt
    2016-04-07 20:57 - 2016-04-07 20:57 - 00000512 _____ C:\Users\Owner\Desktop\MBR.dat
    2016-04-07 12:21 - 2016-04-07 12:22 - 05198336 _____ (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe
    2016-03-29 11:04 - 2016-03-29 11:04 - 00025348 _____ C:\Users\Owner\Downloads\December 31, 2015.pdf
    2016-03-29 11:03 - 2016-03-29 11:03 - 00025823 _____ C:\Users\Owner\Downloads\November 30, 2015.pdf
    2016-03-29 11:02 - 2016-03-29 11:02 - 00026458 _____ C:\Users\Owner\Downloads\October 31, 2015.pdf
    2016-03-28 01:40 - 2016-03-28 01:40 - 00334830 _____ C:\Users\Owner\Desktop\dxweb(3).pdf
    2016-03-28 01:35 - 2016-03-28 01:35 - 00332458 _____ C:\Users\Owner\Downloads\dxweb(3).pdf
    2016-03-28 01:35 - 2016-03-28 01:35 - 00195170 _____ C:\Users\Owner\Downloads\dxweb(2).pdf
    2016-03-27 02:02 - 2016-03-27 02:02 - 00832505 _____ C:\Users\Owner\Downloads\03-22-2015.pdf
    2016-03-27 01:58 - 2016-03-27 01:58 - 00334830 _____ C:\Users\Owner\Downloads\dxweb(1).pdf
    2016-03-27 01:57 - 2016-03-27 01:57 - 00057703 _____ C:\Users\Owner\Downloads\dxweb.pdf
    2016-03-27 01:53 - 2016-03-27 01:53 - 00020580 _____ C:\Users\Owner\Downloads\eSign.pdf
    2016-03-27 00:56 - 2016-03-27 00:56 - 00617735 _____ C:\Users\Owner\Downloads\document(27).pdf
    2016-03-27 00:55 - 2016-03-27 00:55 - 00914439 _____ C:\Users\Owner\Downloads\document(26).pdf
    2016-03-27 00:53 - 2016-03-27 00:53 - 00439450 _____ C:\Users\Owner\Downloads\document(25).pdf
    2016-03-27 00:52 - 2016-03-27 00:52 - 00497615 _____ C:\Users\Owner\Downloads\document(24).pdf
    2016-03-27 00:51 - 2016-03-27 00:51 - 00440876 _____ C:\Users\Owner\Downloads\document(23).pdf
    2016-03-27 00:50 - 2016-03-27 00:50 - 00441066 _____ C:\Users\Owner\Downloads\document(22).pdf
    2016-03-27 00:49 - 2016-03-27 00:49 - 00440980 _____ C:\Users\Owner\Downloads\document(21).pdf
    2016-03-27 00:48 - 2016-03-27 00:48 - 00582434 _____ C:\Users\Owner\Downloads\document(20).pdf
    2016-03-27 00:47 - 2016-03-27 00:47 - 00580720 _____ C:\Users\Owner\Downloads\document(19).pdf
    2016-03-27 00:46 - 2016-03-27 00:46 - 00357172 _____ C:\Users\Owner\Downloads\document(18).pdf
    2016-03-27 00:45 - 2016-03-27 00:45 - 00246002 _____ C:\Users\Owner\Downloads\document(17).pdf
    2016-03-27 00:43 - 2016-03-27 00:43 - 00306242 _____ C:\Users\Owner\Downloads\document(16).pdf
    2016-03-27 00:40 - 2016-03-27 00:40 - 00242544 _____ C:\Users\Owner\Downloads\document(15).pdf
    2016-03-26 00:44 - 2016-03-26 00:44 - 00000652 _____ C:\Users\Owner\Downloads\export(10).csv
    2016-03-26 00:07 - 2016-03-26 00:07 - 00001643 _____ C:\Users\Owner\Downloads\export(9).csv
    2016-03-26 00:05 - 2016-03-26 00:05 - 00000051 _____ C:\Users\Owner\Downloads\export(8).csv
    2016-03-26 00:03 - 2016-03-26 00:03 - 00001643 _____ C:\Users\Owner\Downloads\export(7).csv
    2016-03-24 09:02 - 2016-04-07 21:03 - 05934784 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2016-03-23 00:20 - 2016-03-23 00:20 - 00264192 _____ C:\Users\Owner\Downloads\Event_Planning_101.ppt
    2016-03-22 00:48 - 2016-03-22 00:49 - 00011227 _____ C:\Users\Owner\Desktop\Family Stuff at Dornbusch.odt
    2016-03-18 17:43 - 2016-03-18 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
    2016-03-11 12:43 - 2016-04-01 16:57 - 00014845 _____ C:\Users\Owner\Desktop\PLANT propagation list 2016.odt
    2016-03-09 07:47 - 2016-02-19 12:02 - 00038336 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
    2016-03-09 07:47 - 2016-02-19 11:54 - 01168896 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2016-03-09 07:47 - 2016-02-19 07:07 - 01373184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2016-03-09 07:47 - 2016-02-11 07:07 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2016-03-09 07:47 - 2016-02-05 07:07 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2016-03-09 07:47 - 2016-02-05 07:07 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2016-03-09 07:47 - 2016-02-05 07:07 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2016-03-09 02:22 - 2016-03-09 02:22 - 02086559 _____ C:\Users\Owner\Downloads\HH Lav Carpet Freshener INDIvidual front label.ai
     
    ==================== One Month Modified files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-04-08 12:19 - 2015-07-21 16:14 - 00000906 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
    2016-04-08 12:16 - 2011-03-25 15:22 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-04-08 12:02 - 2012-04-05 19:09 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2016-04-08 10:33 - 2009-07-13 21:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-04-08 10:33 - 2009-07-13 21:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-04-08 10:27 - 2016-01-08 01:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
    2016-04-08 10:18 - 2011-04-12 14:23 - 00000000 ____D C:\ProgramData\MFAData
    2016-04-08 01:47 - 2014-11-01 20:33 - 00000000 ____D C:\Users\Owner\Documents\USLGA
    2016-04-08 01:47 - 2011-10-23 22:06 - 00000000 ____D C:\Users\Owner\Documents\DEQ Pythian Hall Plan
    2016-04-08 01:41 - 2014-09-19 11:49 - 00000000 ____D C:\Users\Owner\Documents\Lavender Festival 2015
    2016-04-08 01:30 - 2016-02-02 20:19 - 00000000 ____D C:\Users\Owner\Documents\Flossie & Stiles
    2016-04-07 21:06 - 2012-04-05 19:09 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2016-04-07 21:05 - 2012-04-05 19:09 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2016-04-07 21:05 - 2011-05-16 00:30 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-04-07 20:50 - 2014-02-09 15:14 - 00000000 ____D C:\Users\Owner\Downloads\WTF is this in this file
    2016-04-07 16:19 - 2015-07-21 16:14 - 00000902 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
    2016-04-07 13:16 - 2011-04-28 14:27 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-04-07 10:08 - 2013-05-08 21:25 - 00000000 ___RD C:\Users\Owner\Dropbox
    2016-04-07 10:08 - 2013-05-08 21:16 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Dropbox
    2016-04-07 10:04 - 2014-03-29 22:01 - 00000222 _____ C:\Windows\system32\devicelist.txt
    2016-04-07 10:04 - 2014-03-29 22:01 - 00000222 _____ C:\Windows\system32\devicealertlist.txt
    2016-04-07 10:04 - 2014-03-29 22:01 - 00000015 _____ C:\Windows\system32\deviceAppeared.txt
    2016-04-07 10:04 - 2011-08-11 15:06 - 00000000 ____D C:\ProgramData\NVIDIA
    2016-04-07 10:04 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2016-04-06 20:33 - 2011-05-12 21:07 - 00000000 ____D C:\Users\Owner\Documents\Northwest Nectar
    2016-04-06 20:22 - 2010-01-14 01:31 - 00000000 ____D C:\Users\Owner\AppData\Local\ApplicationHistory
    2016-04-06 13:55 - 2016-01-11 22:06 - 00000000 ____D C:\Users\Owner\Documents\Invoices 2016
    2016-04-06 13:45 - 2009-07-13 22:32 - 00000000 ____D C:\Windows\system32\FxsTmp
    2016-04-05 22:50 - 2009-07-13 22:13 - 00783374 _____ C:\Windows\system32\PerfStringBackup.INI
    2016-04-05 22:50 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
    2016-04-05 22:43 - 2012-04-26 17:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2016-04-05 20:34 - 2013-04-13 22:56 - 00000000 ____D C:\Users\Owner\Documents\Lavender field plans
    2016-04-01 00:36 - 2011-05-12 21:12 - 00000000 ____D C:\Users\Owner\Documents\Jennifer Stuff
    2016-03-27 04:37 - 2010-01-16 00:36 - 00000000 ____D C:\Users\Owner\AppData\Local\ElevatedDiagnostics
    2016-03-27 00:41 - 2010-04-18 22:01 - 00000000 ____D C:\Users\Owner\Documents\Wayward Winds
    2016-03-26 01:11 - 2013-06-03 16:38 - 00000000 ____D C:\Users\Owner\Documents\Yakima Finances
    2016-03-26 01:11 - 2012-06-02 12:27 - 00000000 ____D C:\Users\Owner\Documents\Yakima Duplex
    2016-03-24 05:10 - 2013-03-25 17:46 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
    2016-03-24 03:01 - 2015-04-04 03:17 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2016-03-24 03:01 - 2015-04-04 03:17 - 00000000 ___SD C:\Windows\system32\GWX
    2016-03-22 15:08 - 2016-02-18 22:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2016-03-18 17:44 - 2015-07-21 16:14 - 00000000 ____D C:\Program Files (x86)\Dropbox
    2016-03-16 15:46 - 2016-03-06 21:21 - 00012780 _____ C:\Users\Owner\Desktop\SHORT LIST.odt
    2016-03-15 20:08 - 2015-06-02 23:15 - 00000000 ____D C:\Users\Owner\Documents\Lavender Festival 2016
    2016-03-12 04:44 - 2015-10-28 15:02 - 00000936 _____ C:\Users\Public\Desktop\AVG Protection.lnk
    2016-03-12 04:44 - 2014-03-31 09:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2016-03-10 04:00 - 2014-12-10 04:26 - 00000000 ____D C:\Windows\system32\appraiser
    2016-03-09 04:43 - 2009-07-13 21:45 - 02222824 _____ C:\Windows\system32\FNTCACHE.DAT
    2016-03-09 04:09 - 2013-08-15 03:00 - 00000000 ____D C:\Windows\system32\MRT
    2016-03-09 04:00 - 2010-01-12 03:52 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
     
    ==================== Files in the root of some directories =======
     
    2013-05-25 08:48 - 2014-06-02 10:10 - 0003745 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
    2014-02-09 16:15 - 2014-02-09 16:15 - 0000045 _____ () C:\Users\Owner\AppData\Roaming\WB.CFG
    2010-01-29 16:06 - 2015-12-16 07:42 - 0037982 _____ () C:\Users\Owner\AppData\Roaming\wklnhst.dat
    2011-04-14 11:18 - 2011-04-14 11:18 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
     
    Some files in TEMP:
    ====================
    C:\Users\Owner\AppData\Local\Temp\avguirn_081496364364.exe
    C:\Users\Owner\AppData\Local\Temp\uninstall.exe
    C:\Users\Owner\AppData\Local\Temp\_is1774.exe
    C:\Users\Owner\AppData\Local\Temp\_is9FD.exe
     
     
    ==================== Bamital & volsnap =================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
     
     
    LastRegBack: 2016-04-08 00:30
     
    ==================== End of FRST.txt ============================
     
     
    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by [removed] (2016-04-08 12:35:55)
    Running from C:\Users\[removed]\Downloads
    Windows 7 Home Premium Service Pack 1 (X64) (2010-01-12 10:40:03)
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Accounts: =============================
     
    Administrator (S-1-5-21-2522848791-1810669900-1685156444-500 - Administrator - Disabled)
    ASPNET (S-1-5-21-2522848791-1810669900-1685156444-1002 - Limited - Enabled)
    Guest (S-1-5-21-2522848791-1810669900-1685156444-501 - Limited - Enabled)
    HomeGroupUser$ (S-1-5-21-2522848791-1810669900-1685156444-1004 - Limited - Enabled)
    Owner (S-1-5-21-2522848791-1810669900-1685156444-1000 - Administrator - Enabled) => C:\Users\Owner
    UpdatusUser (S-1-5-21-2522848791-1810669900-1685156444-1005 - Limited - Enabled) => C:\Users\UpdatusUser
     
    ==================== Security Center ========================
     
    (If an entry is included in the fixlist, it will be removed.)
     
    AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
     
    ==================== Installed Programs ======================
     
    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
     
    Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.2.443 - Adobe Systems Incorporated)
    Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
    Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\…\{AC76BA86-1033-F400-7760-000000000004}_955) (Version:  - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
    Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe Creative Suite 4 Design Premium (HKLM-x32\…\Adobe_55230b0b70661df0f212e88f0b655f7) (Version: 4.0 - Adobe Systems Incorporated)
    Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
    Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
    Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
    Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
    Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe InDesign CS4 Icon Handler x64 (Version: 6.0 - Adobe Systems Incorporated) Hidden
    Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
    Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
    Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
    Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
    Adobe Reader XI (11.0.15) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.15 - Adobe Systems Incorporated)
    Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
    Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
    Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    AVG (Version: 16.51.7497 - AVG Technologies) Hidden
    AVG 2016 (Version: 16.0.4545 - AVG Technologies) Hidden
    AVG Protection (HKLM\…\AVG) (Version: 2016.51.7497 - AVG Technologies)
    AVG SafeGuard toolbar (HKLM-x32\…\AVG SafeGuard toolbar) (Version: 19.3.0.491 - AVG Technologies)
    Backblaze (HKLM-x32\…\Backblaze) (Version:  - Backblaze, Inc)
    Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
    Canon IJWCS - Common Profile Extention Data (HKLM-x32\…\IJWCS - Common Profile Extention Data) (Version: 1.0.0 - Canon Inc.)
    Canon IJWCS - PRO-1 series Extention Data (HKLM-x32\…\IJWCS - PRO-1 series Extention Data) (Version: 1.0.0 - Canon Inc.)
    Canon IJWCS - PRO-10 series Extention Data (HKLM-x32\…\IJWCS - PRO-10 series Extention Data) (Version: 1.0.0 - Canon Inc.)
    Canon IJWCS - PRO-100 series Extention Data (HKLM-x32\…\IJWCS - PRO-100 series Extention Data) (Version: 1.1.0 - Canon Inc.)
    CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\…\CANON iMAGE GATEWAY Task) (Version: 1.7.0.4 - Canon Inc.)
    Canon Internet Library for ZoomBrowser EX (HKLM-x32\…\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.3.9 - Canon Inc.)
    Canon MOV Decoder (HKLM-x32\…\Canon MOV Decoder) (Version: 1.3.0.14 - Canon Inc.)
    Canon MOV Encoder (HKLM-x32\…\Canon MOV Encoder) (Version: 1.1.0.18 - Canon Inc.)
    Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\…\MovieEditTask) (Version: 3.2.0.34 - Canon Inc.)
    Canon My Image Garden (HKLM-x32\…\Canon My Image Garden) (Version: 2.1.0 - Canon Inc.)
    Canon My Image Garden Design Files (HKLM-x32\…\Canon My Image Garden Design Files) (Version: 2.1.0 - Canon Inc.)
    Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
    Canon Print Studio Pro (HKLM-x32\…\Print Studio Pro) (Version: 1.3.5 - Canon Inc.)
    Canon PRO-100 series On-screen Manual (HKLM-x32\…\Canon PRO-100 series On-screen Manual) (Version: 7.5.0 - Canon Inc.)
    Canon PRO-100 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_PRO-100_series) (Version:  - Canon Inc.)
    Canon PRO-100 series User Registration (HKLM-x32\…\Canon PRO-100 series User Registration) (Version:  - Canon Inc.‎)
    Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.)
    Canon Utilities CameraWindow (HKLM-x32\…\CameraWindowLauncher) (Version: 7.2.0.2 - Canon Inc.)
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC6) (Version: 6.5.0.3 - Canon Inc.)
    Canon Utilities Digital Photo Professional 3.6 (HKLM-x32\…\DPP) (Version: 3.6.0.0 - Canon Inc.)
    Canon Utilities EOS Utility (HKLM-x32\…\EOS Utility) (Version: 2.6.0.0 - Canon Inc.)
    Canon Utilities MyCamera (HKLM-x32\…\MyCamera) (Version: 7.2.0.4 - Canon Inc.)
    Canon Utilities PhotoStitch (HKLM-x32\…\PhotoStitch) (Version: 3.1.22.46 - Canon Inc.)
    Canon Utilities Picture Style Editor (HKLM-x32\…\Picture Style Editor) (Version: 1.5.0.0 - Canon Inc.)
    Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\…\RemoteCaptureTask) (Version: 1.8.0.1 - Canon Inc.)
    Canon Utilities WFT-E1/E2/E3/E4 Utility (HKLM-x32\…\WFTK) (Version: 3.3.0.0 - Canon Inc.)
    Canon Utilities ZoomBrowser EX (HKLM-x32\…\ZoomBrowser EX) (Version: 6.3.1.8 - Canon Inc.)
    Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\…\ZoomBrowser EX Memory Card Utility) (Version: 1.2.2.11 - Canon Inc.)
    Cisco WebEx Meetings (HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
    Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
    Dropbox (HKLM-x32\…\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
    Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
    Epson Connect (HKLM-x32\…\{64BA551C-9AF6-495C-93F3-D1270E0045FC}) (Version:  - )
    Epson Customer Participation (HKLM\…\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.0.0.0 - SEIKO EPSON CORPORATION)
    Epson Download Navigator (HKLM-x32\…\{10F63395-157F-4B93-AB4D-702A2FF11942}) (Version: 1.0.1 - SEIKO EPSON CORPORATION)
    Epson Print CD (HKLM-x32\…\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.05.00 - SEIKO EPSON CORPORATION)
    EPSON Printer Software (HKLM\…\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
    Epson Professional Print Sample (HKLM-x32\…\{E7B46D0D-A63D-42AB-9D1D-75A88C280F78}) (Version:  - )
    EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - )
    Epson Stylus Photo R2000 Printer Uninstall (HKLM\…\Epson Stylus Photo R2000) (Version:  - SEIKO EPSON Corporation)
    EPSON WP-4020 Series Printer Uninstall (HKLM\…\EPSON WP-4020 Series) (Version:  - SEIKO EPSON Corporation)
    FMW 1 (Version: 1.72.2 - AVG Technologies) Hidden
    Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
    iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
    iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
    Java 8 Update 31 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation)
    Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
    Java(TM) 6 Update 22 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.220 - Oracle)
    kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
    LaCie Desktop Manager 1.7.0 (HKLM\…\{3845209F-142E-4F48-B61A-AA34D2DB54BB}_is1) (Version: 1.7.0 - LaCie)
    LTCM Client (HKLM-x32\…\LTCM Client) (Version:  - Leader Technologies Inc.)
    Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
    Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
    Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Web Publishing Wizard 1.52 (HKLM-x32\…\WebPost) (Version:  - )
    Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
    MobileMe Control Panel (HKLM\…\{41BC9E31-0D39-462E-8E4C-767B21A3B1C3}) (Version: 3.1.8.0 - Apple Inc.)
    Mozilla Firefox 45.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 45.0.1 (x86 en-US)) (Version: 45.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
    Mozilla Thunderbird 38.7.1 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 38.7.1 (x86 en-US)) (Version: 38.7.1 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MyFonts Order M1374621 (HKLM-x32\…\{89F95935-E17D-DE19-C100-5F1991151CBD}) (Version: 1.0 - MyFonts.com, Inc.)
    Nero 8 Essentials (HKLM-x32\…\{E13AA9BC-0C88-46F8-B4CC-CA32A81A1033}) (Version: 8.3.401 - Nero AG)
    NVIDIA 3D Vision Driver 311.06 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
    NVIDIA Graphics Driver 311.06 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.2.23.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.2.23.3 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.10.0514 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
    NVIDIA Update 1.11.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
    OpenOffice.org 3.1 (HKLM-x32\…\{E6B87DC4-2B3D-4483-ADFF-E483BF718991}) (Version: 3.1.9399 - OpenOffice.org)
    PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
    Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
    Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
    Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
    Pixel Bender Toolkit (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
    QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    RAR File Open Knife - Free Opener (HKLM-x32\…\RAR File Open Knife - Free Opener) (Version: 3.50 - Philipp Winterberg)
    RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
    RealPlayer (HKLM-x32\…\RealPlayer 12.0) (Version:  - RealNetworks)
    RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
    Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
    Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
    Spyder4Elite (HKLM-x32\…\Spyder4Elite) (Version:  - )
    SSC Service Utility v4.30 (HKLM-x32\…\SSC Service Utility_is1) (Version:  - SSC Localization Group)
    Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
    The Print Shop 23 (HKLM-x32\…\{11F7808F-76AD-40E0-A8D9-6445DAEA3F5D}) (Version: 23.00.00 - Broderbund Software)
    VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
    Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\…\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
    Visual Studio 2008 x64 Redistributables (HKLM-x32\…\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
    Visual Studio 2010 x64 Redistributables (HKLM\…\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
    Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Xvid 1.2.1 final uninstall (HKLM-x32\…\Xvid_is1) (Version: 1.2 - Xvid team (Koepi))
    Zip Extractor Packages (HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Zip Extractor Packages) (Version:  - ) <==== ATTENTION
     
    ==================== Custom CLSID (Whitelisted): ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== Scheduled Tasks (Whitelisted) =============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    Task: {0EB9C1A5-3769-41E3-A453-F43CA4521B13} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2522848791-1810669900-1685156444-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-01-24] (RealNetworks, Inc.)
    Task: {0F31EA49-B605-4F22-BCD8-1D7D442BFB50} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated)
    Task: {29DBF75D-9A0E-4A9D-A06E-2CBDEE4A8895} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-21] (Dropbox, Inc.)
    Task: {2A56E453-D926-439F-8006-A82CB2259031} - System32\Tasks\{85A23A3C-9E72-43A6-8223-E68BC1E3594C} => pcalua.exe -a C:\Users\Owner\Downloads\sscserve(1).exe -d C:\Users\Owner\Downloads
    Task: {307186D2-0682-44A7-A62F-4D1B6CC775FB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
    Task: {4335E81C-ACC1-415F-9FE0-CDD206458BF8} - System32\Tasks\{AA1963FF-60BA-45EC-AA73-0ECD1CA18B1C} => pcalua.exe -a C:\epson\epson12335_R2400_printer_driver_650das\SETUP\SETUP64.EXE -d C:\epson\epson12335_R2400_printer_driver_650das\SETUP
    Task: {4C5B65BC-BEE9-464A-8BD2-0E4FBD51D736} - System32\Tasks\{F752A472-11A3-45FB-B5B7-D0F86C92E148} => pcalua.exe -a C:\epson\epson12335_R2400_printer_driver_650das\SETUP\E_SCHK03.EXE -d C:\epson\epson12335_R2400_printer_driver_650das\SETUP
    Task: {4E707F79-BF8C-4C42-B257-1C7186C5DD79} - System32\Tasks\{13AD8D12-2E66-43AA-BABA-A9E55734033A} => C:\Program Files (x86)\The Print Shop 23\PMW.exe [2008-07-16] (Broderbund Properties LLC)
    Task: {65769BB4-6B81-4E28-AADE-666166E85703} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-21] (Dropbox, Inc.)
    Task: {6B21E17A-EDF8-41B7-8FBC-CF6306368958} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {6F4FB8D7-5A29-4520-A6B5-35BAD7661B28} - System32\Tasks\{DC361E74-DD64-408A-A954-E5473ED2C25C} => pcalua.exe -a C:\epson\epson12335_R2400_printer_driver_650das\SETUP\RESCAN.EXE -d C:\epson\epson12335_R2400_printer_driver_650das\SETUP
    Task: {708FDB45-C84E-449B-A596-D902F9330E36} - System32\Tasks\{AF61108E-FDD8-4572-9F61-03167E208D55} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NA2JJ0D1\Thunderbird%20Setup%203.0[1].exe" -d C:\Users\Owner\Desktop
    Task: {76D51FAD-B02A-4639-B739-4F904146383C} - System32\Tasks\{A8A9B129-A267-4713-9ED2-DD7824EB01D2} => pcalua.exe -a D:\English\Guide\setup.exe -d D:\English\Guide
    Task: {8B2935F2-2A10-4D2D-92B0-D05FAEAF783C} - System32\Tasks\{3EDB2623-5612-4759-9F6D-FF5FCAA9C68C} => pcalua.exe -a C:\Users\Owner\Downloads\epson12335(6).exe -d C:\Users\Owner\Downloads
    Task: {8DEF9A29-4689-4B41-AD31-155E6B78D0CC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {8E2C05EB-5389-448E-B86A-C16754FF2705} - System32\Tasks\{C5BD492C-17B5-4FED-8C84-420EFD77CF05} => pcalua.exe -a D:\Setup.exe -d D:\
    Task: {918F7291-57DC-41F1-A8AA-38A7493F8137} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2013-09-20] (Safer-Networking Ltd.)
    Task: {A4B92EF4-C0C8-4325-AE79-143A78D3094F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2522848791-1810669900-1685156444-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-01-24] (RealNetworks, Inc.)
    Task: {AB64741F-EBF0-4EC3-A330-A81E6192A175} - System32\Tasks\DigitalSite => C:\Users\Owner\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
    Task: {B1593518-7043-4D10-A139-92A168E9C5C3} - System32\Tasks\{F75E852D-9AFE-45D4-BCA3-A831F3CF9890} => pcalua.exe -a C:\Users\Owner\Downloads\XvidSetup.exe -d "C:\Program Files (x86)\Mozilla Firefox"
    Task: {D4AC9FB3-39DD-4A1F-8E18-FDCF2BDF0604} - System32\Tasks\{E0065FCA-6F81-47B3-AC5C-57B8D4DC1F0D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\The Print Shop 23\PMW.exe"
    Task: {E37F7EEE-7185-45EE-B3CE-0371B3BABBB1} - System32\Tasks\{F4B1FD3F-C641-4E57-867B-EE353C9305D9} => pcalua.exe -a D:\Setup.exe -d D:\
    Task: {E49F5D9B-1970-4A9B-A80F-D4675B962DB1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2013-09-20] (Safer-Networking Ltd.)
    Task: {EA4F35A8-C56A-4FE1-9A98-49B7FA780C3C} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2522848791-1810669900-1685156444-1000
    Task: {F775DCEF-91BA-433F-B26C-8DB002770DAE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {F7D9DEF2-531D-4D1F-8F34-34C9DD5D5158} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2013-09-20] (Safer-Networking Ltd.)
     
    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
     
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Owner\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
    Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
     
    ==================== Shortcuts =============================
     
    (The entries could be listed to be restored or removed.)
     
    ==================== Loaded Modules (Whitelisted) ==============
     
    2012-11-18 04:02 - 2013-01-18 08:00 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2012-12-06 02:09 - 2015-05-15 17:37 - 00235712 _____ () C:\Program Files (x86)\Backblaze\bzserv.exe
    2014-03-29 22:01 - 2013-09-19 12:00 - 01380352 _____ () C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe
    2012-12-06 02:09 - 2015-05-15 17:37 - 00490176 _____ () C:\Program Files (x86)\Backblaze\bzbui.exe
    2014-03-29 22:01 - 2013-09-19 11:58 - 03461120 _____ () C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe
    2013-03-25 17:46 - 2016-03-24 05:10 - 02662472 _____ () C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
    2009-04-16 22:41 - 2009-04-16 22:41 - 00304128 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\swriter.exe
    2012-12-06 02:09 - 2015-05-15 17:37 - 00304320 _____ () C:\Program Files (x86)\Backblaze\bzfilelist.exe
    2013-12-19 20:22 - 2015-05-15 17:37 - 03272896 _____ () C:\Program Files (x86)\Backblaze\x64\bztransmit64.exe
    2014-10-11 14:06 - 2014-10-11 14:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-02-09 20:05 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2014-02-09 20:05 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    2011-08-09 17:06 - 2012-02-07 15:59 - 00139264 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\Appearance Pak.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00151552 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\RegEx.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 12977947 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\RBScript.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00098304 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\Shell.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00761856 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\XML.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00274432 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\CGamma.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00086016 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\CSensor.dll
    2011-09-22 16:22 - 2012-02-07 15:59 - 00039936 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\MBSRegistrationPlugin16724.dll
    2011-09-22 16:22 - 2012-02-07 15:59 - 00025600 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\MBSPluginVersionPlugin16724.dll
    2016-03-24 05:10 - 2016-03-24 05:10 - 00527944 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.3.0\log4cplusU.dll
    2016-03-18 17:43 - 2016-02-23 11:19 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
    2016-03-18 17:43 - 2016-02-23 11:19 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
    2016-03-18 17:43 - 2016-03-11 17:18 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00112592 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_python_x66cf7a7cx17a72769.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
    2016-03-18 17:43 - 2016-03-11 17:18 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00021824 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00084792 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
    2016-03-18 17:43 - 2016-03-11 17:18 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00158008 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
    2016-03-18 17:43 - 2016-02-23 11:23 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
    2016-03-18 17:43 - 2016-02-23 11:23 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
    2016-03-18 17:43 - 2016-03-11 17:18 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
    2016-03-18 17:43 - 2016-02-23 11:25 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
    2015-10-28 14:36 - 2016-04-07 10:07 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
    2016-01-08 01:23 - 2016-03-29 01:46 - 00153032 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
    2016-01-08 01:23 - 2016-03-29 01:46 - 00022472 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
    2009-04-16 14:02 - 2009-04-16 14:02 - 00970752 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
    2009-04-24 01:33 - 2009-04-24 01:33 - 00139264 _____ () C:\Program Files (x86)\OpenOffice.org 3\Basis\program\NSLDAP32V50.dll
    2009-04-16 14:03 - 2009-04-16 14:03 - 00166400 _____ () C:\Program Files (x86)\OpenOffice.org 3\Basis\program\libxslt.dll
    2016-04-07 21:05 - 2016-04-07 21:05 - 19403968 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll
     
    ==================== Alternate Data Streams (Whitelisted) =========
     
    (If an entry is included in the fixlist, only the ADS will be removed.)
     
    AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [252]
     
    ==================== Safe Mode (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
     
     
    ==================== EXE Association (Whitelisted) ===============
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
     
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Classes\.exe: exefile =>  <===== ATTENTION
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Classes\exefile:  <===== ATTENTION
     
    ==================== Internet Explorer trusted/restricted ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry.)
     
     
    ==================== Hosts content: ===============================
     
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
     
    2009-07-13 19:34 - 2015-01-01 14:59 - 00000042 ____A C:\Windows\system32\Drivers\etc\hosts
     
    ::1 localhost
    127.0.0.1       localhost
     
    ==================== Other Areas ============================
     
    (Currently there is no automatic fix for this section.)
     
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
    DNS Servers: 208.67.220.220 - 208.67.222.222
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.
     
    ==================== MSCONFIG/TASK MANAGER disabled items ==
     
    (Currently there is no automatic fix for this section.)
     
    MSCONFIG\Services: Adobe Version Cue CS4 => 3
    MSCONFIG\Services: BDESVC => 3
    MSCONFIG\Services: EFS => 2
    MSCONFIG\Services: gupdate => 2
    MSCONFIG\Services: gusvc => 3
    MSCONFIG\Services: idsvc => 3
    MSCONFIG\Services: napagent => 3
    MSCONFIG\Services: Nero BackItUp Scheduler 3 => 2
    MSCONFIG\Services: netprofm => 3
    MSCONFIG\Services: NlaSvc => 2
    MSCONFIG\Services: PLFlash DeviceIoControl Service => 2
    MSCONFIG\Services: SharedAccess => 2
    MSCONFIG\Services: Wlansvc => 3
    MSCONFIG\Services: wmiApSrv => 3
    MSCONFIG\Services: WMPNetworkSvc => 2
    MSCONFIG\Services: WPCSvc => 3
    MSCONFIG\Services: wscsvc => 2
    MSCONFIG\Services: WSearch => 2
    MSCONFIG\Services: WwanSvc => 3
    MSCONFIG\startupfolder: C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => C:\Windows\pss\OpenOffice.org 3.1.lnk.Startup
    MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    MSCONFIG\startupreg: EPSON Stylus Photo R2400 => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATI9SA.EXE /FU "C:\Windows\TEMP\E_S3745.tmp" /EF "HKCU"
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: NBKeyScan => "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    MSCONFIG\startupreg: TkBellExe => "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
     
    ==================== FirewallRules (Whitelisted) ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    FirewallRules: [{CA064AE9-C1E6-4344-92D1-622021F8F058}] => (Allow) LPort=5353
    FirewallRules: [{D76F7A57-5C9F-405A-840A-6A06E066B070}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
    FirewallRules: [{912D0C27-FDCB-4D3B-A2D1-B26D62A2B362}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
    FirewallRules: [{D3D09705-D450-41DF-9F17-54F73B0C187C}] => (Allow) LPort=3703
    FirewallRules: [{BD812B1E-3515-4C2F-B5F4-58A8D0F22815}] => (Allow) LPort=3704
    FirewallRules: [{E016C6EE-41D2-4527-BB82-EA411DE8B558}] => (Allow) LPort=51000
    FirewallRules: [{C74980A2-3522-4223-8360-5FBC87D7FFD6}] => (Allow) LPort=51001
    FirewallRules: [{0D3A0EF6-E668-4B96-B74E-12FA64FD8D24}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    FirewallRules: [{6A08B976-39FC-4E9E-9CD2-6AFA9BC42895}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    FirewallRules: [{001C107C-7F67-4BA9-BC35-D9F764D3FA42}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{DCC33B8A-2F02-42DA-9EA9-F155511BFA4B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [TCP Query User{E778489B-2DC2-42D7-B0A2-9572422F427F}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
    FirewallRules: [UDP Query User{FF882A05-0A7C-4DA0-BED7-27DAC0D5AAB4}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
    FirewallRules: [{822B53A7-4D40-4AD3-BA25-A109AEFBEA57}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe
    FirewallRules: [{B2E53A26-AA71-4FFF-8C0B-9F79B43743E5}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe
    FirewallRules: [{57FA5759-AECD-467D-BCF8-733FF2C3F089}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    FirewallRules: [{7D143370-9561-41FE-8A4C-04469ECA81BB}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    FirewallRules: [{E173D5FE-8455-4F2E-BC2D-F3317E3C3636}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{568A4863-9D7D-4055-B0DC-0EAD0C8263A6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{6D831140-E026-4126-BFA1-50BDF278F9C8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{47C7C843-84C6-44B3-8523-3A98A17FBA12}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{43EE03BE-A23B-4424-8E72-C50FB1114917}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
    FirewallRules: [{40CF77FC-67C3-442A-8422-D12A8053C2C1}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
    FirewallRules: [{B7C58480-4999-474A-9215-345B4CCB8051}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
    FirewallRules: [{235BDE70-A5E9-4B33-B450-8C0A975202A0}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
    FirewallRules: [{A32885EE-C0C7-4AD7-8C48-FDD8BAA3A069}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{C0A5D85D-E096-417A-B94F-49DA728DDE50}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{9FF5FD6D-97B5-4FB0-99CE-1AF7718E0A50}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
    FirewallRules: [{BD0FB7B6-BC09-4558-B558-3BBE7601F326}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
    FirewallRules: [{EDBEE052-0383-4F37-A601-A7E0A2270E98}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
    FirewallRules: [{40AB1D22-E761-4A4A-8D54-EF0D3311716D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{0A7E168D-0785-45FD-AEDF-BAB7F21D1135}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [TCP Query User{B2EE3B71-AED0-48A7-B107-2BF345F3683E}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
    FirewallRules: [UDP Query User{8DF2C3A2-99C2-4E93-854C-14D80A17D0F0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
    FirewallRules: [{5957264C-18A5-4D1F-8C7A-76AC53F4A7C0}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{34D29ED6-0D3B-4A27-8BCC-C9D68C0CF82B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{157B9F39-6B11-4D2F-AF0E-6C3829BD86B6}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{720C2848-4736-4407-9EC2-302BA033DD97}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{45E4342B-D21A-4C91-B076-71B41F3F11B0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{E35C6558-D831-4709-BB1C-69D6E8F6B99E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{DA033A23-700F-4B92-BFDD-65755AC2D17D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{4D063B67-E123-4C5B-8148-26CD52FA0B4B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{6B46406A-265E-4B8D-9DF5-A14111866475}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D; 2 Tray Icon
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
     
    ==================== Restore Points =========================
     
    ATTENTION: System Restore is disabled
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
    Error: (04/08/2016 01:42:02 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
    Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
     
    Error: (04/08/2016 01:42:02 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
    Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
     
    Error: (04/08/2016 01:41:50 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
    Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
     
    Error: (04/05/2016 08:36:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Illustrator.exe version 14.0.128.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
     
    Process ID: 226c
     
    Start Time: 01d18beaadb6aae5
     
    Termination Time: 239
     
    Application Path: C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Support Files\Contents\Windows\Illustrator.exe
     
    Report Id: 9ffb0790-fba8-11e5-8dba-4061865cd330
     
    Error: (03/18/2016 01:20:42 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: plugin-container.exe, version: 44.0.2.5884, time stamp: 0x56bbf417
    Faulting module name: NPSWF32_21_0_0_182.dll, version: 21.0.0.182, time stamp: 0x56de03b2
    Exception code: 0x80000003
    Fault offset: 0x003bcafd
    Faulting process id: 0x698
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3
     
    Error: (03/16/2016 03:34:34 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: CNQMUPDT.EXE, version: 2.0.0.0, time stamp: 0x4f7a7000
    Faulting module name: CNMDWLD.DLL, version: 1.0.0.0, time stamp: 0x4f5eedc8
    Exception code: 0xc0000005
    Fault offset: 0x000023c6
    Faulting process id: 0x1710
    Faulting application start time: 0xCNQMUPDT.EXE0
    Faulting application path: CNQMUPDT.EXE1
    Faulting module path: CNQMUPDT.EXE2
    Report Id: CNQMUPDT.EXE3
     
    Error: (03/16/2016 05:40:40 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: plugin-container.exe, version: 44.0.2.5884, time stamp: 0x56bbf417
    Faulting module name: mozglue.dll, version: 44.0.2.5884, time stamp: 0x56bbe58e
    Exception code: 0x80000003
    Fault offset: 0x0000ed3b
    Faulting process id: 0x1798
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3
     
    Error: (03/09/2016 01:44:07 PM) (Source: MsiInstaller) (EventID: 1024) (User: Owner-PC)
    Description: Product: Adobe Reader XI (11.0.14) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011015}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
     
    Error: (03/03/2016 11:51:49 AM) (Source: MsiInstaller) (EventID: 1024) (User: Owner-PC)
    Description: Product: Adobe Reader XI (11.0.13) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011014}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
     
    Error: (02/28/2016 11:50:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Illustrator.exe version 14.0.128.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
     
    Process ID: 160c
     
    Start Time: 01d17116e16baa44
     
    Termination Time: 644
     
    Application Path: C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Support Files\Contents\Windows\Illustrator.exe
     
    Report Id: 9b90ddae-deb0-11e5-8115-4061865cd330
     
     
    System errors:
    =============
    Error: (04/08/2016 12:37:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:43 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:36 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:29 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:07 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:37:00 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:36:53 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 12:36:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
     
    CodeIntegrity:
    ===================================
      Date: 2011-04-12 12:19:01.485
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2011-04-12 12:19:01.470
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
     
    ==================== Memory info =========================== 
     
    Processor: AMD Athlonâ„¢ II X2 240 Processor
    Percentage of memory in use: 61%
    Total physical RAM: 4095.18 MB
    Available physical RAM: 1561.29 MB
    Total Virtual: 8188.57 MB
    Available Virtual: 3016.94 MB
     
    ==================== Drives ================================
     
    Drive c: () (Fixed) (Total:931.41 GB) (Free:246.55 GB) NTFS
    Drive d: (May 25 2014) (CDROM) (Total:0.69 GB) (Free:0.59 GB) UDF
    Drive j: (LACIE SHARE) (Fixed) (Total:23.99 GB) (Free:23.99 GB) FAT32
    Drive k: (LaCie) (Fixed) (Total:3702.02 GB) (Free:3075.76 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 256D4294)
    Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
    Attempted reading MBR returned 0 bytes.
     Could not read MBR for disk 1.
     
    ==================== End of Addition.txt ============================

    Hi,

     

    You have some malware going on along with some foistware from AVG.  Installing AVG  is fine but you need to see what your installing along with it, the AVG toolbar and AVG search are not needed and take up system resources. We can deal with this later

     

     

    All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder
     
     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner TO YOUR DESKTOP
     
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
     
    •  
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
     
     
     
    ===============================================================================
     
     
     
     
    [external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
    •  
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
     
     
     
    ===============================================================================
     
    Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
     
    •  
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
     
     
     
    [external image: MB%202.2.1.1043_zps9tg44ubl.jpg]
     
    •  
    • On the Dashboard click on Update Now
    • Go to the Setting Tab
    • Under Setting go to Detection and Protection
    • Under PUP and PUM make sure both are set to show Treat Detections as Malware
    • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
    • Then on the Dashboard click on Scan
    • Make sure to select THREAT SCAN
    • Then click on Scan
    • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
    • Please paste the log back into this thread for review
    • Exit Malwarebytes
     

    Hi Again, you did just fine. In Malwarebytes when you selected save to clipboard , its just on your windows clipboard and all you had to do was paste it into this thread

     

    The report from AdwCleaner is the Scan report, all that stuff needs to go , did you click on Clean ??  If not run it again and this time after the scan click on Clean 

     

    After you take care of that, lets do this

     

     
    Your running FRST64 from your Downloads folder, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST64 exactly where we want it to be. 
     
     
    Then Right click on FRST64 and select RUN AS ADMINISTRATOR .  When it opens make sure Additions is checked, leave everything else as is, then click on Scan and post both the new FRST64 and Additions logs

    Next three reports, thanks.

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
    Ran by [removed] (administrator) on OWNER-PC (08-04-2016 22:45:46)
    Running from C:\Users\[removed]\Desktop
    [removed]
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    () C:\Program Files (x86)\Backblaze\bzserv.exe
    (SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
    (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
    () C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    () C:\Program Files (x86)\Backblaze\bzbui.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    () C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe
    ( ) C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
    (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
    (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
    (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    () C:\Program Files (x86)\Backblaze\bzfilelist.exe
     
     
    ==================== Registry (Whitelisted) ===========================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM\…\Run: [LaCie Desktop Manager Launcher] => "C:\Program Files\LaCie\Desktop Manager\lacie_launcherd.exe"
    HKLM-x32\…\Run: [Adobe_ID0ENQBO] => C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe [378224 2008-08-15] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
    HKLM-x32\…\Run: [AppleSyncNotifier] => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
    HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
    HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3862440 2016-03-02] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
    HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
    HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM-x32\…\Run: [LTCM Client] => C:\Program Files (x86)\LTCM Client\ltcmClient.exe [1596096 2009-08-05] (Leader Technologies Inc.)
    HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
    HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25577864 2016-03-11] (Dropbox, Inc.)
    HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-03-23] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
    HKLM-x32\…\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OUFWRlJFRS1WMEtNQy1FOVZVVy1FVzBWQS1VVTNYTC1GRVc5Ny1PVTZF"&"inst=NzctNTkwNjcxMzQzLUZQOSs2LUJBUjlHKzEtVEI5KzItRkwrOS1YTzM2 (the data entry has 114 more characters).
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [MobileDocuments] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [490176 2015-05-15] ()
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\Run: [LaCie Desktop Manager Startup] => C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe [3461120 2013-09-19] ()
    HKU\S-1-5-18\…\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [490176 2015-05-15] ()
    ShellExecuteHooks:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
    ShellExecuteHooks-x32:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
    ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-11] (Dropbox, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk [2010-01-13]
    ShortcutTarget: Event Reminder.lnk -> C:\Program Files (x86)\The Print Shop 23\Remind.exe (Broderbund Properties LLC)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SpyderUtility.lnk [2015-02-08]
    ShortcutTarget: SpyderUtility.lnk -> C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility.exe ( )
    BootExecute: autocheck autochk * sdnclean64.exe
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    Tcpip\Parameters: [DhcpNameServer] 208.67.220.220 208.67.222.222
    Tcpip\..\Interfaces\{17B740FD-50B3-466B-9C7E-FF70A987A694}: [DhcpNameServer] 208.67.220.220 208.67.222.222
     
    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = 
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
    URLSearchHook: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 - (No Name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - No File
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-04-02] (RealPlayer)
    BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: Javaâ„¢ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-08] (Oracle Corporation)
    BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
    BHO-x32: Javaâ„¢ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-08] (Oracle Corporation)
    BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
    Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
    Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
    DPF: HKLM-x32 {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
     
    FireFox:
    ========
    FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4mwe4u9r.default-1392587359105
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
    FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-08] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_31\bin\new_plugin\npjp2.dll [No File]
    FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-08] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
    FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
    FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll [2008-10-15] (CANON INC.)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-06-06] (Google, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-08] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-08] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
    FF Plugin-x32: @real.com/nppl3260;version=12.0.1.633 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprjplug;version=12.0.1.633 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.633 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.633 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.)
    FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-02-27] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-02-27] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-12-29] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll [2011-04-02] (RealNetworks, Inc.)
    FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-02-18] [not signed]
    FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-20] [not signed]
    FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
    FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-04-02] [not signed]
     
    Chrome: 
    =======
    CHR HKLM-x32\…\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2011-04-02]
     
    ==================== Services (Whitelisted) ========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    S4 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
    S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [604144 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3934184 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1074448 2016-03-23] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [561104 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R2 bzserv; C:\Program Files (x86)\Backblaze\bzserv.exe [235712 2015-05-15] ()
    S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-07-21] (Dropbox, Inc.)
    S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-07-21] (Dropbox, Inc.)
    R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
    R2 LaCieDesktopManagerService; C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe [1380352 2013-09-19] () [File not signed]
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
    S4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG)
    S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
    R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
     
    ===================== Drivers (Whitelisted) ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2016-01-26] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [272304 2016-01-26] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378288 2016-02-03] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [269232 2016-03-02] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)
    R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)
    S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-08] (Malwarebytes)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
    S3 Spyder4; C:\Windows\System32\DRIVERS\dccmtr.sys [15360 2011-06-02] (Datacolor)
    S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== One Month Created files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-04-08 22:42 - 2016-04-08 22:42 - 00010339 _____ C:\Users\Owner\Desktop\AdwCleaner[C1].txt
    2016-04-08 16:46 - 2016-04-08 16:46 - 00004849 _____ C:\Users\Owner\Desktop\malwarebytes.txt
    2016-04-08 16:15 - 2016-04-08 22:41 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2016-04-08 16:14 - 2016-04-08 16:14 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-04-08 16:14 - 2016-04-08 16:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-04-08 16:14 - 2016-04-08 16:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-04-08 16:14 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2016-04-08 16:14 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
    2016-04-08 16:03 - 2016-04-08 16:11 - 22851472 _____ (Malwarebytes ) C:\Users\Owner\Downloads\mbam-setup-2.2.1.1043.exe
    2016-04-08 16:00 - 2016-04-08 16:00 - 00007743 _____ C:\Users\Owner\Desktop\JRT.txt
    2016-04-08 15:56 - 2016-04-08 15:56 - 01610352 _____ (Malwarebytes) C:\Users\Owner\Desktop\JRT.exe
    2016-04-08 15:52 - 2016-04-08 15:52 - 00015072 _____ C:\Users\Owner\Desktop\AdwCleaner[S1].txt
    2016-04-08 15:48 - 2016-04-08 22:37 - 00000000 ____D C:\AdwCleaner
    2016-04-08 15:47 - 2016-04-08 15:48 - 03119168 _____ C:\Users\Owner\Desktop\AdwCleaner.exe
    2016-04-08 15:20 - 2016-04-08 15:44 - 151335299 _____ C:\Users\Owner\Downloads\wetransfer-169b38.zip
    2016-04-08 12:43 - 2016-04-08 22:49 - 00025361 _____ C:\Users\Owner\Desktop\FRST.txt
    2016-04-08 12:43 - 2016-04-08 12:43 - 00055172 _____ C:\Users\Owner\Desktop\Addition.txt
    2016-04-08 12:35 - 2016-04-08 12:37 - 00055172 _____ C:\Users\Owner\Downloads\Addition.txt
    2016-04-08 12:32 - 2016-04-08 12:37 - 00042003 _____ C:\Users\Owner\Downloads\FRST.txt
    2016-04-08 10:27 - 2016-04-08 12:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
    2016-04-08 01:48 - 2016-04-08 01:57 - 00000000 ____D C:\Users\Owner\Desktop\Printer Stuff
    2016-04-07 21:12 - 2016-04-08 22:45 - 00000000 ____D C:\FRST
    2016-04-07 21:09 - 2016-04-07 21:10 - 02374144 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
    2016-04-07 21:05 - 2016-04-07 21:05 - 01725440 _____ (Farbar) C:\Users\Owner\Downloads\FRST.exe
    2016-04-07 20:57 - 2016-04-07 20:57 - 00002108 _____ C:\Users\Owner\Desktop\aswMBR.txt
    2016-04-07 20:57 - 2016-04-07 20:57 - 00000512 _____ C:\Users\Owner\Desktop\MBR.dat
    2016-04-07 12:21 - 2016-04-07 12:22 - 05198336 _____ (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe
    2016-03-29 11:04 - 2016-03-29 11:04 - 00025348 _____ C:\Users\Owner\Downloads\December 31, 2015.pdf
    2016-03-29 11:03 - 2016-03-29 11:03 - 00025823 _____ C:\Users\Owner\Downloads\November 30, 2015.pdf
    2016-03-29 11:02 - 2016-03-29 11:02 - 00026458 _____ C:\Users\Owner\Downloads\October 31, 2015.pdf
    2016-03-28 01:40 - 2016-03-28 01:40 - 00334830 _____ C:\Users\Owner\Desktop\dxweb(3).pdf
    2016-03-28 01:35 - 2016-03-28 01:35 - 00332458 _____ C:\Users\Owner\Downloads\dxweb(3).pdf
    2016-03-28 01:35 - 2016-03-28 01:35 - 00195170 _____ C:\Users\Owner\Downloads\dxweb(2).pdf
    2016-03-27 02:02 - 2016-03-27 02:02 - 00832505 _____ C:\Users\Owner\Downloads\03-22-2015.pdf
    2016-03-27 01:58 - 2016-03-27 01:58 - 00334830 _____ C:\Users\Owner\Downloads\dxweb(1).pdf
    2016-03-27 01:57 - 2016-03-27 01:57 - 00057703 _____ C:\Users\Owner\Downloads\dxweb.pdf
    2016-03-27 01:53 - 2016-03-27 01:53 - 00020580 _____ C:\Users\Owner\Downloads\eSign.pdf
    2016-03-27 00:56 - 2016-03-27 00:56 - 00617735 _____ C:\Users\Owner\Downloads\document(27).pdf
    2016-03-27 00:55 - 2016-03-27 00:55 - 00914439 _____ C:\Users\Owner\Downloads\document(26).pdf
    2016-03-27 00:53 - 2016-03-27 00:53 - 00439450 _____ C:\Users\Owner\Downloads\document(25).pdf
    2016-03-27 00:52 - 2016-03-27 00:52 - 00497615 _____ C:\Users\Owner\Downloads\document(24).pdf
    2016-03-27 00:51 - 2016-03-27 00:51 - 00440876 _____ C:\Users\Owner\Downloads\document(23).pdf
    2016-03-27 00:50 - 2016-03-27 00:50 - 00441066 _____ C:\Users\Owner\Downloads\document(22).pdf
    2016-03-27 00:49 - 2016-03-27 00:49 - 00440980 _____ C:\Users\Owner\Downloads\document(21).pdf
    2016-03-27 00:48 - 2016-03-27 00:48 - 00582434 _____ C:\Users\Owner\Downloads\document(20).pdf
    2016-03-27 00:47 - 2016-03-27 00:47 - 00580720 _____ C:\Users\Owner\Downloads\document(19).pdf
    2016-03-27 00:46 - 2016-03-27 00:46 - 00357172 _____ C:\Users\Owner\Downloads\document(18).pdf
    2016-03-27 00:45 - 2016-03-27 00:45 - 00246002 _____ C:\Users\Owner\Downloads\document(17).pdf
    2016-03-27 00:43 - 2016-03-27 00:43 - 00306242 _____ C:\Users\Owner\Downloads\document(16).pdf
    2016-03-27 00:40 - 2016-03-27 00:40 - 00242544 _____ C:\Users\Owner\Downloads\document(15).pdf
    2016-03-26 00:44 - 2016-03-26 00:44 - 00000652 _____ C:\Users\Owner\Downloads\export(10).csv
    2016-03-26 00:07 - 2016-03-26 00:07 - 00001643 _____ C:\Users\Owner\Downloads\export(9).csv
    2016-03-26 00:05 - 2016-03-26 00:05 - 00000051 _____ C:\Users\Owner\Downloads\export(8).csv
    2016-03-26 00:03 - 2016-03-26 00:03 - 00001643 _____ C:\Users\Owner\Downloads\export(7).csv
    2016-03-24 09:02 - 2016-04-07 21:03 - 05934784 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2016-03-23 00:20 - 2016-03-23 00:20 - 00264192 _____ C:\Users\Owner\Downloads\Event_Planning_101.ppt
    2016-03-22 00:48 - 2016-03-22 00:49 - 00011227 _____ C:\Users\Owner\Desktop\Family Stuff at Dornbusch.odt
    2016-03-18 17:43 - 2016-03-18 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
    2016-03-11 12:43 - 2016-04-01 16:57 - 00014845 _____ C:\Users\Owner\Desktop\PLANT propagation list 2016.odt
    2016-03-09 07:47 - 2016-02-19 12:02 - 00038336 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
    2016-03-09 07:47 - 2016-02-19 11:54 - 01168896 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2016-03-09 07:47 - 2016-02-19 07:07 - 01373184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2016-03-09 07:47 - 2016-02-11 07:07 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2016-03-09 07:47 - 2016-02-05 07:07 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2016-03-09 07:47 - 2016-02-05 07:07 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2016-03-09 07:47 - 2016-02-05 07:07 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2016-03-09 02:22 - 2016-03-09 02:22 - 02086559 _____ C:\Users\Owner\Downloads\HH Lav Carpet Freshener INDIvidual front label.ai
     
    ==================== One Month Modified files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-04-08 22:49 - 2009-07-13 21:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-04-08 22:49 - 2009-07-13 21:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-04-08 22:42 - 2013-05-08 21:25 - 00000000 ___RD C:\Users\Owner\Dropbox
    2016-04-08 22:42 - 2013-05-08 21:16 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Dropbox
    2016-04-08 22:41 - 2015-07-21 16:14 - 00000902 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
    2016-04-08 22:41 - 2011-04-28 14:27 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-04-08 22:40 - 2014-03-29 22:01 - 00000226 _____ C:\Windows\system32\devicelist.txt
    2016-04-08 22:40 - 2014-03-29 22:01 - 00000226 _____ C:\Windows\system32\devicealertlist.txt
    2016-04-08 22:40 - 2014-03-29 22:01 - 00000015 _____ C:\Windows\system32\deviceAppeared.txt
    2016-04-08 22:40 - 2011-08-11 15:06 - 00000000 ____D C:\ProgramData\NVIDIA
    2016-04-08 22:40 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2016-04-08 22:19 - 2015-07-21 16:14 - 00000906 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
    2016-04-08 22:19 - 2011-04-12 14:23 - 00000000 ____D C:\ProgramData\MFAData
    2016-04-08 22:16 - 2011-03-25 15:22 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-04-08 22:13 - 2012-04-26 17:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2016-04-08 22:02 - 2012-04-05 19:09 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2016-04-08 16:14 - 2011-04-12 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes
    2016-04-08 15:34 - 2010-01-14 01:31 - 00000000 ____D C:\Users\Owner\AppData\Local\ApplicationHistory
    2016-04-08 15:12 - 2016-01-11 22:06 - 00000000 ____D C:\Users\Owner\Documents\Invoices 2016
    2016-04-08 12:44 - 2009-07-13 22:32 - 00000000 ____D C:\Windows\system32\FxsTmp
    2016-04-08 01:47 - 2014-11-01 20:33 - 00000000 ____D C:\Users\Owner\Documents\USLGA
    2016-04-08 01:47 - 2011-10-23 22:06 - 00000000 ____D C:\Users\Owner\Documents\DEQ Pythian Hall Plan
    2016-04-08 01:41 - 2014-09-19 11:49 - 00000000 ____D C:\Users\Owner\Documents\Lavender Festival 2015
    2016-04-08 01:30 - 2016-02-02 20:19 - 00000000 ____D C:\Users\Owner\Documents\Flossie & Stiles
    2016-04-07 21:06 - 2012-04-05 19:09 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2016-04-07 21:05 - 2012-04-05 19:09 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2016-04-07 21:05 - 2011-05-16 00:30 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-04-07 20:50 - 2014-02-09 15:14 - 00000000 ____D C:\Users\Owner\Downloads\WTF is this in this file
    2016-04-06 20:33 - 2011-05-12 21:07 - 00000000 ____D C:\Users\Owner\Documents\Northwest Nectar
    2016-04-05 22:50 - 2009-07-13 22:13 - 00783374 _____ C:\Windows\system32\PerfStringBackup.INI
    2016-04-05 22:50 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
    2016-04-05 20:34 - 2013-04-13 22:56 - 00000000 ____D C:\Users\Owner\Documents\Lavender field plans
    2016-04-01 00:36 - 2011-05-12 21:12 - 00000000 ____D C:\Users\Owner\Documents\Jennifer Stuff
    2016-03-27 04:37 - 2010-01-16 00:36 - 00000000 ____D C:\Users\Owner\AppData\Local\ElevatedDiagnostics
    2016-03-27 00:41 - 2010-04-18 22:01 - 00000000 ____D C:\Users\Owner\Documents\Wayward Winds
    2016-03-26 01:11 - 2013-06-03 16:38 - 00000000 ____D C:\Users\Owner\Documents\Yakima Finances
    2016-03-26 01:11 - 2012-06-02 12:27 - 00000000 ____D C:\Users\Owner\Documents\Yakima Duplex
    2016-03-24 03:01 - 2015-04-04 03:17 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2016-03-24 03:01 - 2015-04-04 03:17 - 00000000 ___SD C:\Windows\system32\GWX
    2016-03-22 15:08 - 2016-02-18 22:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2016-03-18 17:44 - 2015-07-21 16:14 - 00000000 ____D C:\Program Files (x86)\Dropbox
    2016-03-16 15:46 - 2016-03-06 21:21 - 00012780 _____ C:\Users\Owner\Desktop\SHORT LIST.odt
    2016-03-15 20:08 - 2015-06-02 23:15 - 00000000 ____D C:\Users\Owner\Documents\Lavender Festival 2016
    2016-03-12 04:44 - 2015-10-28 15:02 - 00000936 _____ C:\Users\Public\Desktop\AVG Protection.lnk
    2016-03-12 04:44 - 2014-03-31 09:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2016-03-10 14:08 - 2011-04-12 12:23 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2016-03-10 04:00 - 2014-12-10 04:26 - 00000000 ____D C:\Windows\system32\appraiser
    2016-03-09 04:43 - 2009-07-13 21:45 - 02222824 _____ C:\Windows\system32\FNTCACHE.DAT
    2016-03-09 04:09 - 2013-08-15 03:00 - 00000000 ____D C:\Windows\system32\MRT
    2016-03-09 04:00 - 2010-01-12 03:52 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
     
    ==================== Files in the root of some directories =======
     
    2013-05-25 08:48 - 2014-06-02 10:10 - 0003745 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
    2014-02-09 16:15 - 2014-02-09 16:15 - 0000045 _____ () C:\Users\Owner\AppData\Roaming\WB.CFG
    2010-01-29 16:06 - 2015-12-16 07:42 - 0037982 _____ () C:\Users\Owner\AppData\Roaming\wklnhst.dat
    2011-04-14 11:18 - 2011-04-14 11:18 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
     
    Some files in TEMP:
    ====================
    C:\Users\Owner\AppData\Local\Temp\avguirn_081496364364.exe
    C:\Users\Owner\AppData\Local\Temp\libeay32.dll
    C:\Users\Owner\AppData\Local\Temp\msvcr120.dll
    C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
    C:\Users\Owner\AppData\Local\Temp\uninstall.exe
    C:\Users\Owner\AppData\Local\Temp\_is1774.exe
    C:\Users\Owner\AppData\Local\Temp\_is9FD.exe
     
     
    ==================== Bamital & volsnap =================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
     
     
    LastRegBack: 2016-04-08 00:30
     
    ==================== End of FRST.txt ============================
     
     
     
     
     
    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by [removed] (2016-04-08 22:56:47)
    Running from C:\Users\[removed]\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2010-01-12 10:40:03)
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Accounts: =============================
     
    Administrator (S-1-5-21-2522848791-1810669900-1685156444-500 - Administrator - Disabled)
    ASPNET (S-1-5-21-2522848791-1810669900-1685156444-1002 - Limited - Enabled)
    Guest (S-1-5-21-2522848791-1810669900-1685156444-501 - Limited - Enabled)
    HomeGroupUser$ (S-1-5-21-2522848791-1810669900-1685156444-1004 - Limited - Enabled)
    Owner (S-1-5-21-2522848791-1810669900-1685156444-1000 - Administrator - Enabled) => C:\Users\Owner
    UpdatusUser (S-1-5-21-2522848791-1810669900-1685156444-1005 - Limited - Enabled) => C:\Users\UpdatusUser
     
    ==================== Security Center ========================
     
    (If an entry is included in the fixlist, it will be removed.)
     
    AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
     
    ==================== Installed Programs ======================
     
    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
     
    Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.2.443 - Adobe Systems Incorporated)
    Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
    Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\…\{AC76BA86-1033-F400-7760-000000000004}_955) (Version:  - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
    Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe Creative Suite 4 Design Premium (HKLM-x32\…\Adobe_55230b0b70661df0f212e88f0b655f7) (Version: 4.0 - Adobe Systems Incorporated)
    Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
    Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
    Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
    Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
    Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe InDesign CS4 Icon Handler x64 (Version: 6.0 - Adobe Systems Incorporated) Hidden
    Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
    Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
    Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
    Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
    Adobe Reader XI (11.0.15) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.15 - Adobe Systems Incorporated)
    Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
    Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
    Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    AVG (Version: 16.51.7497 - AVG Technologies) Hidden
    AVG 2016 (Version: 16.0.4545 - AVG Technologies) Hidden
    AVG Protection (HKLM\…\AVG) (Version: 2016.51.7497 - AVG Technologies)
    AVG SafeGuard toolbar (HKLM-x32\…\AVG SafeGuard toolbar) (Version: 19.3.0.491 - AVG Technologies)
    Backblaze (HKLM-x32\…\Backblaze) (Version:  - Backblaze, Inc)
    Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
    Canon IJWCS - Common Profile Extention Data (HKLM-x32\…\IJWCS - Common Profile Extention Data) (Version: 1.0.0 - Canon Inc.)
    Canon IJWCS - PRO-1 series Extention Data (HKLM-x32\…\IJWCS - PRO-1 series Extention Data) (Version: 1.0.0 - Canon Inc.)
    Canon IJWCS - PRO-10 series Extention Data (HKLM-x32\…\IJWCS - PRO-10 series Extention Data) (Version: 1.0.0 - Canon Inc.)
    Canon IJWCS - PRO-100 series Extention Data (HKLM-x32\…\IJWCS - PRO-100 series Extention Data) (Version: 1.1.0 - Canon Inc.)
    CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\…\CANON iMAGE GATEWAY Task) (Version: 1.7.0.4 - Canon Inc.)
    Canon Internet Library for ZoomBrowser EX (HKLM-x32\…\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.3.9 - Canon Inc.)
    Canon MOV Decoder (HKLM-x32\…\Canon MOV Decoder) (Version: 1.3.0.14 - Canon Inc.)
    Canon MOV Encoder (HKLM-x32\…\Canon MOV Encoder) (Version: 1.1.0.18 - Canon Inc.)
    Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\…\MovieEditTask) (Version: 3.2.0.34 - Canon Inc.)
    Canon My Image Garden (HKLM-x32\…\Canon My Image Garden) (Version: 2.1.0 - Canon Inc.)
    Canon My Image Garden Design Files (HKLM-x32\…\Canon My Image Garden Design Files) (Version: 2.1.0 - Canon Inc.)
    Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
    Canon Print Studio Pro (HKLM-x32\…\Print Studio Pro) (Version: 1.3.5 - Canon Inc.)
    Canon PRO-100 series On-screen Manual (HKLM-x32\…\Canon PRO-100 series On-screen Manual) (Version: 7.5.0 - Canon Inc.)
    Canon PRO-100 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_PRO-100_series) (Version:  - Canon Inc.)
    Canon PRO-100 series User Registration (HKLM-x32\…\Canon PRO-100 series User Registration) (Version:  - Canon Inc.‎)
    Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.)
    Canon Utilities CameraWindow (HKLM-x32\…\CameraWindowLauncher) (Version: 7.2.0.2 - Canon Inc.)
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC6) (Version: 6.5.0.3 - Canon Inc.)
    Canon Utilities Digital Photo Professional 3.6 (HKLM-x32\…\DPP) (Version: 3.6.0.0 - Canon Inc.)
    Canon Utilities EOS Utility (HKLM-x32\…\EOS Utility) (Version: 2.6.0.0 - Canon Inc.)
    Canon Utilities MyCamera (HKLM-x32\…\MyCamera) (Version: 7.2.0.4 - Canon Inc.)
    Canon Utilities PhotoStitch (HKLM-x32\…\PhotoStitch) (Version: 3.1.22.46 - Canon Inc.)
    Canon Utilities Picture Style Editor (HKLM-x32\…\Picture Style Editor) (Version: 1.5.0.0 - Canon Inc.)
    Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\…\RemoteCaptureTask) (Version: 1.8.0.1 - Canon Inc.)
    Canon Utilities WFT-E1/E2/E3/E4 Utility (HKLM-x32\…\WFTK) (Version: 3.3.0.0 - Canon Inc.)
    Canon Utilities ZoomBrowser EX (HKLM-x32\…\ZoomBrowser EX) (Version: 6.3.1.8 - Canon Inc.)
    Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\…\ZoomBrowser EX Memory Card Utility) (Version: 1.2.2.11 - Canon Inc.)
    Cisco WebEx Meetings (HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
    Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
    Dropbox (HKLM-x32\…\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
    Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
    Epson Connect (HKLM-x32\…\{64BA551C-9AF6-495C-93F3-D1270E0045FC}) (Version:  - )
    Epson Customer Participation (HKLM\…\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.0.0.0 - SEIKO EPSON CORPORATION)
    Epson Download Navigator (HKLM-x32\…\{10F63395-157F-4B93-AB4D-702A2FF11942}) (Version: 1.0.1 - SEIKO EPSON CORPORATION)
    Epson Print CD (HKLM-x32\…\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.05.00 - SEIKO EPSON CORPORATION)
    EPSON Printer Software (HKLM\…\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
    Epson Professional Print Sample (HKLM-x32\…\{E7B46D0D-A63D-42AB-9D1D-75A88C280F78}) (Version:  - )
    EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - )
    Epson Stylus Photo R2000 Printer Uninstall (HKLM\…\Epson Stylus Photo R2000) (Version:  - SEIKO EPSON Corporation)
    EPSON WP-4020 Series Printer Uninstall (HKLM\…\EPSON WP-4020 Series) (Version:  - SEIKO EPSON Corporation)
    FMW 1 (Version: 1.72.2 - AVG Technologies) Hidden
    Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
    iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
    iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
    Java 8 Update 31 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation)
    Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
    Java(TM) 6 Update 22 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.220 - Oracle)
    kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
    LaCie Desktop Manager 1.7.0 (HKLM\…\{3845209F-142E-4F48-B61A-AA34D2DB54BB}_is1) (Version: 1.7.0 - LaCie)
    LTCM Client (HKLM-x32\…\LTCM Client) (Version:  - Leader Technologies Inc.)
    Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
    Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
    Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
    Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Web Publishing Wizard 1.52 (HKLM-x32\…\WebPost) (Version:  - )
    Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
    MobileMe Control Panel (HKLM\…\{41BC9E31-0D39-462E-8E4C-767B21A3B1C3}) (Version: 3.1.8.0 - Apple Inc.)
    Mozilla Firefox 45.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 45.0.1 (x86 en-US)) (Version: 45.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
    Mozilla Thunderbird 38.7.2 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 38.7.2 (x86 en-US)) (Version: 38.7.2 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MyFonts Order M1374621 (HKLM-x32\…\{89F95935-E17D-DE19-C100-5F1991151CBD}) (Version: 1.0 - MyFonts.com, Inc.)
    Nero 8 Essentials (HKLM-x32\…\{E13AA9BC-0C88-46F8-B4CC-CA32A81A1033}) (Version: 8.3.401 - Nero AG)
    NVIDIA 3D Vision Driver 311.06 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
    NVIDIA Graphics Driver 311.06 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.2.23.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.2.23.3 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.10.0514 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
    NVIDIA Update 1.11.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
    OpenOffice.org 3.1 (HKLM-x32\…\{E6B87DC4-2B3D-4483-ADFF-E483BF718991}) (Version: 3.1.9399 - OpenOffice.org)
    PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
    Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
    Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
    Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
    Pixel Bender Toolkit (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
    QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    RAR File Open Knife - Free Opener (HKLM-x32\…\RAR File Open Knife - Free Opener) (Version: 3.50 - Philipp Winterberg)
    RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
    RealPlayer (HKLM-x32\…\RealPlayer 12.0) (Version:  - RealNetworks)
    RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
    Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
    Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
    Spyder4Elite (HKLM-x32\…\Spyder4Elite) (Version:  - )
    SSC Service Utility v4.30 (HKLM-x32\…\SSC Service Utility_is1) (Version:  - SSC Localization Group)
    Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
    The Print Shop 23 (HKLM-x32\…\{11F7808F-76AD-40E0-A8D9-6445DAEA3F5D}) (Version: 23.00.00 - Broderbund Software)
    VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
    Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\…\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
    Visual Studio 2008 x64 Redistributables (HKLM-x32\…\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
    Visual Studio 2010 x64 Redistributables (HKLM\…\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
    Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Xvid 1.2.1 final uninstall (HKLM-x32\…\Xvid_is1) (Version: 1.2 - Xvid team (Koepi))
     
    ==================== Custom CLSID (Whitelisted): ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== Scheduled Tasks (Whitelisted) =============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    Task: {0EB9C1A5-3769-41E3-A453-F43CA4521B13} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2522848791-1810669900-1685156444-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-01-24] (RealNetworks, Inc.)
    Task: {0F31EA49-B605-4F22-BCD8-1D7D442BFB50} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated)
    Task: {29DBF75D-9A0E-4A9D-A06E-2CBDEE4A8895} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-21] (Dropbox, Inc.)
    Task: {2A56E453-D926-439F-8006-A82CB2259031} - System32\Tasks\{85A23A3C-9E72-43A6-8223-E68BC1E3594C} => pcalua.exe -a C:\Users\Owner\Downloads\sscserve(1).exe -d C:\Users\Owner\Downloads
    Task: {307186D2-0682-44A7-A62F-4D1B6CC775FB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
    Task: {4335E81C-ACC1-415F-9FE0-CDD206458BF8} - System32\Tasks\{AA1963FF-60BA-45EC-AA73-0ECD1CA18B1C} => pcalua.exe -a C:\epson\epson12335_R2400_printer_driver_650das\SETUP\SETUP64.EXE -d C:\epson\epson12335_R2400_printer_driver_650das\SETUP
    Task: {4C5B65BC-BEE9-464A-8BD2-0E4FBD51D736} - System32\Tasks\{F752A472-11A3-45FB-B5B7-D0F86C92E148} => pcalua.exe -a C:\epson\epson12335_R2400_printer_driver_650das\SETUP\E_SCHK03.EXE -d C:\epson\epson12335_R2400_printer_driver_650das\SETUP
    Task: {4E707F79-BF8C-4C42-B257-1C7186C5DD79} - System32\Tasks\{13AD8D12-2E66-43AA-BABA-A9E55734033A} => C:\Program Files (x86)\The Print Shop 23\PMW.exe [2008-07-16] (Broderbund Properties LLC)
    Task: {65769BB4-6B81-4E28-AADE-666166E85703} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-21] (Dropbox, Inc.)
    Task: {6B21E17A-EDF8-41B7-8FBC-CF6306368958} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {6F4FB8D7-5A29-4520-A6B5-35BAD7661B28} - System32\Tasks\{DC361E74-DD64-408A-A954-E5473ED2C25C} => pcalua.exe -a C:\epson\epson12335_R2400_printer_driver_650das\SETUP\RESCAN.EXE -d C:\epson\epson12335_R2400_printer_driver_650das\SETUP
    Task: {708FDB45-C84E-449B-A596-D902F9330E36} - System32\Tasks\{AF61108E-FDD8-4572-9F61-03167E208D55} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NA2JJ0D1\Thunderbird%20Setup%203.0[1].exe" -d C:\Users\Owner\Desktop
    Task: {76D51FAD-B02A-4639-B739-4F904146383C} - System32\Tasks\{A8A9B129-A267-4713-9ED2-DD7824EB01D2} => pcalua.exe -a D:\English\Guide\setup.exe -d D:\English\Guide
    Task: {8B2935F2-2A10-4D2D-92B0-D05FAEAF783C} - System32\Tasks\{3EDB2623-5612-4759-9F6D-FF5FCAA9C68C} => pcalua.exe -a C:\Users\Owner\Downloads\epson12335(6).exe -d C:\Users\Owner\Downloads
    Task: {8DEF9A29-4689-4B41-AD31-155E6B78D0CC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {8E2C05EB-5389-448E-B86A-C16754FF2705} - System32\Tasks\{C5BD492C-17B5-4FED-8C84-420EFD77CF05} => pcalua.exe -a D:\Setup.exe -d D:\
    Task: {918F7291-57DC-41F1-A8AA-38A7493F8137} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2013-09-20] (Safer-Networking Ltd.)
    Task: {A4B92EF4-C0C8-4325-AE79-143A78D3094F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2522848791-1810669900-1685156444-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-01-24] (RealNetworks, Inc.)
    Task: {AB64741F-EBF0-4EC3-A330-A81E6192A175} - \DigitalSite -> No File <==== ATTENTION
    Task: {B1593518-7043-4D10-A139-92A168E9C5C3} - System32\Tasks\{F75E852D-9AFE-45D4-BCA3-A831F3CF9890} => pcalua.exe -a C:\Users\Owner\Downloads\XvidSetup.exe -d "C:\Program Files (x86)\Mozilla Firefox"
    Task: {D4AC9FB3-39DD-4A1F-8E18-FDCF2BDF0604} - System32\Tasks\{E0065FCA-6F81-47B3-AC5C-57B8D4DC1F0D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\The Print Shop 23\PMW.exe"
    Task: {E37F7EEE-7185-45EE-B3CE-0371B3BABBB1} - System32\Tasks\{F4B1FD3F-C641-4E57-867B-EE353C9305D9} => pcalua.exe -a D:\Setup.exe -d D:\
    Task: {E49F5D9B-1970-4A9B-A80F-D4675B962DB1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2013-09-20] (Safer-Networking Ltd.)
    Task: {EA4F35A8-C56A-4FE1-9A98-49B7FA780C3C} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2522848791-1810669900-1685156444-1000
    Task: {F775DCEF-91BA-433F-B26C-8DB002770DAE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {F7D9DEF2-531D-4D1F-8F34-34C9DD5D5158} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2013-09-20] (Safer-Networking Ltd.)
     
    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
     
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
     
    ==================== Shortcuts =============================
     
    (The entries could be listed to be restored or removed.)
     
    ==================== Loaded Modules (Whitelisted) ==============
     
    2012-11-18 04:02 - 2013-01-18 08:00 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2012-12-06 02:09 - 2015-05-15 17:37 - 00235712 _____ () C:\Program Files (x86)\Backblaze\bzserv.exe
    2014-03-29 22:01 - 2013-09-19 12:00 - 01380352 _____ () C:\Program Files\LaCie\Desktop Manager\lacie_dm_service.exe
    2012-12-06 02:09 - 2015-05-15 17:37 - 00490176 _____ () C:\Program Files (x86)\Backblaze\bzbui.exe
    2014-03-29 22:01 - 2013-09-19 11:58 - 03461120 _____ () C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe
    2012-12-06 02:09 - 2015-05-15 17:37 - 00304320 _____ () C:\Program Files (x86)\Backblaze\bzfilelist.exe
    2014-10-11 14:06 - 2014-10-11 14:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-02-09 20:05 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    2014-02-09 20:05 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2014-02-09 20:05 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    2014-02-09 20:05 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    2014-02-09 20:05 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00139264 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\Appearance Pak.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00151552 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\RegEx.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 12977947 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\RBScript.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00098304 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\Shell.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00761856 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\XML.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00274432 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\CGamma.dll
    2011-08-09 17:06 - 2012-02-07 15:59 - 00086016 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\CSensor.dll
    2011-09-22 16:22 - 2012-02-07 15:59 - 00039936 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\MBSRegistrationPlugin16724.dll
    2011-09-22 16:22 - 2012-02-07 15:59 - 00025600 _____ () C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility Libs\MBSPluginVersionPlugin16724.dll
    2016-03-18 17:43 - 2016-02-23 11:19 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
    2016-03-18 17:43 - 2016-02-23 11:19 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
    2016-03-18 17:43 - 2016-03-11 17:18 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00112592 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_python_x66cf7a7cx17a72769.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
    2016-03-18 17:43 - 2016-03-11 17:18 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
    2016-03-18 17:43 - 2016-02-23 11:19 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00021824 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
    2016-03-18 17:42 - 2016-03-11 17:18 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
    2016-03-18 17:43 - 2016-02-23 11:21 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00084792 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
    2016-03-18 17:43 - 2016-03-11 17:18 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
    2016-03-18 17:43 - 2016-02-23 11:20 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00158008 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
    2016-03-18 17:43 - 2016-02-23 11:23 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
    2016-03-18 17:43 - 2016-02-23 11:23 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
    2016-03-18 17:43 - 2016-03-11 17:18 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
    2016-03-18 17:43 - 2016-03-11 17:18 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
    2016-03-18 17:43 - 2016-02-23 11:25 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
    2015-10-28 14:36 - 2016-04-07 10:07 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
    2016-04-08 10:28 - 2016-04-08 10:28 - 00153032 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
    2016-04-08 10:28 - 2016-04-08 10:28 - 00022472 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
     
    ==================== Alternate Data Streams (Whitelisted) =========
     
    (If an entry is included in the fixlist, only the ADS will be removed.)
     
    AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [252]
     
    ==================== Safe Mode (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
     
     
    ==================== EXE Association (Whitelisted) ===============
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
     
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Classes\.exe: exefile =>  <===== ATTENTION
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Software\Classes\exefile:  <===== ATTENTION
     
    ==================== Internet Explorer trusted/restricted ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry.)
     
     
    ==================== Hosts content: ===============================
     
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
     
    2009-07-13 19:34 - 2015-01-01 14:59 - 00000042 ____A C:\Windows\system32\Drivers\etc\hosts
     
    ::1 localhost
    127.0.0.1       localhost
     
    ==================== Other Areas ============================
     
    (Currently there is no automatic fix for this section.)
     
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
    DNS Servers: 208.67.220.220 - 208.67.222.222
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.
     
    ==================== MSCONFIG/TASK MANAGER disabled items ==
     
    (Currently there is no automatic fix for this section.)
     
    MSCONFIG\Services: Adobe Version Cue CS4 => 3
    MSCONFIG\Services: BDESVC => 3
    MSCONFIG\Services: EFS => 2
    MSCONFIG\Services: gupdate => 2
    MSCONFIG\Services: gusvc => 3
    MSCONFIG\Services: idsvc => 3
    MSCONFIG\Services: napagent => 3
    MSCONFIG\Services: Nero BackItUp Scheduler 3 => 2
    MSCONFIG\Services: netprofm => 3
    MSCONFIG\Services: NlaSvc => 2
    MSCONFIG\Services: PLFlash DeviceIoControl Service => 2
    MSCONFIG\Services: SharedAccess => 2
    MSCONFIG\Services: Wlansvc => 3
    MSCONFIG\Services: wmiApSrv => 3
    MSCONFIG\Services: WMPNetworkSvc => 2
    MSCONFIG\Services: WPCSvc => 3
    MSCONFIG\Services: wscsvc => 2
    MSCONFIG\Services: WSearch => 2
    MSCONFIG\Services: WwanSvc => 3
    MSCONFIG\startupfolder: C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => C:\Windows\pss\OpenOffice.org 3.1.lnk.Startup
    MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    MSCONFIG\startupreg: EPSON Stylus Photo R2400 => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATI9SA.EXE /FU "C:\Windows\TEMP\E_S3745.tmp" /EF "HKCU"
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: NBKeyScan => "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    MSCONFIG\startupreg: TkBellExe => "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
     
    ==================== FirewallRules (Whitelisted) ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    FirewallRules: [{CA064AE9-C1E6-4344-92D1-622021F8F058}] => (Allow) LPort=5353
    FirewallRules: [{D76F7A57-5C9F-405A-840A-6A06E066B070}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
    FirewallRules: [{912D0C27-FDCB-4D3B-A2D1-B26D62A2B362}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
    FirewallRules: [{D3D09705-D450-41DF-9F17-54F73B0C187C}] => (Allow) LPort=3703
    FirewallRules: [{BD812B1E-3515-4C2F-B5F4-58A8D0F22815}] => (Allow) LPort=3704
    FirewallRules: [{E016C6EE-41D2-4527-BB82-EA411DE8B558}] => (Allow) LPort=51000
    FirewallRules: [{C74980A2-3522-4223-8360-5FBC87D7FFD6}] => (Allow) LPort=51001
    FirewallRules: [{0D3A0EF6-E668-4B96-B74E-12FA64FD8D24}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    FirewallRules: [{6A08B976-39FC-4E9E-9CD2-6AFA9BC42895}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    FirewallRules: [{001C107C-7F67-4BA9-BC35-D9F764D3FA42}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{DCC33B8A-2F02-42DA-9EA9-F155511BFA4B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [TCP Query User{E778489B-2DC2-42D7-B0A2-9572422F427F}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
    FirewallRules: [UDP Query User{FF882A05-0A7C-4DA0-BED7-27DAC0D5AAB4}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
    FirewallRules: [{822B53A7-4D40-4AD3-BA25-A109AEFBEA57}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe
    FirewallRules: [{B2E53A26-AA71-4FFF-8C0B-9F79B43743E5}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe
    FirewallRules: [{57FA5759-AECD-467D-BCF8-733FF2C3F089}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    FirewallRules: [{7D143370-9561-41FE-8A4C-04469ECA81BB}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    FirewallRules: [{E173D5FE-8455-4F2E-BC2D-F3317E3C3636}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{568A4863-9D7D-4055-B0DC-0EAD0C8263A6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{6D831140-E026-4126-BFA1-50BDF278F9C8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{47C7C843-84C6-44B3-8523-3A98A17FBA12}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{43EE03BE-A23B-4424-8E72-C50FB1114917}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
    FirewallRules: [{40CF77FC-67C3-442A-8422-D12A8053C2C1}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
    FirewallRules: [{B7C58480-4999-474A-9215-345B4CCB8051}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
    FirewallRules: [{235BDE70-A5E9-4B33-B450-8C0A975202A0}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
    FirewallRules: [{A32885EE-C0C7-4AD7-8C48-FDD8BAA3A069}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{C0A5D85D-E096-417A-B94F-49DA728DDE50}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{9FF5FD6D-97B5-4FB0-99CE-1AF7718E0A50}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
    FirewallRules: [{BD0FB7B6-BC09-4558-B558-3BBE7601F326}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
    FirewallRules: [{EDBEE052-0383-4F37-A601-A7E0A2270E98}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
    FirewallRules: [{40AB1D22-E761-4A4A-8D54-EF0D3311716D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{0A7E168D-0785-45FD-AEDF-BAB7F21D1135}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [TCP Query User{B2EE3B71-AED0-48A7-B107-2BF345F3683E}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
    FirewallRules: [UDP Query User{8DF2C3A2-99C2-4E93-854C-14D80A17D0F0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
    FirewallRules: [{5957264C-18A5-4D1F-8C7A-76AC53F4A7C0}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{34D29ED6-0D3B-4A27-8BCC-C9D68C0CF82B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{157B9F39-6B11-4D2F-AF0E-6C3829BD86B6}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{720C2848-4736-4407-9EC2-302BA033DD97}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{45E4342B-D21A-4C91-B076-71B41F3F11B0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{E35C6558-D831-4709-BB1C-69D6E8F6B99E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{DA033A23-700F-4B92-BFDD-65755AC2D17D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{4D063B67-E123-4C5B-8148-26CD52FA0B4B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{6B46406A-265E-4B8D-9DF5-A14111866475}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D; 2 Tray Icon
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
     
    ==================== Restore Points =========================
     
    ATTENTION: System Restore is disabled
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
    Error: (04/08/2016 03:58:28 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: plugin-container.exe, version: 45.0.1.5918, time stamp: 0x56e8b7df
    Faulting module name: mozglue.dll, version: 45.0.1.5918, time stamp: 0x56e8a981
    Exception code: 0x80000003
    Fault offset: 0x0000f0ea
    Faulting process id: 0x1b2c
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3
     
    Error: (04/08/2016 01:42:02 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
    Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
     
    Error: (04/08/2016 01:42:02 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
    Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
     
    Error: (04/08/2016 01:41:50 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
    Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
     
    Error: (04/05/2016 08:36:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Illustrator.exe version 14.0.128.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
     
    Process ID: 226c
     
    Start Time: 01d18beaadb6aae5
     
    Termination Time: 239
     
    Application Path: C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Support Files\Contents\Windows\Illustrator.exe
     
    Report Id: 9ffb0790-fba8-11e5-8dba-4061865cd330
     
    Error: (03/18/2016 01:20:42 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: plugin-container.exe, version: 44.0.2.5884, time stamp: 0x56bbf417
    Faulting module name: NPSWF32_21_0_0_182.dll, version: 21.0.0.182, time stamp: 0x56de03b2
    Exception code: 0x80000003
    Fault offset: 0x003bcafd
    Faulting process id: 0x698
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3
     
    Error: (03/16/2016 03:34:34 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: CNQMUPDT.EXE, version: 2.0.0.0, time stamp: 0x4f7a7000
    Faulting module name: CNMDWLD.DLL, version: 1.0.0.0, time stamp: 0x4f5eedc8
    Exception code: 0xc0000005
    Fault offset: 0x000023c6
    Faulting process id: 0x1710
    Faulting application start time: 0xCNQMUPDT.EXE0
    Faulting application path: CNQMUPDT.EXE1
    Faulting module path: CNQMUPDT.EXE2
    Report Id: CNQMUPDT.EXE3
     
    Error: (03/16/2016 05:40:40 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: plugin-container.exe, version: 44.0.2.5884, time stamp: 0x56bbf417
    Faulting module name: mozglue.dll, version: 44.0.2.5884, time stamp: 0x56bbe58e
    Exception code: 0x80000003
    Fault offset: 0x0000ed3b
    Faulting process id: 0x1798
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3
     
    Error: (03/09/2016 01:44:07 PM) (Source: MsiInstaller) (EventID: 1024) (User: Owner-PC)
    Description: Product: Adobe Reader XI (11.0.14) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011015}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
     
    Error: (03/03/2016 11:51:49 AM) (Source: MsiInstaller) (EventID: 1024) (User: Owner-PC)
    Description: Product: Adobe Reader XI (11.0.13) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011014}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
     
     
    System errors:
    =============
    Error: (04/08/2016 11:03:04 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 11:02:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 11:02:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 11:00:33 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 10:45:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 10:43:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
    %%1069
     
    Error: (04/08/2016 10:43:19 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
    Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
    %%1330
     
    To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
     
    Error: (04/08/2016 10:42:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 10:42:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
    Error: (04/08/2016 10:42:36 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
    %%1058
     
     
    CodeIntegrity:
    ===================================
      Date: 2011-04-12 12:19:01.485
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2011-04-12 12:19:01.470
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
     
    ==================== Memory info =========================== 
     
    Processor: AMD Athlonâ„¢ II X2 240 Processor
    Percentage of memory in use: 45%
    Total physical RAM: 4095.18 MB
    Available physical RAM: 2241.76 MB
    Total Virtual: 8188.57 MB
    Available Virtual: 4727 MB
     
    ==================== Drives ================================
     
    Drive c: () (Fixed) (Total:931.41 GB) (Free:246.45 GB) NTFS
    Drive d: (May 25 2014) (CDROM) (Total:0.69 GB) (Free:0.59 GB) UDF
    Drive j: (LACIE SHARE) (Fixed) (Total:23.99 GB) (Free:23.99 GB) FAT32
    Drive k: (LaCie) (Fixed) (Total:3702.02 GB) (Free:3075.76 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 256D4294)
    Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
    Attempted reading MBR returned 0 bytes.
     Could not read MBR for disk 1.
     
    ==================== End of Addition.txt ============================

    Morning

     

    Your logs look so much better , just a few things to fix

     

     

    After you run the fix , Fixlist will be gone and replaced by a Fixlog, post it please, also let me know if you see any improvement with system performance 

     

     

    Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
    Please copy the entire contents Inside of the code box below beginning with START and ending with END
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
     
    Start
    CloseProcesses:
    CreateRestorePoint: 
    HKLM-x32\…\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OUFWRlJFRS1WMEtNQy1FOVZVVy1FVzBWQS1VVTNYTC1GRVc5Ny1PVTZF"&"inst=NzctNTkwNjcxMzQzLUZQOSs2LUJBUjlHKzEtVEI5KzItRkwrOS1YTzM2 (the data entry has 114 more characters).
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-2522848791-1810669900-1685156444-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-21-2522848791-1810669900-1685156444-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    Task: {B1593518-7043-4D10-A139-92A168E9C5C3} - System32\Tasks\{F75E852D-9AFE-45D4-BCA3-A831F3CF9890} => pcalua.exe -a C:\Users\Owner\Downloads\XvidSetup.exe -d "C:\Program Files (x86)\Mozilla Firefox"
    CMD: ipconfig /flushdns
    Hosts:
    EmptyTemp:
    End
    
     
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

     

    Hi,  tried to write back but no reply box! Just figured out that I wasn't logged in LOL    Here is the Fixlog

     

    The computer is still freezing up, but not as bad.

     

    NEW issue, whenever I try to open a graphics file (Adobe Illustrator) I get a message that says there is not enough memory to open the file. It used to do that occasionally when I was working in really big complicated files. But now I can't even open a small file.

     

    Not sure whats going on, maybe a windows problem, the Fixlog showed that it could not create a new restore point.

     

    Lets run a free online virus scanner, if it comes back ok, then I will send you to our windows forum and see what they can find wrong with Windows

     

    Please run this free online virus scanner from ESET
    •  
       
    • Note: It will run using Internet Explorer, Firefox or Chome.
       
    • Tick the box next to YES, I accept the Terms of Use.
       
    • Click Start
       
    • When asked, allow the activex control to install
       
    • Click Start
       
    • Make sure that the option Remove found threats is NOT TICKED, and the option Scan unwanted applications is checked
       
    • Click Scan
       
    • Wait for the scan to finish
       
    • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
       
    • Copy and paste that log as a reply to this topic
     

    Ok, that took awhile. I didn't see a remove threats box to not tick. I think it may have cleaned the files. There were only 4 total. I can open Illustrator now, but still get the "not enough memory" message with some files.   Thanks!

    Attachments:

    Good Morning,

     

    Those 4 files where in your Downloads folder and are most likely responsible for installing some of the garbage that we removed. But there gone now.

     

    Your computer now appears to be clean. 

     

    not enough memory to open the file <——When I Google this it brings up a lot of issues. Something is not right, could be conflicting programs or the OS itself

     

    Go ahead and post in our Windows forum, tell them about the issues your having, also link them to this thread so they can see what we have done and they will know your computer is now clean and they can look further into the problem

     

    https://forums.whatthetech.com/index.php?showforum=119    <—Post here

     

     

    Double click on AdwCleaner.exe to run the tool again.
    •  
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.
     
     
     
    ==========================================================
     
     
    Please download DelFix and save the file to your Desktop.
     
    [external image: DelFix_zps139e2ea1.jpg]
     
    •  
    • Windows XP Double Click DelFix.exe to run the program. 
    • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
    • Checkmark " Remove Disinfection Tools"
    • Click the Run button
     
     
    This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
     
     
     
     
    So How did I get infected in the first place <– Some reading for you to keep yourself safe online
     
     
    Safe Surfn
    Ken
     
     
     

     

     

     

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI