This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CryptoLocker [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

📎Help.png

Help! Help! My Laptop has cryptolocker, What Do I Do??

I searched about it, and found out that there was a way to decrypt my files using https://www. decryptcryptolocker.com/ , but whenever I upload the file it says that the file is not encrypted, but im clearly sure the files are incrypted and I really really need all the files for my homework[external image: cry2.gif]

 

 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-10 12:32:31
—————————–
12:32:31.589    OS Version: Windows 6.1.7601 Service Pack 1
12:32:31.590    Number of processors: 4 586 0x3601
12:32:31.595    ComputerName: YOYOYO-PC  UserName: acer
12:32:36.955    Initialize success
12:32:36.987    VM: initialized successfully
12:32:36.991    VM: Intel CPU virtualization not supported 
12:32:55.538    AVAST engine download error: 0
12:33:00.781    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
12:33:00.786    Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
12:33:00.944    Disk 0 MBR read successfully
12:33:00.949    Disk 0 MBR scan
12:33:00.960    Disk 0 Windows 7 default MBR code
12:33:00.967    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        13312 MB offset 2048
12:33:01.009    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 27265024
12:33:01.021    Disk 0 unknown boot code
12:33:01.074    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       463526 MB offset 27469824
12:33:01.081    Disk 0 statistics 790/0/0 @ 1.91 MB/s
12:33:01.091    Scan finished successfully
12:33:19.086    Disk 0 MBR has been saved successfully to "C:\Users\acer\Desktop\MBR.dat"
12:33:19.099    The log file has been saved successfully to "C:\Users\acer\Desktop\aswMBR.txt"
 
