Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Slow computer and lockups


  • This topic is locked This topic is locked
15 replies to this topic

#1 MrRay1968

MrRay1968

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 09 September 2016 - 02:32 PM

My computer is very slow and tends to lockup when in use.  The mouse and the keyboard freeze and then after a bit start to work again. In looking at the various tools I see that when it is locked or frozen the CPU usage is at 100% but the ram is never at max.  Also it never seems to use all my installed ram

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by Ray (administrator) on RAY-HP7PRO (09-09-2016 12:13:19)
Running from C:\Users\Ray\Desktop
Loaded Profiles: Ray (Available Profiles: Ray & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21384 2016-04-19] (Western Digital Technologies, Inc.)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\...\Policies\Explorer: [NoDrives] 214656
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\...\MountPoints2: {0a7eea20-a255-11e2-93ce-001fc69fadf1} - O:\TLBootstrap_WPP.exe
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\...\MountPoints2: {9ec88beb-1c73-11e2-be20-001fc69fadf1} - M:\LaunchU3.exe -a
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\...\MountPoints2: {d485a8ac-1ad4-11e2-a89d-001fc69fadf1} - U:\LaunchU3.exe -a
HKU\S-1-5-18\...\RunOnce: [{91120000-0014-0000-0000-0000000FF1CE}] => C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} =>  No File
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} =>  No File
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} =>  No File
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} =>  No File
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} =>  No File
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
GroupPolicyScripts: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{66FA82F1-D4A0-431C-86F0-51A99E4AEFDC}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://att.net/
URLSearchHook: HKU\S-1-5-21-1698355976-1673233905-4234267092-1001 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-1698355976-1673233905-4234267092-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-1698355976-1673233905-4234267092-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} -  No File
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)

FireFox:
========
FF ProfilePath: C:\Users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\mpsrd2k8.default
FF DefaultSearchEngine: Bing
FF SelectedSearchEngine: Bing
FF SearchEngineOrder.3: Bing
FF Keyword.URL: hxxp://www.bing.com/search?FORM=SL5JDF&PC=SL5J&q=
FF Homepage: hxxp://www.msn.com/?pc=SL5J&ocid=SL5JDHP&osmkt=en-us
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\mpsrd2k8.default\searchplugins\bing-.xml [2016-03-04]
FF Extension: (Bing Search) - C:\Users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\mpsrd2k8.default\Extensions\bingsearch.full@microsoft.com.xpi [2016-03-04]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-05-03] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-05-03] (Dropbox, Inc.)
S4 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
S4 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
S4 pcCMService; C:\Program Files (x86)\Common Files\Motive\pcCMService.exe [361472 2012-03-13] (Alcatel-Lucent) [File not signed]
S4 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [441344 2012-03-13] (Alcatel-Lucent) [File not signed]
S4 pcServiceHost; C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe [342528 2013-01-01] (Alcatel-Lucent) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7248144 2016-08-08] (TeamViewer GmbH)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [254232 2016-09-07] (RaMMicHaeL)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1049464 2016-04-19] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [314744 2016-04-19] (Western Digital Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 WD Backup Drive Helper; C:\Windows\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B}
S3 WD Backup Snapshot; C:\Windows\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD}

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-12-18] () [File not signed]
S3 ampa; C:\Windows\SysWOW64\ampa.sys [14448 2013-12-18] () [File not signed]
S3 avisfltr; C:\Windows\System32\DRIVERS\avisfltr.sys [388168 2013-01-19] (BitDefender)
R3 CAXHWBS3; C:\Windows\System32\DRIVERS\CAXHWBS3.sys [288256 2009-06-30] (Conexant Systems, Inc.)
S3 DigiartyVirtualCDBus; C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys [276256 2015-11-03] (Digiarty Software, Inc.)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [77040 2012-11-08] (Fresco Logic)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-06-06] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [47104 2016-05-20] ()
R3 MODEMCSA; C:\Windows\System32\drivers\MODEMCSA.sys [24064 2009-07-13] (Microsoft Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2012-03-13] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2012-03-13] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2012-03-13] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2012-03-13] (Printing Communications Assoc., Inc. (PCAUSA))
R3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [2473616 2014-12-10] (MediaTek Inc.)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32568 2015-08-16] (EldoS Corporation)
S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [141384 2010-11-11] (MCCI Corporation)
S3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [203264 2011-11-14] (VIA Technologies, Inc.)
R3 WirelessKeyboardFilter; C:\Windows\System32\DRIVERS\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2016-01-18] (wisecleaner.com)
S3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2011-11-14] (VIA Technologies, Inc.)
U3 DfSdkS; no ImagePath
S4 mfehidk01; \Device\mfehidk01.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-09 12:13 - 2016-09-09 12:14 - 00014165 _____ C:\Users\Ray\Desktop\FRST.txt
2016-09-09 12:13 - 2016-09-06 11:37 - 02397696 _____ (Farbar) C:\Users\Ray\Desktop\FRST64.exe
2016-09-09 12:12 - 2016-09-09 12:13 - 00000000 ____D C:\FRST
2016-09-09 11:41 - 2016-09-09 11:42 - 04341113 _____ C:\Users\Ray\Downloads\WD_Quick_View_Setup_for_Windows.zip
2016-09-09 11:28 - 2016-09-09 11:28 - 00001072 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2016-09-09 11:28 - 2016-09-09 11:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-09-09 11:20 - 2016-09-09 11:20 - 00002151 _____ C:\Users\Public\Desktop\WD Backup.lnk
2016-09-09 11:20 - 2016-09-09 11:20 - 00000000 ____D C:\Users\Ray\Downloads\WD_Backup_1.5.5953.19614
2016-09-09 11:03 - 2016-09-09 11:03 - 08497626 _____ C:\Users\Ray\Downloads\WDSync_1.3.5949.26210.zip
2016-09-09 10:59 - 2016-09-09 10:59 - 00000000 ____D C:\Users\Ray\AppData\Roaming\Western Digital
2016-09-09 10:54 - 2016-09-09 10:55 - 06418572 _____ C:\Users\Ray\Downloads\WD_Backup_1.5.5953.19614.zip
2016-09-09 10:49 - 2016-09-09 10:50 - 63849440 _____ C:\Users\Ray\Downloads\WDMyCloud_win.exe
2016-09-07 14:11 - 2016-09-07 14:11 - 00000000 ____D C:\ProgramData\Unchecky
2016-09-07 14:11 - 2016-09-07 14:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky
2016-09-07 14:11 - 2016-09-07 14:11 - 00000000 ____D C:\Program Files (x86)\Unchecky
2016-09-07 14:10 - 2016-09-07 14:10 - 00000860 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-09-06 11:49 - 2016-09-06 11:49 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-09-06 11:49 - 2016-09-06 11:49 - 00002017 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-09-06 11:25 - 2016-09-09 11:30 - 00000000 ____D C:\Users\Ray\Desktop\computer cleaning tools
2016-09-06 11:21 - 2016-09-06 11:21 - 00000000 ____D C:\Users\Ray\Downloads\AdbeRdr11000_mui_Std
2016-09-02 17:42 - 2016-09-02 17:42 - 00172515 _____ C:\Users\Ray\Downloads\3516.pdf
2016-09-02 17:14 - 2016-09-02 17:14 - 00105845 _____ C:\Users\Ray\Downloads\f4506a.pdf
2016-09-02 17:14 - 2016-09-02 17:14 - 00100400 _____ C:\Users\Ray\Downloads\f4506t.pdf
2016-09-02 17:04 - 2016-09-02 17:04 - 00094862 _____ C:\Users\Ray\Downloads\f4506.pdf
2016-09-02 16:44 - 2016-09-02 16:44 - 00000000 ____D C:\ProgramData\Caphyon
2016-09-02 16:43 - 2016-09-06 11:54 - 00000000 ____D C:\Program Files (x86)\Free PDF Soulutions
2016-09-02 16:40 - 2016-09-02 16:40 - 06728584 _____ (Free PDF Soulutions) C:\Users\Ray\Downloads\Free PDF Reader.exe
2016-09-02 16:40 - 2016-09-02 16:40 - 00000000 ____D C:\Users\Ray\AppData\Roaming\Free PDF Soulutions
2016-09-02 16:14 - 2016-09-02 16:14 - 00094862 _____ C:\Users\Ray\Downloads\f4506--2015.pdf
2016-09-02 15:32 - 2016-09-02 15:34 - 00000000 ____D C:\ProgramData\WRData
2016-08-25 09:52 - 2016-07-08 08:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-08-25 09:52 - 2016-07-08 08:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-08-25 09:48 - 2016-07-07 08:36 - 01896168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2016-08-25 09:48 - 2016-07-07 08:36 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2016-08-25 09:48 - 2016-07-07 08:36 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2016-08-25 09:48 - 2016-07-07 08:08 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2016-08-25 09:48 - 2016-07-01 08:31 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-08-25 09:48 - 2016-07-01 08:31 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-08-25 09:48 - 2016-07-01 08:13 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-08-25 09:48 - 2016-07-01 08:13 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-08-25 09:48 - 2016-07-01 07:56 - 00464896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-08-25 09:48 - 2016-07-01 07:56 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-08-25 09:48 - 2016-07-01 07:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-08-19 10:06 - 2016-09-02 12:01 - 00000000 ____D C:\Program Files\Macrorit
2016-08-18 11:59 - 2016-08-18 11:59 - 00230965 _____ C:\Users\Ray\Downloads\f433b.pdf
2016-08-18 11:57 - 2016-08-18 11:57 - 00647739 _____ C:\Users\Ray\Downloads\f656b.pdf
2016-08-18 10:00 - 2016-08-18 10:00 - 00000000 ____D C:\Program Files\Western Digital
2016-08-10 13:54 - 2016-08-02 07:54 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-10 13:54 - 2016-08-02 07:08 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-10 13:54 - 2016-08-01 23:54 - 25808384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-10 13:54 - 2016-08-01 23:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-08-10 13:54 - 2016-08-01 23:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-08-10 13:54 - 2016-08-01 23:32 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-10 13:54 - 2016-08-01 23:32 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-08-10 13:54 - 2016-08-01 23:31 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-08-10 13:54 - 2016-08-01 23:31 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-08-10 13:54 - 2016-08-01 23:31 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-08-10 13:54 - 2016-08-01 23:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-08-10 13:54 - 2016-08-01 23:24 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-08-10 13:54 - 2016-08-01 23:23 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-08-10 13:54 - 2016-08-01 23:20 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-08-10 13:54 - 2016-08-01 23:19 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-08-10 13:54 - 2016-08-01 23:19 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-08-10 13:54 - 2016-08-01 23:18 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-10 13:54 - 2016-08-01 23:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-08-10 13:54 - 2016-08-01 23:18 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-08-10 13:54 - 2016-08-01 23:11 - 00969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-08-10 13:54 - 2016-08-01 23:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-08-10 13:54 - 2016-08-01 23:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-08-10 13:54 - 2016-08-01 23:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-08-10 13:54 - 2016-08-01 22:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-08-10 13:54 - 2016-08-01 22:56 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-08-10 13:54 - 2016-08-01 22:55 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-08-10 13:54 - 2016-08-01 22:54 - 20343808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-10 13:54 - 2016-08-01 22:53 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-08-10 13:54 - 2016-08-01 22:51 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-08-10 13:54 - 2016-08-01 22:51 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-08-10 13:54 - 2016-08-01 22:51 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-08-10 13:54 - 2016-08-01 22:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-08-10 13:54 - 2016-08-01 22:51 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-08-10 13:54 - 2016-08-01 22:50 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-08-10 13:54 - 2016-08-01 22:47 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-10 13:54 - 2016-08-01 22:45 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-08-10 13:54 - 2016-08-01 22:44 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-08-10 13:54 - 2016-08-01 22:42 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-08-10 13:54 - 2016-08-01 22:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-08-10 13:54 - 2016-08-01 22:41 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-08-10 13:54 - 2016-08-01 22:41 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-08-10 13:54 - 2016-08-01 22:40 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-08-10 13:54 - 2016-08-01 22:38 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-10 13:54 - 2016-08-01 22:38 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-10 13:54 - 2016-08-01 22:37 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-08-10 13:54 - 2016-08-01 22:36 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-10 13:54 - 2016-08-01 22:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-08-10 13:54 - 2016-08-01 22:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-08-10 13:54 - 2016-08-01 22:28 - 15412224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-10 13:54 - 2016-08-01 22:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-08-10 13:54 - 2016-08-01 22:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-08-10 13:54 - 2016-08-01 22:25 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-08-10 13:54 - 2016-08-01 22:24 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-08-10 13:54 - 2016-08-01 22:23 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-10 13:54 - 2016-08-01 22:22 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-08-10 13:54 - 2016-08-01 22:21 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-10 13:54 - 2016-08-01 22:16 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-08-10 13:54 - 2016-08-01 22:15 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-10 13:54 - 2016-08-01 22:14 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-10 13:54 - 2016-08-01 22:14 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-08-10 13:54 - 2016-08-01 22:11 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-10 13:54 - 2016-08-01 22:10 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-10 13:54 - 2016-08-01 21:59 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-10 13:54 - 2016-08-01 21:56 - 02393088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-10 13:54 - 2016-08-01 21:53 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-10 13:54 - 2016-08-01 21:51 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-10 13:50 - 2016-07-08 08:37 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-10 13:50 - 2016-07-08 08:37 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-08-10 13:50 - 2016-07-08 08:32 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-08-10 13:50 - 2016-07-08 08:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-08-10 13:50 - 2016-07-08 08:17 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-08-10 13:50 - 2016-07-08 08:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-08-10 13:50 - 2016-07-08 08:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-08-10 13:50 - 2016-07-08 08:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-08-10 13:50 - 2016-07-08 07:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-08-10 13:50 - 2016-07-08 07:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-08-10 13:50 - 2016-07-08 07:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-08-10 13:50 - 2016-07-08 07:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-08-10 13:50 - 2016-07-08 07:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-08-10 13:50 - 2016-07-08 07:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-08-10 13:32 - 2016-07-08 08:01 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-08-10 12:44 - 2016-08-10 12:44 - 00001045 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2016-08-10 12:44 - 2016-08-10 12:44 - 00001033 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk
2016-08-10 12:43 - 2016-08-10 12:45 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-08-10 12:41 - 2016-08-10 12:41 - 09814472 _____ (TeamViewer GmbH) C:\Users\Ray\Downloads\TeamViewer_Setup_en.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-09 11:40 - 2012-10-18 16:36 - 00000000 ____D C:\Users\Ray
2016-09-09 11:38 - 2009-07-13 21:45 - 00032704 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-09 11:38 - 2009-07-13 21:45 - 00032704 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-09 11:37 - 2016-04-27 09:26 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-09-09 11:35 - 2014-02-06 15:30 - 00001599 _____ C:\Users\Ray\Desktop\DOWNLOAD.lnk
2016-09-09 11:25 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2016-09-09 11:20 - 2015-03-22 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2016-09-09 11:20 - 2015-03-22 12:02 - 00000000 ____D C:\Program Files (x86)\Western Digital
2016-09-09 11:20 - 2015-03-15 11:44 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-09 10:50 - 2015-03-22 12:14 - 00000000 ____D C:\ProgramData\Apple
2016-09-09 10:47 - 2015-03-22 12:14 - 00000174 _____ C:\Users\Ray\Desktop\WD My Cloud Dashboard.url
2016-09-09 10:40 - 2009-07-13 22:13 - 00797918 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-09 10:40 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
2016-09-08 19:21 - 2012-10-18 16:39 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1533AE83-EFFA-431F-8568-7B996A36E533}
2016-09-07 14:47 - 2015-08-20 07:46 - 00008192 _____ C:\Windows\SysWOW64\WDPABKP.dat
2016-09-07 14:46 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-06 15:00 - 2012-10-26 16:03 - 00003174 _____ C:\Windows\System32\Tasks\HPCeeScheduleForRay
2016-09-06 15:00 - 2012-10-26 16:03 - 00000324 _____ C:\Windows\Tasks\HPCeeScheduleForRay.job
2016-09-06 12:42 - 2014-12-11 10:40 - 00000064 _____ C:\Windows\TaxACT14.ini
2016-09-06 11:48 - 2012-11-14 10:48 - 00000000 ____D C:\ProgramData\Adobe
2016-09-06 11:46 - 2011-10-27 19:37 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-09-02 15:49 - 2015-10-29 09:46 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-09-02 15:43 - 2014-07-11 18:40 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-09-02 12:25 - 2014-01-20 16:36 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-09-01 10:06 - 2015-10-15 09:43 - 00000000 ____D C:\Program Files\WhoCrashed
2016-09-01 10:01 - 2012-11-18 16:23 - 00000000 ____D C:\Windows\Minidump
2016-09-01 10:00 - 2012-10-18 16:28 - 00286272 ____N C:\Windows\Minidump\090116-57657-01.dmp
2016-09-01 09:32 - 2012-10-20 09:57 - 00000000 ____D C:\Users\Ray\Desktop\Mikes Tax
2016-08-25 10:59 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2016-08-19 10:09 - 2012-10-18 16:28 - 00287744 ____N C:\Windows\Minidump\081916-65146-01.dmp
2016-08-19 09:46 - 2013-02-09 11:48 - 00000000 ____D C:\Users\Ray\Desktop\Scanned
2016-08-19 09:37 - 2012-10-22 12:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2016-08-18 10:00 - 2015-03-22 13:18 - 00000000 ____D C:\Program Files\Common Files\Western Digital
2016-08-18 10:00 - 2015-03-22 12:02 - 00000000 ____D C:\ProgramData\Western Digital
2016-08-10 15:19 - 2012-10-20 10:18 - 00000000 ____D C:\Users\Ray\Documents\Lillians Recipes
2016-08-10 15:17 - 2012-10-20 10:17 - 00000000 ____D C:\Users\Ray\Documents\AArecipes by type
2016-08-10 14:42 - 2016-07-29 18:29 - 00492336 _____ C:\Windows\system32\FNTCACHE.DAT
2016-08-10 14:14 - 2013-04-12 18:14 - 00000000 ____D C:\Users\Ray\Desktop\PDF
2016-08-10 14:08 - 2013-08-14 03:02 - 00000000 ____D C:\Windows\system32\MRT
2016-08-10 14:07 - 2012-10-22 11:03 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-10 12:49 - 2016-05-03 11:10 - 00000000 ___RD C:\Users\Administrator.Ray-HP7Pro\Dropbox
2016-08-10 12:44 - 2012-12-09 16:35 - 00000000 ____D C:\Users\Ray\AppData\Roaming\TeamViewer

==================== Files in the root of some directories =======

2012-05-08 14:15 - 2012-05-08 14:15 - 0000005 _____ () C:\Program Files (x86)\basis-link
2012-08-13 10:57 - 2012-08-13 10:57 - 0012927 _____ () C:\Program Files (x86)\readme.html
2015-11-26 11:53 - 2015-12-03 12:14 - 0000624 _____ () C:\Users\Ray\AppData\Roaming\All CPU MeterV3_Settings.ini
2015-10-19 16:14 - 2015-10-19 16:14 - 0000053 _____ () C:\Users\Ray\AppData\Roaming\LogFile.txt
2012-11-01 16:38 - 2014-07-06 12:28 - 0001715 _____ () C:\Users\Ray\AppData\Roaming\SAS7_000.DAT
2013-06-03 10:01 - 2012-11-23 05:54 - 0196608 _____ () C:\Users\Ray\AppData\Local\common_functions.dll
2015-01-21 10:48 - 2015-01-21 10:48 - 0003584 _____ () C:\Users\Ray\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-04-03 15:27 - 2014-05-13 17:44 - 0000058 _____ () C:\Users\Ray\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2012-11-23 05:54 - 2012-11-23 05:54 - 0114688 _____ () C:\Users\Ray\AppData\Local\ie_runner_app.exe
2013-06-03 10:01 - 2012-06-26 03:59 - 0940544 _____ (Apache Software Foundation) C:\Users\Ray\AppData\Local\log4cxx.dll
2012-11-20 15:53 - 2012-11-21 14:39 - 0003292 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash
2012-11-20 15:53 - 2012-11-20 15:56 - 0000708 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121120145337.log
2012-11-21 10:54 - 2012-11-21 10:54 - 0000708 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121095434.log
2012-11-21 14:31 - 2012-11-21 14:36 - 0000976 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133134.log
2012-11-21 14:36 - 2012-11-21 14:39 - 0000488 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133602.log
2012-11-21 14:39 - 2012-11-21 14:39 - 0003292 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133908.gnucash
2012-11-21 14:39 - 2012-11-21 14:39 - 0000660 _____ () C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133908.log
2013-06-17 15:06 - 2014-12-18 17:05 - 0000173 _____ () C:\Users\Ray\AppData\Local\msmathematics.qat.Ray
2012-11-20 15:56 - 2012-11-20 15:56 - 0000218 _____ () C:\Users\Ray\AppData\Local\recently-used.xbel
2013-02-07 14:40 - 2016-09-02 12:09 - 0007614 _____ () C:\Users\Ray\AppData\Local\Resmon.ResmonCfg

Files to move or delete:
====================
C:\Users\Ray\WDMyCloud_win.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-09-05 00:54

==================== End of FRST.txt ============================

Attached Files


Edited by hamluis, 09 September 2016 - 04:00 PM.
Moved from Win 7 to Malware Removal Logs - Hamluis.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 10 September 2016 - 09:33 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
Remove this helper via the Control Panel > Programs > Programs and features.
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION

===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.
 
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} =>  No File
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} =>  No File
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} =>  No File
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} =>  No File
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} =>  No File
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
GroupPolicyScripts: Restriction <======= ATTENTION
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1698355976-1673233905-4234267092-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
URLSearchHook: HKU\S-1-5-21-1698355976-1673233905-4234267092-1001 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
Toolbar: HKU\S-1-5-21-1698355976-1673233905-4234267092-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-1698355976-1673233905-4234267092-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} -  No File
U3 DfSdkS; no ImagePath
S4 mfehidk01; \Device\mfehidk01.sys [X]
Task: {0021C438-B617-4EDB-89A4-8BD65C8E255A} - \DropboxUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {1A5D5FE1-16E7-44D1-B182-D1A82FEDB98C} - \SMWUpd -> No File <==== ATTENTION
Task: {1BC06437-AA93-4679-93B6-9B6F56B809E6} - \SMupdate1 -> No File <==== ATTENTION
Task: {24DC94D0-94F9-4629-86E1-E8A98D33BF2E} - \CloudNATIONAL -> No File <==== ATTENTION
Task: {24E82EDA-AD90-40D7-9036-C9CA0F7266FB} - \Microsoft\Windows\Multimedia\SMupdate3 -> No File <==== ATTENTION
Task: {2C9024CF-7F54-4CB3-A922-74DD384C91CB} - \Security Center Update - 1576487034 -> No File <==== ATTENTION
Task: {31F20AA2-B228-4C90-A6E8-FD9F7DC1465B} - \Smp -> No File <==== ATTENTION
Task: {45981F65-57B6-435F-A1C4-3581FFA19165} - \SPBIW_UpdateTask_Time_313132323535393831382d3437415a556c2a3223346c41 -> No File <==== ATTENTION
Task: {4816A4E7-1D59-4336-956C-57714E02F85D} - no filepath
Task: {505CBF2D-1486-4408-A911-3B99DB82FD12} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {670FA3E4-5FD7-4912-B58B-7434D23A4F4D} - \SPDriver -> No File <==== ATTENTION
Task: {715D61D4-71E1-41DA-A8B0-429F1253132E} - \SMW_UpdateTask_Time_313132323535393831382d3437415a556c2a3223346c41 -> No File <==== ATTENTION
Task: {72DC039F-D8D0-42CC-9321-66F457CB582E} - \Microsoft\Windows\Maintenance\SMupdate2 -> No File <==== ATTENTION
Task: {782CCD30-BADA-4F8F-8EFA-E77A70E4E65F} - \SmartWeb Upgrade Trigger Task -> No File <==== ATTENTION
Task: {7C6F9A93-3032-43E8-A8B2-4FF45A6DFA56} - no filepath
Task: {C034F4A7-0ABA-41B6-8848-0830940548FC} - \Security Center Update - 3936112122 -> No File <==== ATTENTION
Task: {C23820B4-029B-47B0-B4A4-83E9BEDEC4D7} - \YTDownloaderUpd -> No File <==== ATTENTION
Task: {C92630D3-DE70-4D22-A031-4FF35F935DEF} - \YTDownloader -> No File <==== ATTENTION
Task: {F259BE4D-F0B2-4503-AED9-6A793898A729} - \ShopperPro -> No File <==== ATTENTION
Task: {F3F135DC-0B72-41C5-947A-A6C2B6CC581F} - \DropboxUpdateTaskMachineCore -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:0FF263E8 [472]
AlternateDataStreams: C:\ProgramData\Temp:373E1720 [118]
AlternateDataStreams: C:\ProgramData\Temp:A303874F [174]
AlternateDataStreams: C:\Users\Ray\Desktop\TaxACT14 - Shortcut.lnk:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\2014 Individual Tax Return File.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\2014 Individual Tax Return File.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\2014 Individual Tax Return File.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\2014 Individual Tax Return File.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\2014 Individual Tax Return File.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\2014 Individual Tax Return File.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ALVININA M GEDKO'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ALVININA M GEDKO'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ALVININA M GEDKO'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ALVININA M GEDKO'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ALVININA M GEDKO'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ALVININA M GEDKO'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\AMANDA LUJAN'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\AMANDA LUJAN'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\AMANDA LUJAN'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\AMANDA LUJAN'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\AMANDA LUJAN'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\AMANDA LUJAN'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ANDREA L FRANKLIN'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ANDREA L FRANKLIN'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ANDREA L FRANKLIN'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ANDREA L FRANKLIN'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ANDREA L FRANKLIN'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ANDREA L FRANKLIN'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Anthony M Dupire's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Anthony M Dupire's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Anthony M Dupire's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Anthony M Dupire's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Anthony M Dupire's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Anthony M Dupire's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA A WARREN'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA A WARREN'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA A WARREN'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA A WARREN'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA A WARREN'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA A WARREN'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA G ANDREWS'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA G ANDREWS'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA G ANDREWS'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA G ANDREWS'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA G ANDREWS'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\BARBARA G ANDREWS'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Brenda G Fluty's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Brenda G Fluty's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Brenda G Fluty's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Brenda G Fluty's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Brenda G Fluty's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Brenda G Fluty's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Bruce L and Shelli A Curl's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Bruce L and Shelli A Curl's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Bruce L and Shelli A Curl's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Bruce L and Shelli A Curl's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Bruce L and Shelli A Curl's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Bruce L and Shelli A Curl's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\CASSANDRA  J REED'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\CASSANDRA  J REED'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\CASSANDRA  J REED'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\CASSANDRA  J REED'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\CASSANDRA  J REED'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\CASSANDRA  J REED'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Charles E and Katherine G Bailey's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Charles E and Katherine G Bailey's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Charles E and Katherine G Bailey's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Charles E and Katherine G Bailey's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Charles E and Katherine G Bailey's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Charles E and Katherine G Bailey's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Danny  R Smith and Michele Curran-Smith's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Danny  R Smith and Michele Curran-Smith's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Danny  R Smith and Michele Curran-Smith's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Danny  R Smith and Michele Curran-Smith's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Danny  R Smith and Michele Curran-Smith's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Danny  R Smith and Michele Curran-Smith's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DANNY R SMITH AND MICHELE CURRAN-SMITH'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DANNY R SMITH AND MICHELE CURRAN-SMITH'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DANNY R SMITH AND MICHELE CURRAN-SMITH'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DANNY R SMITH AND MICHELE CURRAN-SMITH'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DANNY R SMITH AND MICHELE CURRAN-SMITH'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DANNY R SMITH AND MICHELE CURRAN-SMITH'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DAVID L PERRY AND IRENE'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DAVID L PERRY AND IRENE'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DAVID L PERRY AND IRENE'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DAVID L PERRY AND IRENE'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DAVID L PERRY AND IRENE'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DAVID L PERRY AND IRENE'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DONALD L AND GRACE H LEZER'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DONALD L AND GRACE H LEZER'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DONALD L AND GRACE H LEZER'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DONALD L AND GRACE H LEZER'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DONALD L AND GRACE H LEZER'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\DONALD L AND GRACE H LEZER'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Elisabeth L Hawthorne's 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Elisabeth L Hawthorne's 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Elisabeth L Hawthorne's 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Elisabeth L Hawthorne's 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Elisabeth L Hawthorne's 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Elisabeth L Hawthorne's 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ELIZABETH R MCCOY'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ELIZABETH R MCCOY'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ELIZABETH R MCCOY'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ELIZABETH R MCCOY'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ELIZABETH R MCCOY'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ELIZABETH R MCCOY'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ERNEST SERRIA'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ERNEST SERRIA'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ERNEST SERRIA'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ERNEST SERRIA'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ERNEST SERRIA'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ERNEST SERRIA'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\FREDRICK M AND LYNNE NASH'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\FREDRICK M AND LYNNE NASH'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\FREDRICK M AND LYNNE NASH'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\FREDRICK M AND LYNNE NASH'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\FREDRICK M AND LYNNE NASH'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\FREDRICK M AND LYNNE NASH'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\GEORGIA L HANSON'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\GEORGIA L HANSON'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\GEORGIA L HANSON'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\GEORGIA L HANSON'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\GEORGIA L HANSON'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\GEORGIA L HANSON'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\HENRY AND PAULINE REIS'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\HENRY AND PAULINE REIS'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\HENRY AND PAULINE REIS'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\HENRY AND PAULINE REIS'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\HENRY AND PAULINE REIS'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\HENRY AND PAULINE REIS'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JACK R AND DOLORES NICHOL'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JACK R AND DOLORES NICHOL'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JACK R AND DOLORES NICHOL'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JACK R AND DOLORES NICHOL'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JACK R AND DOLORES NICHOL'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JACK R AND DOLORES NICHOL'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Jacqueline Y ortiz's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Jacqueline Y ortiz's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Jacqueline Y ortiz's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Jacqueline Y ortiz's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Jacqueline Y ortiz's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Jacqueline Y ortiz's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\James E Lierle's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\James E Lierle's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\James E Lierle's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\James E Lierle's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\James E Lierle's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\James E Lierle's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN L TUCKER'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN L TUCKER'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN L TUCKER'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN L TUCKER'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN L TUCKER'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN L TUCKER'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN VANCE'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN VANCE'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN VANCE'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN VANCE'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN VANCE'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOAN VANCE'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joanne E Bilbo's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joanne E Bilbo's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joanne E Bilbo's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joanne E Bilbo's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joanne E Bilbo's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joanne E Bilbo's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\John bO's 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\John bO's 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\John bO's 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\John bO's 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\John bO's 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\John bO's 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph A Chappelle's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph A Chappelle's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph A Chappelle's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph A Chappelle's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph A Chappelle's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph A Chappelle's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph B and Deanna Hickman's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph B and Deanna Hickman's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph B and Deanna Hickman's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph B and Deanna Hickman's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph B and Deanna Hickman's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Joseph B and Deanna Hickman's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOSEPH J AND VIRGINIA SPARACIO'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOSEPH J AND VIRGINIA SPARACIO'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOSEPH J AND VIRGINIA SPARACIO'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOSEPH J AND VIRGINIA SPARACIO'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOSEPH J AND VIRGINIA SPARACIO'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JOSEPH J AND VIRGINIA SPARACIO'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JULIUS F GILL'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JULIUS F GILL'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JULIUS F GILL'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JULIUS F GILL'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JULIUS F GILL'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\JULIUS F GILL'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Karen W Chung's 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Karen W Chung's 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Karen W Chung's 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Karen W Chung's 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Karen W Chung's 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Karen W Chung's 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KATHLEEN J PARIS'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KATHLEEN J PARIS'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KATHLEEN J PARIS'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KATHLEEN J PARIS'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KATHLEEN J PARIS'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KATHLEEN J PARIS'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KIMBERLE A ENGLAND'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KIMBERLE A ENGLAND'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KIMBERLE A ENGLAND'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KIMBERLE A ENGLAND'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KIMBERLE A ENGLAND'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\KIMBERLE A ENGLAND'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Larry D Lucas's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Larry D Lucas's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Larry D Lucas's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Larry D Lucas's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Larry D Lucas's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Larry D Lucas's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Loi V Chung and Liyan Tan's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Loi V Chung and Liyan Tan's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Loi V Chung and Liyan Tan's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Loi V Chung and Liyan Tan's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Loi V Chung and Liyan Tan's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Loi V Chung and Liyan Tan's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\LOUIS AND IRENE RAMOS'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\LOUIS AND IRENE RAMOS'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\LOUIS AND IRENE RAMOS'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\LOUIS AND IRENE RAMOS'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\LOUIS AND IRENE RAMOS'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\LOUIS AND IRENE RAMOS'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Louise G Marron's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Louise G Marron's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Louise G Marron's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Louise G Marron's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Louise G Marron's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Louise G Marron's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marcos V Valdez's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marcos V Valdez's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marcos V Valdez's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marcos V Valdez's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marcos V Valdez's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marcos V Valdez's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marion Villasenoir Jr and Patricia Villasenior's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marion Villasenoir Jr and Patricia Villasenior's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marion Villasenoir Jr and Patricia Villasenior's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marion Villasenoir Jr and Patricia Villasenior's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marion Villasenoir Jr and Patricia Villasenior's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Marion Villasenoir Jr and Patricia Villasenior's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Melanie R Bruno's 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Melanie R Bruno's 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Melanie R Bruno's 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Melanie R Bruno's 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Melanie R Bruno's 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Melanie R Bruno's 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's -s 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's -s 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's -s 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's -s 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's -s 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's -s 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael J Daugelli's 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael Lane's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael Lane's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael Lane's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael Lane's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael Lane's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael Lane's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael P Shanahan's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael P Shanahan's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael P Shanahan's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael P Shanahan's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael P Shanahan's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michael P Shanahan's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michele Curran-Smith's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michele Curran-Smith's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michele Curran-Smith's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michele Curran-Smith's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michele Curran-Smith's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Michele Curran-Smith's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\MIGUEL V BARAJAS'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\MIGUEL V BARAJAS'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\MIGUEL V BARAJAS'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\MIGUEL V BARAJAS'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\MIGUEL V BARAJAS'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\MIGUEL V BARAJAS'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\PAUL D AND CATHERINE M NELSON'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\PAUL D AND CATHERINE M NELSON'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\PAUL D AND CATHERINE M NELSON'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\PAUL D AND CATHERINE M NELSON'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\PAUL D AND CATHERINE M NELSON'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\PAUL D AND CATHERINE M NELSON'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Randy D Sweaney's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Randy D Sweaney's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Randy D Sweaney's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Randy D Sweaney's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Randy D Sweaney's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Randy D Sweaney's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\RAYMOND J AND LILLIAN R DUPIRE'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\RAYMOND J AND LILLIAN R DUPIRE'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\RAYMOND J AND LILLIAN R DUPIRE'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\RAYMOND J AND LILLIAN R DUPIRE'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\RAYMOND J AND LILLIAN R DUPIRE'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\RAYMOND J AND LILLIAN R DUPIRE'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard E Josh's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard E Josh's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard E Josh's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard E Josh's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J and Catherine M Howell's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J and Catherine M Howell's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J and Catherine M Howell's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J and Catherine M Howell's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J and Catherine M Howell's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J and Catherine M Howell's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J Morris and Leslie A Morrison's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J Morris and Leslie A Morrison's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J Morris and Leslie A Morrison's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J Morris and Leslie A Morrison's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J Morris and Leslie A Morrison's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Richard J Morris and Leslie A Morrison's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT E HAWKINS AND ISBEL HAWKNS'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT E HAWKINS AND ISBEL HAWKNS'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT E HAWKINS AND ISBEL HAWKNS'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT E HAWKINS AND ISBEL HAWKNS'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT E HAWKINS AND ISBEL HAWKNS'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT E HAWKINS AND ISBEL HAWKNS'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT K AND JOY BERG'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT K AND JOY BERG'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT K AND JOY BERG'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT K AND JOY BERG'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT K AND JOY BERG'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [166]
AlternateDataStreams: C:\Users\Ray\Documents\ROBERT K AND JOY BERG'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [166]
AlternateDataStreams: C:\Users\Ray\Documents\SAL R AND SHERRY DIMERCURIO'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SAL R AND SHERRY DIMERCURIO'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SAL R AND SHERRY DIMERCURIO'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SAL R AND SHERRY DIMERCURIO'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SAL R AND SHERRY DIMERCURIO'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SAL R AND SHERRY DIMERCURIO'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVADOR LUJAN  III AND EMMA LUJAN'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVADOR LUJAN  III AND EMMA LUJAN'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVADOR LUJAN  III AND EMMA LUJAN'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVADOR LUJAN  III AND EMMA LUJAN'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVADOR LUJAN  III AND EMMA LUJAN'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVADOR LUJAN  III AND EMMA LUJAN'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVATORE J BRUNO AND PHYLLIS AIELLO-BRUNO'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVATORE J BRUNO AND PHYLLIS AIELLO-BRUNO'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVATORE J BRUNO AND PHYLLIS AIELLO-BRUNO'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVATORE J BRUNO AND PHYLLIS AIELLO-BRUNO'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVATORE J BRUNO AND PHYLLIS AIELLO-BRUNO'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SALVATORE J BRUNO AND PHYLLIS AIELLO-BRUNO'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\sam allen's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\sam allen's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\sam allen's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\sam allen's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\sam allen's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\sam allen's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra  B Bruno and Salvatore J Bruno III's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra  B Bruno and Salvatore J Bruno III's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra  B Bruno and Salvatore J Bruno III's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra  B Bruno and Salvatore J Bruno III's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra  B Bruno and Salvatore J Bruno III's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra  B Bruno and Salvatore J Bruno III's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra L Corbett-Ballesteros's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra L Corbett-Ballesteros's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra L Corbett-Ballesteros's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Sandra L Corbett-Ballesteros's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SHIRLEY DAVIES'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SHIRLEY DAVIES'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SHIRLEY DAVIES'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SHIRLEY DAVIES'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SHIRLEY DAVIES'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SHIRLEY DAVIES'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SUNNI ROLAND'S 2014 TAX RETURN.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SUNNI ROLAND'S 2014 TAX RETURN.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SUNNI ROLAND'S 2014 TAX RETURN.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SUNNI ROLAND'S 2014 TAX RETURN.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SUNNI ROLAND'S 2014 TAX RETURN.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\SUNNI ROLAND'S 2014 TAX RETURN.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Warren H and Maria F Verlander's 2014 Individual Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Warren H and Maria F Verlander's 2014 Individual Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Warren H and Maria F Verlander's 2014 Individual Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Warren H and Maria F Verlander's 2014 Individual Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Warren H and Maria F Verlander's 2014 Individual Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\Warren H and Maria F Verlander's 2014 Individual Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\William T and Pqsti J Barron's 2014 Tax Return.ta4 - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\William T and Pqsti J Barron's 2014 Tax Return.ta4.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\William T and Pqsti J Barron's 2014 Tax Return.ta4_Daily - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\William T and Pqsti J Barron's 2014 Tax Return.ta4_Daily.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\William T and Pqsti J Barron's 2014 Tax Return.ta4_Weekly - Copy.ba4:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ray\Documents\William T and Pqsti J Barron's 2014 Tax Return.ta4_Weekly.ba4:com.dropbox.attributes [168]


cmd: netsh winsock reset catalog

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.

Please post the log and let me know what problem persists with this computer.

#3 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 15 September 2016 - 09:58 PM

Since I need to switch email address can we transfer this very very welcomed help session to bigrayxxx1968@att.net or ray.dupirexxx@gmail.com.  Please

Edited by nasdaq, 16 September 2016 - 08:29 AM.


#4 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 15 September 2016 - 10:00 PM

I have copied the fixitlist.txt to the folder containing fsrt but "fix" no can find



#5 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 16 September 2016 - 08:33 AM

Since I need to switch email address can we transfer this very very welcomed help session to bigrayxxx1968@att.net or ray.dupirexxx@gmail.com. Please

You should never post any email address in a forum.
Bots are looking for these and use them to spam you.

I have obfuscated you addresses in post no. 3.

p.s.
I do not understand where to transfer this as you have requested.

===

Try this instead of the Farbar fix.

Temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zeok tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b
Now...
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.

Please attach the zoek-results.log in your reply.

Also, please provide an update on how the computer is behaving after running the above script.

#6 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 16 September 2016 - 04:41 PM

Attached please find the zoek-results.log.

Computer still slow no change it seems

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Ray on Fri 09/16/2016 at 10:19:35.13.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Ray\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

9/16/2016 10:28:47 AM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\Barnes & Noble deleted successfully
C:\PROGRA~2\Citrix deleted successfully
C:\PROGRA~2\Free PDF Soulutions deleted successfully
C:\PROGRA~2\IDriveWindows deleted successfully
C:\PROGRA~2\LinkFunc deleted successfully
C:\PROGRA~2\LSoft Technologies Inc deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\NTI deleted successfully
C:\PROGRA~2\Security Task Manager deleted successfully
C:\PROGRA~2\UltimateOutsider deleted successfully
C:\PROGRA~2\COMMON~1\Apple deleted successfully
C:\Program Files\CloneSpy deleted successfully
C:\Program Files\Free WMA to MP3 Converter deleted successfully
C:\Program Files\Identity Finder 4(2) deleted successfully
C:\Program Files\Macrorit deleted successfully
C:\Program Files\Malwarebytes' Anti-Malware deleted successfully
C:\Program Files\Messenger deleted successfully
C:\Program Files\MSXML 4.0 deleted successfully
C:\Program Files\NetMeeting deleted successfully
C:\Program Files\Outlook Express deleted successfully
C:\Program Files\VideoLAN deleted successfully
C:\Program Files\Windows Live SkyDrive deleted successfully
C:\Program Files\Windows Media Connect 2 deleted successfully
C:\Program Files\Common Files\Designer deleted successfully
C:\Program Files\Common Files\Sonic Shared deleted successfully
C:\Program Files\Common Files\Windows Live deleted successfully
C:\Program Files\Common Files\Wise Installation Wizard deleted successfully
C:\PROGRA~3\install_clap deleted successfully
C:\PROGRA~3\Karen's Power Tools deleted successfully
C:\PROGRA~3\Local Settings deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~3\PDF Architect deleted successfully
C:\PROGRA~3\PDF Architect 2 deleted successfully
C:\PROGRA~3\RoboForm deleted successfully
C:\PROGRA~3\UAB deleted successfully
C:\Users\Ray\AppData\Roaming\anyburn deleted successfully
C:\Users\Ray\AppData\Roaming\Balabolka deleted successfully
C:\Users\Ray\AppData\Roaming\Carbonite deleted successfully
C:\Users\Ray\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant deleted successfully
C:\Users\Ray\AppData\Roaming\com.wd.WDMyCloud deleted successfully
C:\Users\Ray\AppData\Roaming\Dexpot deleted successfully
C:\Users\Ray\AppData\Roaming\DiskDefrag deleted successfully
C:\Users\Ray\AppData\Roaming\dlg deleted successfully
C:\Users\Ray\AppData\Roaming\Dyoquduw deleted successfully
C:\Users\Ray\AppData\Roaming\HP Support Assistant deleted successfully
C:\Users\Ray\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Ray\AppData\Roaming\nvda deleted successfully
C:\Users\Ray\AppData\Roaming\PDF Architect deleted successfully
C:\Users\Ray\AppData\Roaming\PDF Architect 2 deleted successfully
C:\Users\Ray\AppData\Roaming\ProcessLasso deleted successfully
C:\Users\Ray\AppData\Roaming\qBittorrent deleted successfully
C:\Users\Ray\AppData\Roaming\RoboForm deleted successfully
C:\Users\Ray\AppData\Roaming\Uthiecf deleted successfully
C:\Users\Ray\AppData\Roaming\WinRAR deleted successfully
C:\Users\Ray\AppData\Roaming\ZinioReader4 deleted successfully
C:\Users\Ray\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Ray\AppData\Local\EmieSiteList deleted successfully
C:\Users\Ray\AppData\Local\EmieUserList deleted successfully
C:\Users\Ray\AppData\Local\PDFC deleted successfully
C:\Users\Ray\AppData\Local\Pogoplug deleted successfully
C:\Users\Ray\AppData\Local\qBittorrent deleted successfully
C:\Users\Ray\AppData\Local\TeamViewer deleted successfully
C:\Users\Ray\AppData\Local\Windows Live deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-1698355976-1673233905-4234267092-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-1698355976-1673233905-4234267092-1001\Software\Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Deleting Services ======================

==== FireFox Fix ======================

ProfilePath: C:\Users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\mpsrd2k8.default

user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- FireFox user.js and prefs.js backups ----

prefs_20160916_1233_.backup

==== Batch Command(s) Run By Tool======================

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Barnes & Noble not found
C:\PROGRA~2\Citrix not found
C:\PROGRA~2\Free PDF Soulutions not found
C:\PROGRA~2\IDriveWindows not found
C:\PROGRA~2\LinkFunc not found
C:\PROGRA~2\LSoft Technologies Inc not found
C:\PROGRA~2\NTI not found
C:\PROGRA~2\Security Task Manager not found
C:\PROGRA~2\UltimateOutsider not found
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~2\The Print Shop 23.1 deleted
C:\PROGRA~2\DealusiFindeerProi deleted
C:\PROGRA~2\Fatkun Batch Download Image deleted
C:\windows\SysNative\Tasks\Open URL by RoboForm deleted
C:\Users\Ray\AppData\LocalLow\PC-Helpsoft deleted
C:\PROGRA~2\Uninstall Information\ib_uninst_514 deleted
C:\PROGRA~2\Uninstall Information\ib_uninst_555 deleted
C:\PROGRA~2\Yahoo! deleted
C:\PROGRA~2\AVG Secure Search deleted
C:\Users\Ray\AppData\Roaming\All CPU MeterV3_Settings.ini deleted
C:\Users\Ray\AppData\Roaming\LogFile.txt deleted
C:\PROGRA~3\Yahoo! deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121120145337.log deleted
C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121095434.log deleted
C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133134.log deleted
C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133602.log deleted
C:\Users\Ray\AppData\Local\Mikes Landscape & Gardening Service.gnucash.20121121133908.log deleted
C:\Users\Ray\AppData\Local\common_functions.dll deleted
C:\Users\Ray\AppData\Local\log4cxx.dll deleted
C:\Users\Ray\AppData\Local\ie_runner_app.exe deleted
C:\Users\Ray\AppData\Local\PC_Drivers_Headquarters deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\speed browser deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\FileTypeAssistant deleted
C:\Users\Ray\AppData\LocalLow\AVG Secure Search deleted
C:\Users\Ray\AppData\LocalLow\Yahoo! deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Yahoo! deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Yahoo! Companion deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Users\Ray\WDMyCloud_win.exe deleted

==== Orphaned Tasks deleted from Registry ======================

Bomgar Task 271566197 deleted
Bomgar Task 271855828 deleted
Carbonite Installer - Start Carbonite UI deleted
DropboxUpdateTaskMachineCore deleted
DropboxUpdateTaskMachineUA deleted
Open URL by RoboForm deleted
{6B262F4C-B790-41DD-B05A-D4B27B68BF1C} deleted
{6E160D64-0B2D-45E7-A5ED-33201F55E1C4} deleted
{C3667D1C-EEE6-461E-8865-34B9583583D8} deleted
{EF482EEA-A4A3-4DEA-A7DE-67A5E8E5A850} deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\mpsrd2k8.default
user_pref("browser.startup.homepage", "http://www.msn.com/?pc=SL5J&ocid=SL5JDHP&osmkt=en-us");
user_pref("browser.search.defaultenginename", "Bing ");
user_pref("browser.search.selectedEngine", "Bing ");
user_pref("keyword.URL", "http://www.bing.com/search?FORM=SL5JDF&PC=SL5J&q=");

==== Firefox Extensions ======================

ProfilePath: C:\Users\Ray\AppData\Roaming\Mozilla\Firefox\Profiles\mpsrd2k8.default
- Bing Search - %ProfilePath%\extensions\bingsearch.full@microsoft.com.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://att.net/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Start Page Redirect Cache"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Start Page Redirect Cache"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://att.net/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page Redirect Cache"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page Redirect Cache"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{3CB12E97-BDDF-4488-8C61-217335DD319F}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
HKLM\SearchScopes\{3CB12E97-BDDF-4488-8C61-217335DD319F} - http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
HKLM\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} - http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - No_Url_Value
HKLM\Wow6432Node\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
HKCU\SearchScopes\{3CB12E97-BDDF-4488-8C61-217335DD319F} - http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
HKCU\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1698355976-1673233905-4234267092-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_USERS\S-1-5-21-1698355976-1673233905-4234267092-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1698355976-1673233905-4234267092-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Administrator.Ray-HP7Pro\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ray\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ray\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

No Chrome Cache found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=184 folders=88 131093373 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\temp emptied successfully
C:\Users\Administrator.Ray-HP7Pro\AppData\Local\temp emptied successfully
C:\Users\Administrator.SHEDOLD\AppData\Local\temp emptied successfully
C:\Users\Client Data\AppData\Local\temp emptied successfully
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Owner\AppData\Local\temp emptied successfully
C:\Users\Owner.xp\AppData\Local\temp emptied successfully
C:\Users\Owner.YOUR-FSYLY0JTWN\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\Ray\AppData\Local\temp emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Windows\TEMP successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Fri 09/16/2016 at 13:36:03.15 ======================



#7 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 17 September 2016 - 08:30 AM

Up date all the old drivers.

Navigate to this page.
http://secunia.com/vulnerability_scanning/personal/

Download and install the Secunia PSI.

Run the application and updates all the programs/drivers that needs to be updated.

===
p.s.

Secunia will start looking for new updates every time you boot the system.
This is an overkill. When all is well you can remove it using the Add/Remove programs applet.

#8 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 18 September 2016 - 01:45 PM

downloaded installed and ran  only two items updated  no change in operations  thanks



#9 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 19 September 2016 - 08:16 AM

Please Download and run the ComboFix tool.

How to use ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Follow the instructions on the page.

Post the content of the C:\ComboFix.txt file for my review.

p.s.
When all is well you can remove the tool by following the Uninstall instructions on the same page.

#10 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 19 September 2016 - 10:03 PM

While installing Comobofix I got BSOD, so I tried again same result First time when antivirus off and second time as admin.  See dump files below

 

System Information (local)

Computer name: RAY-HP7PRO
Windows version: Windows 7 Service Pack 1, 6.1, build: 7601
Windows dir: C:\Windows
Hardware: p7-1154, Hewlett-Packard, PEGATRON CORPORATION, 2ACD
CPU: AuthenticAMD AMD A6-3600 APU with Radeon™ HD Graphics AMD586, level: 18
4 logical processors, active mask: 15
RAM: 16626831360 bytes total



 

Crash Dump Analysis

Crash dump directory: C:\Windows\Minidump

Crash dumps are enabled on your computer.

On Tue 9/20/2016 2:32:17 AM GMT your computer crashed
crash dump file: C:\Windows\Minidump\091916-53586-01.dmp
This was probably caused by the following module: procexp113.sys (PROCEXP113+0x15E5)
Bugcheck code: 0xC4 (0xF6, 0xE0, 0xFFFFFA800E63B060, 0xFFFFF8800A3125E5)
Error: DRIVER_VERIFIER_DETECTED_VIOLATION
Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
A driver references a user-mode handle as kernel mode. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: procexp113.sys .
Google query: procexp113.sys DRIVER_VERIFIER_DETECTED_VIOLATION



On Tue 9/20/2016 2:25:24 AM GMT your computer crashed
crash dump file: C:\Windows\Minidump\091916-65629-01.dmp
This was probably caused by the following module: procexp113.sys (PROCEXP113+0x15E5)
Bugcheck code: 0xC4 (0xF6, 0xE0, 0xFFFFFA8012EF8960, 0xFFFFF8800A3645E5)
Error: DRIVER_VERIFIER_DETECTED_VIOLATION
Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
A driver references a user-mode handle as kernel mode. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: procexp113.sys .
Google query: procexp113.sys DRIVER_VERIFIER_DETECTED_VIOLATION

Prior to Comobo and Secunia PSI
On Fri 9/9/2016 8:29:13 PM GMT your computer crashed
crash dump file: C:\Windows\Minidump\090916-68172-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x6F400)
Bugcheck code: 0xC4 (0xE1, 0xFFFFF980DEC26F70, 0x0, 0x0)
Error: DRIVER_VERIFIER_DETECTED_VIOLATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
A synchronization object was found to have an address that was either invalid or pageable. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Thu 9/1/2016 4:58:47 PM GMT your computer crashed
crash dump file: C:\Windows\Minidump\090116-57657-01.dmp
This was probably caused by the following module: aswmbr.sys (aswMBR+0x1569)
Bugcheck code: 0xC4 (0xF6, 0x128, 0xFFFFFA800F1B8060, 0xFFFFF8800A765569)
Error: DRIVER_VERIFIER_DETECTED_VIOLATION
Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
A driver references a user-mode handle as kernel mode. This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: aswmbr.sys .
Google query: aswmbr.sys DRIVER_VERIFIER_DETECTED_VIOLATION



On Fri 8/19/2016 5:07:43 PM GMT your computer crashed
crash dump file: C:\Windows\Minidump\081916-65146-01.dmp
This was probably caused by the following module: mda_ntdrv.sys (0xFFFFF8800B9A7101)
Bugcheck code: 0xC2 (0x9D, 0x4FCFB5E, 0x0, 0xFFFFF8800B9A7101)
Error: BAD_POOL_CALLER
file path: C:\Windows\system32\mda_ntdrv.sys
Bug check description: This indicates that the current thread is making a bad pool request.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: mda_ntdrv.sys .
Google query: mda_ntdrv.sys BAD_POOL_CALLER




 

Conclusion

5 crash dumps have been found and analyzed. 3 third party drivers have been identified to be causing system crashes on your computer. It is strongly suggested that you check for updates for these drivers on their company websites. Click on the links below to search with Google for updates for these drivers:

mda_ntdrv.sys
aswmbr.sys
procexp113.sys

 



#11 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 20 September 2016 - 09:46 AM


The files identified in the crash are install by Combofix.
Why you system crashed is unknown to me. Combofix is normally running well on Windows 7.

Try this cleaning scan.

Please scan your computer with ESET Online Scanner.
  • Click on this link to open ESET Online Scanner in a new window.
    • Click on the Scan Now button to download the esetonlinescanner_enu.exe file. Save it to your Desktop.
    • Close all your programs and browsers.
    • Please disable your antivirus program to avoid potential conflicts, improve the performance and speed up the scan.
    • Double click on esetonlinescanner_enu.exe to start ESET Online Scanner. It will open a window with the Terms of Use.
  • Check mark Download latest version of ESET Online Scanner and click the Accept button.
  • Accept any security warnings that may appear.
  • Under Computer scan settings, check mark Enable detection of potentially unwanted applications.
  • Then click Advanced settings and check mark the following options:
    • Enable detection of potentially unsafe applications
    • Clean threats automatically
  • Click the Scan button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats.
  • Click Export, and save the file to your Desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
Note: If nothing is found, it will not produce a log.

Please re-enable your antivirus program.

#12 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 26 September 2016 - 08:26 AM

Are you still with me?

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/

#13 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 27 September 2016 - 01:20 PM

i am still here but computer problems e-mail problems and a broken knee cap slow me down.

 

Ran eset twice. 1st tme ran screen changed color and coundn't read results, but seem to find two threats.  Ran again and after 10hrs 57 mins and 18 secs found zero

threats in 216392 files guess first run removed the two threats. no logs generated

 

No improvement in operations.  Any more ideas?



#14 nasdaq

nasdaq

  • Malware Response Team
  • 39,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:47 AM

Posted 28 September 2016 - 09:12 AM


Check the hardware on your HP computer.
http://support.hp.com/us-en/document/c03467259

Keep me posted.

#15 MrRay1968

MrRay1968
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:47 PM

Posted 28 September 2016 - 02:01 PM

Downloaded support file made usb ran same all seems to be ok        btw  the link is for a laptop but I was able to change 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users