=========================================================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by [removed] (administrator) on YOYOYO-PC on 10-04-2015 11:44:15
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft Windows 7 Home Basic  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe
(Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nalpeiron Ltd.) C:\Windows\System32\NlsSrv32.exe
(Symantec Corporation) C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(TorchMedia Inc.) C:\Users\acer\AppData\Local\Torch\Update\TorchCrashHandler.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Egis Technology Inc.) C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Vimicro) C:\Windows\vmsnap3.exe
() C:\Windows\Domino.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IEMonitor.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\saUpd.exe
(McAfee, Inc.) C:\Program Files\McAfee\virusscan\mcods.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McChHost.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\saUI.exe
(McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Service.exe
(BlueStack Systems) C:\Program Files\BlueStacks\HD-Network.exe
(BlueStack Systems) C:\Program Files\BlueStacks\HD-BlockDevice.exe
(BlueStack Systems) C:\Program Files\BlueStacks\HD-SharedFolder.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(McAfee, Inc.) C:\Program Files\McAfee\msc\mcsvrcnt.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\acer\Desktop\aswMBR.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SuiteTray] => C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-21] (Egis Technology Inc.)
HKLM\…\Run: [GfxServiceInstall] => C:\Windows\system32\GfxCUIServiceInstall.vbs [131 2012-06-27] ()
HKLM\…\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [714120 2012-02-08] (Acer Incorporated)
HKLM\…\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-03-22] (RealNetworks, Inc.)
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM\…\Run: [VMSnap3] => C:\Windows\VMSnap3.exe [49152 2006-07-18] (Vimicro)
HKLM\…\Run: [Domino] => C:\Windows\Domino.exe [49152 2006-07-04] ()
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1934632 2010-10-08] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\…\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [859864 2015-03-10] (BlueStack Systems, Inc.)
HKLM\…\Run: [MRT] => C:\Windows\system32\MRT.exe [119837696 2015-02-26] (Microsoft Corporation)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [51712 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [uTorrent] => C:\Users\acer\AppData\Roaming\uTorrent\uTorrent.exe [1936720 2014-08-09] (BitTorrent Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [YsvdPack] => C:\Windows\System32\regsvr32.exe C:\Users\acer\AppData\Local\Anjkworks\AtNet3D.dll
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [GettingStarted] => "C:\Users\acer\AppData\Roaming\Microsoft\Windows\IEUpdate\GettingStarted.exe"
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [fsutil] => "C:\Users\acer\AppData\Roaming\Microsoft\Windows\IEUpdate\fsutil.exe"
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3882576 2014-11-16] (Tonec Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\CurrentVersion\Windows: [Load] C:\Users\acer\LOCALS~1\Temp\msvauryol.exe <===== ATTENTION
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\MountPoints2: {f352303d-f814-11e2-ac07-083e8e5528a2} - Explorer.exe UserGuild.htm
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Command Processor: "C:\Users\acer\AppData\Roaming\Microsoft\Windows\IEUpdate\pcaui.exe" <===== ATTENTION!
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Users\acer\AppData\Roaming\Microsoft\Windows\IEUpdate\pcaui.exe
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3882576 2014-11-16] (Tonec Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\RunOnce: [Application Restart #0] => C:\Program Files\EgisTec IPS\EgisUpdate.exe [202608 2011-03-29] (Egis Technology Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\RunOnce: [Application Restart #1] => C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE [2162024 2010-03-09] (Microsoft Corporation)
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\RunOnce: [Application Restart #2] => C:\Program Files\Google\Chrome\Application\chrome.exe [809288 2015-03-31] (Google Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\MountPoints2: {d75c6af4-b556-11e2-ada7-089e0126a971} - Explorer.exe UserGuild.htm
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\MountPoints2: {f352303d-f814-11e2-ac07-083e8e5528a2} - Explorer.exe UserGuild.htm
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [450048 2011-09-13] ()
HKU\S-1-5-21-728575759-1552540791-2427072771-1009\…\RunOnce: [Application Restart #0] => C:\Program Files\EgisTec IPS\EgisUpdate.exe [202608 2011-03-29] (Egis Technology Inc.)
HKU\S-1-5-21-728575759-1552540791-2427072771-1009\…\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-728575759-1552540791-2427072771-1009\…\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-728575759-1552540791-2427072771-1009\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [450048 2011-09-13] ()
HKU\S-1-5-21-728575759-1552540791-2427072771-501\…\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-728575759-1552540791-2427072771-501\…\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-728575759-1552540791-2427072771-501\Control Panel\Desktop\\SCRNSAVE.EXE -> c:\Program Files\Acer Games\Insaniquarium Deluxe\wtmui_default\Insaniquarium.scr [106496 2004-08-18] ()
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browsemngr.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browsermngr.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe
IFEO\cltmngsvc.exe: [Debugger] tasklist.exe
IFEO\delta babylon.exe: [Debugger] tasklist.exe
IFEO\delta tb.exe: [Debugger] tasklist.exe
IFEO\delta2.exe: [Debugger] tasklist.exe
IFEO\deltainstaller.exe: [Debugger] tasklist.exe
IFEO\deltasetup.exe: [Debugger] tasklist.exe
IFEO\deltatb.exe: [Debugger] tasklist.exe
IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\iminentsetup.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\rjatydimofu.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\sweetimsetup.exe: [Debugger] tasklist.exe
IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\acer\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [1SecureIconsProvider] -> {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll ()
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll (Tonec Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10647A&gct;=hp&d;=405-0&v;=a13350-159&t;=4
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10647A&gct;=hp&d;=405-0&v;=a10960-159&t;=4
HKU\S-1-5-21-728575759-1552540791-2427072771-501\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKU\S-1-5-21-728575759-1552540791-2427072771-501\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
URLSearchHook: HKU\S-1-5-21-728575759-1552540791-2427072771-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
URLSearchHook: HKU\S-1-5-21-728575759-1552540791-2427072771-501 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-1000 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID;=119776&babsrc;=SP_ss&mntrId;=8A7E083E8E5528A2
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID;=119776&babsrc;=SP_ss&mntrId;=8A7E083E8E5528A2
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2405} URL = http://dts.search.ask.com/sr?src=ieb&gct;=ds&appid;=0&systemid;=405&v;=a13350-159&apn;_uid=4059525214204030&apn;_dtid=BND405&o;=APN10647&apn;_ptnrs=AG8&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-1004 -> DefaultScope Software\Microsoft\Internet Explorer\SearchScopes URL = 
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-1004 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2405} URL = http://dts.search.ask.com/sr?src=ieb&gct;=ds&appid;=0&systemid;=405&v;=a10960-159&apn;_uid=4059525214204030&apn;_dtid=BND405&o;=APN10647&apn;_ptnrs=AG8&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-728575759-1552540791-2427072771-501 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2014-11-07] (Internet Download Manager, Tonec Inc.)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-07] (Adobe Systems Incorporated)
BHO: SavevidComponent Class -> {25EB66FC-03A7-40AA-A073-EAAF723CDD90} -> C:\Program Files\Savevid\SavevidActiveX.dll [2013-09-22] (Bandoo Media Inc.)
BHO: Seairich–NewiTAb -> {29E39A2B-10E8-2FD3-0B6D-3AA291D62047} -> C:\ProgramData\Seairich–NewiTAb\515d0834d6e1e.dll [2013-04-04] ()
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-03-06] (RealDownloader)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-04-04] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Movies Toolbar (Dist. by Bandoo Media, Inc.) -> {95bef0b1-9d3a-41f3-bb8b-8275aaa48c66} -> C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll No File
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2014-10-30] (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: delta Helper Object -> {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -> C:\Program Files\Delta\delta\1.8.16.16\bh\delta.dll [2013-03-13] (Delta-search.com)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-04-04] (Oracle Corporation)
BHO: BBrowwse2osavvE -> {E88B3E14-8BB5-971E-FA26-F06A23EB12B1} -> C:\ProgramData\BBrowwse2osavvE\515d075150794.dll [2013-04-04] ()
BHO: ͬ²½Ò»¼ü°²×°Ö§³Ö -> {F72C8153-7140-4FEE-8F69-CA4579D71195} -> C:\Program Files\Tongbu\Addin\tbIEAddin.dll [2014-09-06] (同步网络平台)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2014-10-30] (McAfee, Inc.)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.16.16\deltaTlbr.dll [2013-03-13] (Delta-search.com)
Toolbar: HKLM - Movies Toolbar (Dist. by Bandoo Media, Inc.) - {95bef0b1-9d3a-41f3-bb8b-8275aaa48c66} - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll No File
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2014-10-30] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2014-10-30] (McAfee, Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\msc\McSnIePl.dll [2013-03-13] (McAfee, Inc.)
Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.123.254
Tcpip\..\Interfaces\{ABF4E7D4-0B7B-4BBA-B9D9-77137A9C4043}: [NameServer] 192.168.123.254
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2010-01-27] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-04-04] (Oracle Corporation)
FF Plugin: @kuaiyong.yrtd.com,version=1.0.1.1 -> C:\Program Files\kuaiyong\np_kyplugin.dll [2012-11-29] (YRTD)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2013-03-13] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.1.18 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-03-22] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-03-06] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-03-06] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-03-06] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.1.18 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-03-22] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-03-06] (RealDownloader)
FF Plugin: @tongbu.com/tongbu,version=0.1 -> C:\Program Files\Tongbu\Addin\npTongbuAddin.dll [2014-09-06] (同步网络平台)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-08] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-08] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-07-31] (VideoLAN)
FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-13] ()
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-07] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-728575759-1552540791-2427072771-1000: @nsroblox.roblox.com/launcher -> C:\Users\acer\AppData\Local\Roblox\Versions\version-8662400b82814a15\\NPRobloxProxy.dll [2013-03-20] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-728575759-1552540791-2427072771-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\acer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-728575759-1552540791-2427072771-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\acer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-03-24] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-728575759-1552540791-2427072771-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\MIgueloooooooo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-21] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-728575759-1552540791-2427072771-501: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Guest\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-04] (Unity Technologies ApS)
FF Extension: FTdownloader V3.0 - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\profiles\extensions\[removed] [2013-04-11]
FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2012-07-23]
FF HKLM\…\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-03-22]
FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2012-07-23]
FF HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\acer\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\acer\AppData\Roaming\IDM\idmmzcc5 [2014-11-23]
FF HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\SeaMonkey\Extensions: [[removed]] - C:\Users\MIgueloooooooo\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\MIgueloooooooo\AppData\Roaming\IDM\idmmzcc5 [2014-12-15]
 
Chrome: 
=======
CHR StartupUrls: Default -> "https://yts.to/home","https://kickass.to/"
CHR DefaultSuggestURL: Default -> 
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~1\mcafee\msc\npmcsn~1.dll ()
CHR Profile: C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (PasswordBox - Log in with 1-Click) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajgnnllmjadopdlmpplonojbfogkjlcl [2014-08-09]
CHR Extension: (Kingdom Rush) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckmfhhjalnddapegkbbohfaodgbnocim [2014-11-02]
CHR Extension: (SiteAdvisor) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-06-02]
CHR Extension: (IDM Integration Module) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-11-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-08]
CHR Extension: (FVD Video Downloader) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2013-06-25]
CHR Extension: (Flow Colors Bridges) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhgjgepioclaangaicgmecejjcebppik [2013-10-24]
CHR Extension: (Savevid) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\liibpejlpebkfpddljfpipkpjhphifon [2013-11-07]
CHR Extension: (Google Wallet) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-15]
CHR Extension: (Flow Colors) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbnmelddedlommnmllmfhoephaidddmk [2013-10-24]
CHR HKLM\…\Chrome\Extension: [aaaajhegnoacmkmglfacmbbhpoadcdkh] - C:\Users\acer\AppData\Local\savevidmoviestoolbarha\GC\toolbar.crx [2013-08-29]
CHR HKLM\…\Chrome\Extension: [bbffdhejhaoiflnpooogkckfdcmmjppn] - C:\Program Files\FTDownloader.com\FTDownloader10.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Users\acer\AppData\Roaming\BabSolution\CR\BabylonChrome1.crx [2013-04-14]
CHR HKLM\…\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\acer\AppData\Roaming\BabSolution\CR\delta1.crx [2013-04-14]
CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - http://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-03-06]
CHR HKLM\…\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2014-11-07]
CHR HKLM\…\Chrome\Extension: [liibpejlpebkfpddljfpipkpjhphifon] - C:\Program Files\Savevid\SavevidChrome.crx [2013-11-07]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [414720 2015-03-14] (BlueStack Systems, Inc.) [File not signed]
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [388824 2015-03-10] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [794328 2015-03-10] (BlueStack Systems, Inc.)
R2 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [173424 2011-06-22] (Egis Technology Inc. )
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [738688 2012-02-08] (Acer Incorporated)
R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [28264 2012-02-29] (Acer Incorporated)
R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1755136 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
R2 Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [255376 2012-02-07] (Acer Incorporated)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\McAfee\msc\McAWFwk.exe [203080 2011-01-29] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [279488 2013-02-25] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [203840 2013-02-19] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169320 2013-02-19] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [172416 2013-02-19] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 nlsX86cc; C:\Windows\system32\NlsSrv32.exe [66560 2012-08-24] (Nalpeiron Ltd.) [File not signed]
R2 NOBU; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2057560 2010-06-02] (Symantec Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 TorchCrashHandler; C:\Users\acer\AppData\Local\Torch\Update\TorchCrashHandler.exe [1217032 2014-10-29] (TorchMedia Inc.) <==== ATTENTION
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131800 2015-03-10] (BlueStack Systems)
S3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [504360 2012-03-22] (Broadcom Corporation.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [60920 2013-02-19] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [146872 2012-04-20] (McAfee, Inc.)
S1 lcrfclvj; C:\Windows\system32\drivers\lcrfclvj.sys [49088 2015-04-10] (Microsoft Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [133416 2013-02-19] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [235264 2013-02-19] (McAfee, Inc.)
S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [65928 2013-02-19] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [363080 2013-02-19] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [565888 2013-02-19] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [92632 2013-02-19] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [210608 2013-02-19] (McAfee, Inc.)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [21600 2012-07-23] (Egis Technology Inc.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16936 2012-07-23] (Egis Technology Inc.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [62240 2012-07-23] (Egis Technology Inc.)
R3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [254056 2011-05-30] (Realtek Semiconductor Corp.)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [113608 2013-01-27] (Power Software Ltd)
S3 vvftav303; C:\Windows\System32\drivers\vvftav303.sys [480128 2007-06-23] (Vimicro Corporation)
S3 ZSMC0303; C:\Windows\System32\Drivers\usbVM303.sys [1472768 2007-05-15] (Vimicro Corporation)
S1 cbirioqf; \??\C:\Windows\system32\drivers\cbirioqf.sys [X]
U3 mfeavfk01; No ImagePath
U3 aswMBR; \??\C:\Users\acer\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\acer\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== Three Months Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-10 11:40 - 2015-04-10 11:44 - 00043660 _____ () C:\Users\acer\Desktop\Addition.txt
2015-04-10 11:36 - 2015-04-10 11:45 - 00038331 _____ () C:\Users\acer\Desktop\FRST.txt
2015-04-10 11:35 - 2015-04-10 11:44 - 00000000 ____D () C:\FRST
2015-04-10 11:25 - 2015-04-10 11:25 - 01135104 _____ (Farbar) C:\Users\acer\Desktop\FRST.exe
2015-04-10 11:21 - 2015-04-10 11:24 - 05198336 _____ (AVAST Software) C:\Users\acer\Desktop\aswMBR.exe
2015-04-10 10:09 - 2015-04-10 10:09 - 00049088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\lcrfclvj.sys
2015-04-09 18:38 - 2015-04-09 18:38 - 00001006 _____ () C:\Users\acer\Desktop\CryptoLocker.lnk
2015-04-09 12:15 - 2015-04-09 12:15 - 00001808 _____ () C:\Users\acer\wow.txt
2015-04-09 11:23 - 2015-04-09 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-04-08 23:08 - 2015-04-08 23:08 - 02142470 _____ () C:\Users\acer\enc_files.txt
2015-04-08 22:36 - 2015-04-10 08:56 - 00000000 ____D () C:\Users\acer\AppData\Roaming\WinDsk
2015-04-08 21:35 - 2015-04-08 21:35 - 00000215 _____ () C:\Users\acer\AppData\Roaming\nyjuikoitg
2015-04-08 18:29 - 2015-04-08 18:29 - 00000000 ____D () C:\Users\acer\.android
2015-04-08 18:25 - 2015-04-08 18:25 - 00001769 _____ () C:\Users\Public\Desktop\Start BlueStacks.lnk
2015-04-08 18:24 - 2015-04-08 18:24 - 00001811 _____ () C:\Users\Public\Desktop\Apps.lnk
2015-04-08 18:20 - 2015-04-08 18:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2015-04-08 18:20 - 2015-04-08 18:22 - 00000000 ____D () C:\ProgramData\BlueStacks
2015-04-08 18:20 - 2015-04-08 18:20 - 00000000 ____D () C:\Program Files\BlueStacks
2015-04-08 07:46 - 2015-04-08 07:46 - 00679808 _____ (Installer Application Soft ) C:\Users\acer\Desktop\dim-screen.exe
2015-04-07 23:18 - 2015-04-07 23:18 - 00000000 ___HD () C:\ProgramData\CanonBJ
2015-04-07 21:24 - 2015-04-07 21:25 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-07 21:19 - 2015-04-07 21:19 - 00000000 ____D () C:\Users\MIgueloooooooo\AppData\Local\Apple Computer
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-10 11:09 - 2012-09-09 09:12 - 01950826 _____ () C:\Windows\WindowsUpdate.log
2015-04-10 11:02 - 2013-03-20 22:29 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-10 11:00 - 2014-11-30 01:48 - 00000802 _____ () C:\Windows\Tasks\Security Center Update - 817942462.job
2015-04-10 10:43 - 2013-03-27 22:38 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-728575759-1552540791-2427072771-1000UA.job
2015-04-10 10:41 - 2013-11-07 15:15 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2015-04-10 09:24 - 2014-12-14 21:51 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-10 09:16 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-10 09:15 - 2013-05-24 21:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-10 08:48 - 2013-03-27 22:38 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-728575759-1552540791-2427072771-1000Core.job
2015-04-09 21:15 - 2013-03-21 17:14 - 00000000 ____D () C:\Users\acer\Desktop\FILES
2015-04-09 18:44 - 2009-07-14 12:39 - 00118337 _____ () C:\Windows\setupact.log
2015-04-09 15:16 - 2014-07-29 11:59 - 26094195 _____ () C:\Users\acer\Downloads\Pop Danthology 2013 - Mashup of 68 songs! - YouTube.mp4
2015-04-09 15:16 - 2013-04-27 14:48 - 00914549 _____ () C:\Users\acer\Downloads\rarbsd-4.2.0.tar.gz
2015-04-09 15:15 - 2014-08-01 19:58 - 00061886 _____ () C:\Users\acer\Downloads\GTA-San-Andreas-save-game-ios-100-completed-by-VoltSmith45.zip
2015-04-09 14:10 - 2013-11-13 16:08 - 00236544 ___SH () C:\Users\MIgueloooooooo\Desktop\Thumbs.db
2015-04-09 14:06 - 2014-10-19 23:07 - 00012447 _____ () C:\Users\acer\Documents\Project in Computer (2nd Quarter)(2014).xlsx
2015-04-09 14:06 - 2014-10-19 23:07 - 00000165 ____H () C:\Users\acer\Documents\~$Project in Computer (2nd Quarter)(2014).xlsx
2015-04-09 12:15 - 2013-03-19 11:43 - 00000000 ____D () C:\Users\acer
2015-04-09 11:18 - 2013-04-07 13:14 - 00000000 ____D () C:\Users\acer\AppData\Roaming\uTorrent
2015-04-09 08:02 - 2013-03-20 22:29 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-08 23:10 - 2014-11-16 11:49 - 00023977 _____ () C:\Users\acer\Desktop\JamAarReg.rar
2015-04-08 23:10 - 2014-10-27 18:46 - 07207014 _____ () C:\Users\acer\Desktop\Soc Sci Presentation.pptx
2015-04-08 23:10 - 2014-01-27 14:32 - 00022016 ___SH () C:\Users\acer\Desktop\Thumbs.db
2015-04-08 23:10 - 2013-12-15 21:20 - 92437920 _____ () C:\Users\acer\Desktop\GEDC1280.avi.MOV
2015-04-08 18:24 - 2009-07-14 10:37 - 00000000 __RHD () C:\Users\Public\Libraries
2015-04-08 17:43 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\rescache
2015-04-08 13:33 - 2013-08-05 22:50 - 00000000 ____D () C:\Users\acer\AppData\Roaming\vlc
2015-04-08 13:08 - 2009-07-14 12:34 - 00022624 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-08 13:08 - 2009-07-14 12:34 - 00022624 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-08 11:44 - 2014-11-22 00:11 - 00000000 ____D () C:\Users\acer\AppData\Roaming\FrameworkUpdate
2015-04-08 10:47 - 2013-11-07 15:15 - 00001464 _____ () C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2015-04-08 10:07 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-08 08:10 - 2013-03-31 19:00 - 00000000 ____D () C:\Users\acer\AppData\Roaming\DMCache
2015-04-08 08:02 - 2013-07-27 21:10 - 00000000 ____D () C:\Users\acer\Downloads\INSTALLERS
2015-04-08 07:54 - 2014-09-10 18:08 - 00000000 ____D () C:\Users\acer\Downloads\TORRENTZ
2015-04-07 23:17 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\system32\spool
2015-04-07 23:16 - 2014-08-05 20:33 - 00000000 ____D () C:\Users\acer\AppData\Roaming\Dropbox
2015-04-07 23:12 - 2009-07-14 12:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-07 21:19 - 2013-10-28 09:12 - 00000000 ____D () C:\Users\MIgueloooooooo\AppData\Roaming\Apple Computer
2015-04-07 21:03 - 2014-12-06 14:27 - 00000000 ____D () C:\Users\PAPA\AppData\Local\Google
 
==================== Files in the root of some directories =======
 
2015-04-08 21:35 - 2015-04-08 21:35 - 0225280 _____ () C:\Users\acer\AppData\Roaming\01. Untrust Us.mp3
2014-11-11 19:09 - 2014-11-11 19:06 - 0628224 _____ () C:\Users\acer\AppData\Roaming\5a55e5.exe
2013-04-23 08:49 - 2013-02-10 05:55 - 0114176 _____ () C:\Users\acer\AppData\Roaming\BabMaint.exe
2015-04-08 21:35 - 2015-04-08 21:35 - 0000215 _____ () C:\Users\acer\AppData\Roaming\nyjuikoitg
2014-11-15 19:48 - 2014-11-15 19:46 - 0716288 _____ (Duplex Secure Ltd.) C:\Users\acer\AppData\Roaming\Q7w3u.exe
2014-07-08 21:09 - 2014-11-12 19:17 - 0000600 _____ () C:\Users\acer\AppData\Roaming\winscp.rnd
2013-10-25 11:41 - 2013-10-25 11:41 - 0000000 ____H () C:\Users\acer\AppData\Roaming\winsvcon.txt
2014-11-09 14:59 - 2014-11-09 14:56 - 0922112 _____ (Corel Corporation) C:\Users\acer\AppData\Roaming\Y3c7s.exe
2014-11-15 19:15 - 2014-11-15 19:15 - 0000480 ____H () C:\Users\acer\AppData\Roaming\麽鎒駓覜
2014-09-22 20:47 - 2014-09-22 20:47 - 0003584 _____ () C:\Users\acer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-08 21:06 - 2014-07-08 21:44 - 0000600 _____ () C:\Users\acer\AppData\Local\PUTTY.RND
2013-07-27 21:32 - 2013-07-27 21:32 - 0007648 _____ () C:\Users\acer\AppData\Local\Resmon.ResmonCfg
2014-11-15 19:18 - 2014-12-04 09:50 - 0000552 _____ () C:\ProgramData\@system.temp
2014-11-15 19:15 - 2014-12-04 09:51 - 0000288 ____H () C:\ProgramData\@system3.att
 
Some content of TEMP:
====================
C:\Users\acer\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpetrg3k.dll
C:\Users\acer\AppData\Local\Temp\ICReinstall_dim-screen.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\Delta.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\DeltaTB.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\i4jdel0.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\ICReinstall_FileExtractorSetup.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\MybabylonTB.exe
C:\Users\MIgueloooooooo\AppData\Local\Temp\WSSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-04-08 17:33
 
==================== End Of Log ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by [removed] at 2015-04-10 11:46:16
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
¿ìÓÃÆ»¹ûÖúÊÖ 2.2.2.7 (HKLM\…\{2E3FA0CF-AC2D-4E6F-8EF3-D75E91681441}_is1) (Version: 2.2.2.7 - ±±¾©ÓÆÈ»ÌìµØ¿Æ¼¼ÓÐÏÞ¹«Ë¾)
µTorrent (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\uTorrent) (Version: 3.4.2.32691 - BitTorrent Inc.)
A4 TECH PC Camera H (HKLM\…\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D303B}) (Version:  - )
A4 TECH PC Camera H (HKLM\…\{CE3B8E96-B0AF-4871-9178-1519B58E3A93}) (Version: 2007.11.12 - A4 TECH)
Acer Crystal Eye Webcam (HKLM\…\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2904.00 - CyberLink Corp.)
Acer Crystal Eye Webcam (Version: 1.5.2904.00 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (HKLM\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated)
Acer Games (HKLM\…\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM\…\Acer Registration) (Version: 1.04.3506 - Acer Incorporated)
Acer ScreenSaver (HKLM\…\Acer Screensaver) (Version: 20.12.0110.1025 - Acer Incorporated)
Acer Updater (HKLM\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3501 - Acer Incorporated)
Acer VCM (HKLM\…\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3501 - Acer Incorporated)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
Adobe Flash Player 10 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 10.0.45.2 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 11.2.202.222 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\…\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
Advanced Archive Password Recovery (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Advanced Archive Password Recovery) (Version: 4.53 - ElcomSoft Co. Ltd.)
Akhra: The Treasures (Version: 2.2.0.98 - WildTangent) Hidden
Alice's Magical Mahjong (Version: 2.2.0.98 - WildTangent) Hidden
Apple Application Support (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Babylon Chrome Toolbar (HKLM\…\Babylon Chrome Toolbar) (Version:  - Babylon Ltd.) <==== ATTENTION
BBrowwse2osavvE (HKLM\…\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}) (Version:  - BrowseToSave) <==== ATTENTION
Bejeweled 3 (Version: 2.2.0.98 - WildTangent) Hidden
Bing Bar (HKLM\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
BlueStacks App Player 0.9.17.4138 Superuser BSEasy (HKLM\…\{4FCF716C-CEB4-499D-AFB8-A5375105EC2A}) (Version: 0.9.17.4138 - BlueStack Systems, Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
BrowseToSave 1.74 (HKLM\…\SP_48c708f2) (Version:  - ) <==== ATTENTION
Chuzzle Deluxe (Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Delta Chrome Toolbar (HKLM\…\Delta Chrome Toolbar) (Version:  - Delta) <==== ATTENTION
Delta toolbar   (HKLM\…\delta) (Version: 1.8.16.16 - Delta) <==== ATTENTION
Diego's Ultimate Rescue (Version: 2.2.0.95 - WildTangent) Hidden
Dropbox (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Dropbox) (Version: 2.10.52 - Dropbox, Inc.)
eBay Worldwide (HKLM\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
EPUB File Reader (HKLM\…\{818C5857-5C74-4CAC-9F43-E5597086852D}_is1) (Version:  - )
Euro Truck Simulator 2 (HKLM\…\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.1.1 - SCS Software)
Evernote v. 4.5.2 (HKLM\…\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
Facebook Video Calling 3.1.0.521 (HKLM\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FBReader for Windows (HKLM\…\FBReader for Windows) (Version:  - )
Final Drive: Nitro (Version: 2.2.0.95 - WildTangent) Hidden
Fooz Kids (HKLM\…\FoozKids) (Version: 3.1.2 - FUHU, Inc.)
Fooz Kids (Version: 3.1.2 - FUHU, Inc.) Hidden
Fooz Kids Platform (HKLM\…\{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}) (Version: 2.1 - FUHU, Inc.)
Fotogalerija Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM\…\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
iCare Data Recovery 5.2 (HKLM\…\iCare Data Recovery_is1) (Version:  - iCare Software)
iCloud (HKLM\…\{AC6EE263-E4DD-4150-9014-689B1D4A3315}) (Version: 4.0.5.20 - Apple Inc.)
Identity Card (HKLM\…\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Insaniquarium Deluxe (Version: 2.2.0.97 - WildTangent) Hidden
Intel(R) Control Center (HKLM\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.14.8.1083 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Internet Download Manager (HKLM\…\Internet Download Manager) (Version:  - Tonec Inc.)
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 21 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.210 - Oracle)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM\…\LManager) (Version: 5.1.7 - Acer Inc.)
LEGO MINDSTORMS NXT - English Language Pack (HKLM\…\{D70FB770-BE91-4A1C-942B-F2F7C3BFB2C7}) (Version: 2.0.100.0 - The LEGO Group)
LEGO MINDSTORMS NXT Driver (HKLM\…\{D30E4145-9120-4497-AD35-F78482C3CF88}) (Version: 1.17.770 - LEGO)
LEGO MINDSTORMS NXT Migration Package (HKLM\…\{6C1D47CC-682C-4673-8CA8-DEE659628599}) (Version: 1.2.8.0 - LEGO)
LEGO MINDSTORMS NXT Software v2.0 (HKLM\…\{5B7EDCF8-E6AD-4E99-972C-34BF1F07B349}) (Version: 2.0.114.0 - LEGO)
McAfee Internet Security Suite (HKLM\…\MSC) (Version: 11.6.511 - McAfee, Inc.)
McAfee SiteAdvisor (HKLM\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.154 - McAfee, Inc.)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Access 2010 (HKLM\…\Office14.Access) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office 2010 (HKLM\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5139.5005 - Microsoft Corporation)
Microsoft PowerPoint 2010 (HKLM\…\Office14.POWERPOINT) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
MixPad (HKLM\…\MixPad) (Version: 3.46 - NCH Software)
Movies Toolbar for Chrome (Dist. by Bandoo Media, Inc.) (HKLM\…\savevidmoviestoolbarhaCR) (Version: 1.6.2.0 - APN LLC) <==== ATTENTION
Movies Toolbar for Internet Explorer (Dist. by Bandoo Media, Inc.) (HKLM\…\savevidmoviestoolbarhaIE) (Version: 1.6.2.0 - APN LLC) <==== ATTENTION
Mozilla Firefox 21.0 (x86 en-US) (HKU\S-1-5-21-728575759-1552540791-2427072771-501\…\Mozilla Firefox 21.0 (x86 en-US)) (Version: 21.0 - Mozilla)
My Farm Life (Version: 2.2.0.97 - WildTangent) Hidden
My Kingdom for the Princess 3 (Version: 2.2.0.98 - WildTangent) Hidden
MyWinLocker 4 (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Need for Speed™ Most Wanted (HKLM\…\{ADE91A13-434D-4229-00BC-182BAD607303}) (Version:  - )
Network Addon Mod 31.1 (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Network Addon Mod) (Version: 31.1 - The NAM Team)
newsXpresso (HKLM\…\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (Version: 1.0.0.40 - esobi Inc.) Hidden
Norton Online Backup (HKLM\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
Online Weather (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Online Weather) (Version: 1.0 - )
PFConfig 1.0.296 (HKLM\…\PFConfig) (Version: 1.0.296 - Portforward.com)
PhoneRescue 1.4.0 (HKLM\…\{2FAFFE02-4D6B-4C0A-906B-1B33DAF0DD14}}_is1) (Version: 1.4.0 - iMobie Inc.)
Poczta usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Port Forward Network Utilities 2.0.1 (HKLM\…\Port Forward Network Utilities) (Version: 2.0.1 - Portforward.com)
Pošta Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
PowerISO (HKLM\…\PowerISO) (Version: 5.5 - Power Software Ltd)
PP助手2.0 (HKLM\…\ihelper) (Version: 2.1.0.4026 - 广州铁人网络科技有限公司)
PP助手2.0 Win版 (HKLM\…\PP助手2.0 Win版) (Version: 2.2.0.4174 - 广州铁人网络科技有限公司)
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
RealDownloader (Version: 1.3.1 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.0 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6549 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.83 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Running Sheep (Version: 2.2.0.98 - WildTangent) Hidden
Savevid (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Savevid) (Version: 0.0.0.881 - Bandoo Media Inc) <==== ATTENTION
Seairich–NewiTAb (HKLM\…\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}) (Version:  - NewTab) <==== ATTENTION
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
SimCity 4 Deluxe (HKLM\…\{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}) (Version:  - )
Skip-Bo - Castaway Caper (Version: 2.2.0.95 - WildTangent) Hidden
Skype™ 6.11 (HKLM\…\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Slingo Deluxe (Version: 2.2.0.95 - WildTangent) Hidden
Super Granny 6 (Version: 2.2.0.97 - WildTangent) Hidden
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.1.18.0 - Synaptics Incorporated)
Tongbu Assistant 2.1.8.0 (HKLM\…\Tongbu2) (Version: 2.1.8.0 - Xiamen Tongbu Network Ltd.)
Torch (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\Torch) (Version: 36.0.0.8226 - Torch Media, Inc) <==== ATTENTION
trakAxPC (HKLM\…\{406550D6-0FAA-4B40-91D3-87E0BCB37482}) (Version: 4.02.4 - HighAndes)
Unity Web Player (HKU\S-1-5-21-728575759-1552540791-2427072771-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-728575759-1552540791-2427072771-1004\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-728575759-1552540791-2427072771-501\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update Installer for WildTangent Games App (Version:  - WildTangent) Hidden
VideoPad Video Editor (HKLM\…\VideoPad) (Version: 3.22 - NCH Software)
VLC media player 2.0.8 (HKLM\…\VLC media player) (Version: 2.0.8 - VideoLAN)
WavePad Sound Editor (HKLM\…\WavePad) (Version: 5.48 - NCH Software)
Wedding Dash (Version: 2.2.0.95 - WildTangent) Hidden
Welcome Center (HKLM\…\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
WIDCOMM Bluetooth Software (HKLM\…\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.2610 - Broadcom Corporation)
WildTangent Games App (Acer Games) (Version: 4.0.5.32 - WildTangent) Hidden
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinSCP 5.5.4 (HKLM\…\winscp3_is1) (Version: 5.5.4 - Martin Prikryl)
Wondershare Dr.Fone for iOS(Build 4.8.0.7) (HKLM\…\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 4.8.0.7 - Wondershare Software Co.,Ltd.)
Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\acer\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\acer\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\InprocServer32 -> C:\Users\acer\AppData\Local\Roblox\Versions\version-8662400b82814a15\RobloxProxy.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\acer\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}\localserver32 -> C:\Users\acer\AppData\Local\Torch\Application\36.0.0.8226\delegate_execute.exe (The Chromium Authors)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\acer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\acer\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-1004_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\MIgueloooooooo\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-728575759-1552540791-2427072771-501_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Guest\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
 
==================== Restore Points  =========================
 
10-04-2015 08:37:31 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 10:04 - 2013-05-30 13:51 - 00010298 ___AH C:\Windows\system32\Drivers\etc\hosts
37.221.160.35 www.imeetzu.com
37.221.160.35 imeetzu.com
37.221.160.35 www.omegle.com
37.221.160.35 omegle.com
37.221.160.35 www.runescape.com
37.221.160.35 runescape.com
37.221.160.35 google.com
37.221.160.35 www.google.ae
37.221.160.35 www.google.com.af
37.221.160.35 www.google.com.ag
37.221.160.35 www.google.off.ai
37.221.160.35 www.google.am
37.221.160.35 www.google.com.ar
37.221.160.35 www.google.as
37.221.160.35 www.google.at
37.221.160.35 www.google.com.au
37.221.160.35 www.google.az
37.221.160.35 www.google.ba
37.221.160.35 www.google.com.bd
37.221.160.35 www.google.be
37.221.160.35 www.google.bg
37.221.160.35 www.google.com.bh
37.221.160.35 www.google.bi
37.221.160.35 www.google.com.bo
37.221.160.35 www.google.com.br
37.221.160.35 www.google.bs
37.221.160.35 www.google.co.bw
37.221.160.35 www.google.com.bz
37.221.160.35 www.google.ca
 
There are 325 more lines.
 
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {073CBE52-44F1-4BE6-9966-689CA8382317} - \Security Center Update - 2001078741 No Task File <==== ATTENTION
Task: {0A604231-8652-4766-B6D6-3AEA3A685C38} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {0D5B23A8-0AAC-4AEF-BE21-D5A228891CD8} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-728575759-1552540791-2427072771-1004 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {15548545-4059-4B7D-9A31-205C0D6380A5} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {1BA55BD5-3813-46DB-A925-13F3D9C06323} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {22404395-B07C-45A2-AD44-6EA61247C052} - \Security Center Update - 544203410 No Task File <==== ATTENTION
Task: {2AE8160E-C2C7-43DC-BD74-2EA3045E13B7} - System32\Tasks\EPUpdater => C:\Users\acer\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION
Task: {3CF82DFF-0CF2-432D-AA15-06962B644FDB} - \Security Center Update - 203538831 No Task File <==== ATTENTION
Task: {3FC4B3BC-DBB4-4D37-80D0-6F8988BA2BAE} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2014-10-17] (Apple Inc.)
Task: {581C66E5-4003-49A8-ADCE-DAC267487A48} - \Security Center Update - 214585899 No Task File <==== ATTENTION
Task: {59EAA4F3-049A-4380-AFA9-128BD417EDD5} - \Security Center Update - 3693161717 No Task File <==== ATTENTION
Task: {5EA6B8D3-4A66-4266-B35B-FEAA7FECC7CC} - \Security Center Update - 1352438397 No Task File <==== ATTENTION
Task: {6968F5D7-4F70-415A-983D-67B28B36E84E} - System32\Tasks\Security Center Update - 817942462 => C:\Users\acer\AppData\Roaming\Ozuryxal\ewevany.exe [2014-09-19] (Anurisel Corporatu) <==== ATTENTION
Task: {71EF7A1F-2221-4321-AD0A-E9DA1BD7FF65} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-728575759-1552540791-2427072771-1004 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {8A0C1F8F-DD84-495B-A3AB-0E2B65F36D9F} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
Task: {9406C441-093A-4D61-A3DF-CF4BED46603F} - System32\Tasks\{1A91BB3B-2A7E-4BAA-9106-CB3B99698813} => pcalua.exe -a "C:\Users\acer\Desktop\FILES\MOVIES\The Best of Me 2014\WMP x264 Codec Pack.exe" -d "C:\Users\acer\Desktop\FILES\MOVIES\The Best of Me 2014"
Task: {A18A481A-DBAE-401F-B59A-7593275DEE6E} - \Security Center Update - 250425684 No Task File <==== ATTENTION
Task: {A488FAFF-C779-47E2-821B-763C1E580C6F} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated)
Task: {A4BD8347-03CE-4505-87FE-F3FE095600A6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-20] (Google Inc.)
Task: {AF3E79B6-CEF1-4B15-90CA-859D7A4A7151} - System32\Tasks\{41007B59-9A7D-4276-A73A-A658419DA762} => C:\Users\acer\Desktop\FILES\MOVIES\The Best of Me 2014\WMP x264 Codec Pack.exe
Task: {C451414D-55FA-4ECE-BABF-A8261BCFCBA6} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
Task: {C47B1DD2-DC86-49D3-9DBB-3963C1BB404B} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-728575759-1552540791-2427072771-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {C6CA2FE1-5C1D-4687-ADAD-E50B7F5E0F5B} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {D1DA8876-E980-4651-BB9B-3FFE34676863} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-728575759-1552540791-2427072771-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {D4F3D04E-079D-48D1-8A5C-62533DD4907D} - System32\Tasks\Games\UpdateCheck_S-1-5-21-728575759-1552540791-2427072771-501
Task: {D7C5CF16-81EB-4E45-ACF2-32B9E351FA83} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-728575759-1552540791-2427072771-1000UA => C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-27] (Facebook Inc.)
Task: {DA913C37-FD58-4499-9723-825AE846BC40} - \Security Center Update - 1289334620 No Task File <==== ATTENTION
Task: {DB4008C0-7F89-467E-A03F-27B92046591C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-728575759-1552540791-2427072771-1000Core => C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-27] (Facebook Inc.)
Task: {F5A0DCBD-1C71-4A45-9E97-2B8674B68934} - \Security Center Update - 2576887529 No Task File <==== ATTENTION
Task: {F5F793FC-E0BD-4179-97F1-F7D82CBA009E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-20] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-728575759-1552540791-2427072771-1000Core.job => C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-728575759-1552540791-2427072771-1000UA.job => C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Security Center Update - 817942462.job => C:\Users\acer\AppData\Roaming\Ozuryxal\ewevany.exe <==== ATTENTION
 
==================== Loaded Modules (whitelisted) ==============
 
2012-11-09 01:36 - 2012-11-09 01:36 - 00024064 _____ () C:\Windows\System32\sxc2ml3.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-03-06 02:21 - 2013-03-06 02:21 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-10-26 16:04 - 2014-10-26 16:04 - 02416128 _____ () C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll
2014-10-26 16:05 - 2014-10-26 16:05 - 01828352 _____ () C:\ProgramData\Microsoft\Secure\Icons\IconsCacheHelper.dll
2013-11-03 14:01 - 2006-07-04 14:16 - 00049152 _____ () C:\Windows\Domino.exe
2014-12-05 10:37 - 2014-12-05 10:37 - 00035840 _____ () C:\Users\acer\AppData\Local\Anjkworks\AtNet3D.dll
2014-10-16 13:39 - 2014-10-16 13:39 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll
2012-07-23 15:35 - 2010-11-06 15:50 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2015-04-08 15:35 - 2015-03-31 05:07 - 01174856 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\libglesv2.dll
2015-04-08 15:35 - 2015-03-31 05:07 - 00080200 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\libegl.dll
2015-04-08 15:35 - 2015-03-31 05:07 - 09279304 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll
2015-04-08 15:35 - 2015-03-31 05:07 - 14974280 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Windows\system32\Drivers\lcrfclvj.sys:changelist
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-728575759-1552540791-2427072771-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\acer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-728575759-1552540791-2427072771-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\MIgueloooooooo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-728575759-1552540791-2427072771-1009\Control Panel\Desktop\\Wallpaper -> C:\Users\PAPA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-728575759-1552540791-2427072771-501\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.123.254
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk => C:\Windows\pss\Acer VCM.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Facebook Update => "C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files\PowerISO\PWRISOVM.EXE -startup
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
 
==================== Accounts: =============================
 
acer (S-1-5-21-728575759-1552540791-2427072771-1000 - Administrator - Enabled) => C:\Users\acer
Administrator (S-1-5-21-728575759-1552540791-2427072771-500 - Administrator - Disabled)
Guest (S-1-5-21-728575759-1552540791-2427072771-501 - Administrator - Disabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-728575759-1552540791-2427072771-1008 - Limited - Enabled)
MIgueloooooooo (S-1-5-21-728575759-1552540791-2427072771-1004 - Limited - Enabled) => C:\Users\MIgueloooooooo
PAPA (S-1-5-21-728575759-1552540791-2427072771-1009 - Limited - Enabled) => C:\Users\PAPA
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Virtual WiFi Miniport Adapter
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/10/2015 08:34:31 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
Error: BITS connection error Type: 150::InternetConnectionFailure.
 
Error: (04/09/2015 09:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 71496
 
Error: (04/09/2015 09:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 71496
 
Error: (04/09/2015 09:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/09/2015 09:33:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 70482
 
Error: (04/09/2015 09:33:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 70482
 
Error: (04/09/2015 09:33:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/09/2015 09:33:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 69483
 
Error: (04/09/2015 09:33:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 69483
 
Error: (04/09/2015 09:33:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (04/10/2015 08:35:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the btwdins service.
 
Error: (04/10/2015 08:33:51 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the EapHost service.
 
Error: (04/10/2015 08:33:21 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
 
Error: (04/10/2015 08:33:21 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the DsiWMIService service.
 
Error: (04/09/2015 08:19:32 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
Error: (04/09/2015 07:45:37 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
Error: (04/09/2015 01:40:55 PM) (Source: volsnap) (EventID: 36) (User: )
Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
 
Error: (04/09/2015 00:41:25 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the DsiWMIService service.
 
Error: (04/09/2015 07:39:21 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
 
Error: (04/09/2015 07:39:21 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Appinfo service.
 
 
Microsoft Office Sessions:
=========================
Error: (04/10/2015 08:34:31 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Error: BITS connection error Type: 150::InternetConnectionFailure.
 
Error: (04/09/2015 09:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 71496
 
Error: (04/09/2015 09:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 71496
 
Error: (04/09/2015 09:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/09/2015 09:33:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 70482
 
Error: (04/09/2015 09:33:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 70482
 
Error: (04/09/2015 09:33:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/09/2015 09:33:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 69483
 
Error: (04/09/2015 09:33:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 69483
 
Error: (04/09/2015 09:33:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-04-08 10:37:53.824
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-14 04:29:29.284
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-14 04:29:29.284
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-14 04:28:33.481
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-14 03:54:38.203
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-14 03:54:38.203
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-14 03:51:53.498
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-26 15:28:34.419
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-26 15:21:26.976
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-26 09:41:02.665
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\mcafee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Atom(TM) CPU N2800 @ 1.86GHz
Percentage of memory in use: 96%
Total physical RAM: 2036.3 MB
Available physical RAM: 80.27 MB
Total Pagefile: 4833.91 MB
Available Pagefile: 775.01 MB
Total Virtual: 2047.88 MB
Available Virtual: 1899.7 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:452.66 GB) (Free:22.81 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0BEC2444)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452.7 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

 

Hello AnyaIsTheOne, welcome to WhatTheTech's Malware Removal forum!
 
My name is Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that.  :)
 
======================================================
 
Please read through the points below to ensure this process moves as quickly and efficiently as possible.

  • Ensure you read through my instructions thoroughly, and carry out each step in the order specified.
  • Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in providing the best set of instructions for you.
  • Please backup important files before proceeding with my instructions. Malware removal can be unpredictable at times.   
  • If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
  • Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
  • I will notify you when I believe your computer is free of malware. Please bear in mind, absence of symptoms does not necessarily correlate to absence of malware, so please wait until the "All Clean". 
  • Ensure you are following this topic. Click [external image: etYzdbu.png] at the top of the page. 

======================================================

I apologise for the delay.
 

My Laptop has cryptolocker, What Do I Do??
I searched about it, and found out that there was a way to decrypt my files using https://www. decryptcryptolocker.com/ , but whenever I upload the file it says that the file is not encrypted, but im clearly sure the files are incrypted and I really really need all the files for my homework

Your computer doesn't have CryptoLocker. 
File have been encrypted by PClock. 
 
Fortunately, there may be a solution to brute force decryption of your files. It depends on the variant of PClock. 
This is something we can explore. However, please be aware that there are no guarantees. 
 
—
 
Your computer is badly compromised. 
Zbot, Miuref, Sathurbot and Fleercivet to name a few. And of course, PClock. This type of malware is very serious, which is why I'm going to issue the following warning. 
 

[external image: goGMWSt.gif]BACKDOOR WARNING
 
——————————
 
One or more of the identified infections is known to use a backdoor, that allows attackers to remotely control your computer, download/execute files and steal system, financial & personal information.
 
If your computer has been used for online banking, has credit card information or other sensitive data, using a non-infected computer/device you should immediately change all account information (including those used for Email, eBay, Paypal, online forums, etc).
 
Banking and credit card institutions should be notified of the possible security breach. Please read the following article for more information: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
 
Whilst the identified infection(s) can be removed, there is no way to guarantee the trustworthiness of your computer unless you reformat your Hard Drive and reinstall your Operating System. This is due to the nature of the infection, which allows a remote attacker to make any number of modifications. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat/reinstall. Please read the following articles for more information.

  • When should I re-format? How should I reinstall?
  • Help: I Got Hacked. Now What Do I Do?
  • Where to draw the line? When to recommend a format and reinstall?
You now have the choice between cleaning the infection(s) present or reformatting your computer. Ultimately, the decision is personal, and what you're most comfortable with. Once you've read the articles linked above, let me know if you have any questions, and how you wish to proceed.

 
Please let me know your thoughts on above, and how you wish to proceed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI