Hello..
My laptop has been infected Bitcryptor Ransomware. I have removed the malware but all my files have been encrypted by it. How to decrypt the files?
I have checked on the other websites there is no solution available.
I have the bitcoin address.
Please help.
[removed]
Platform: Windows 8.1 Pro with Media Center (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
() C:\Users\VDG\Downloads\avira_antivirus_en-us.exe
(Avira Operations GmbH & Co. KG) C:\Users\VDG\AppData\Local\Temp\RarSFX0\presetup.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Enigma Software Group USA, LLC.) C:\Users\VDG\AppData\Local\Temp\esg_uninstall.exe~
(Ginger Software) C:\Program Files (x86)\Ginger\GingerServices\GingerServices.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3498728 2014-12-03] (Adobe Systems Inc.)
HKLM-x32\…\Run: [NokiaMServer] => C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
HKLM-x32\…\Run: [NokiaMusic FastStart] => C:\Program Files (x86)\Nokia\Nokia Music Player\NokiaMusicPlayer.exe [2193000 2011-10-21] (Nokia)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM-x32\…\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [383768 2013-07-12] (Alcor Micro Corp.)
HKLM-x32\…\Run: [zenvpn] => C:\Program Files (x86)\ZenVPN OpenVPN bundle\bin\zenvpn.exe
HKLM-x32\…\Run: [Avira Systray] => C:\Program Files (x86)\Avira\Launcher\Avira.OE.Systray.exe [128760 2015-05-07] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\Run: [] => [X]
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\Run: [uTorrent] => C:\Users\VDG\AppData\Roaming\uTorrent\uTorrent.exe [1999952 2015-04-29] (BitTorrent Inc.)
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\MountPoints2: {26ac4df8-a565-11e4-8271-4a9d2419d092} - "D:\AutoRun.exe"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\MountPoints2: {34621dd5-5a65-11e4-8258-c0143dc1280e} - "D:\AutoRun.exe"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\MountPoints2: {34621e36-5a65-11e4-8258-c0143dc1280e} - "D:\AutoRun.exe"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\MountPoints2: {399ebc6d-e54a-11e4-828c-3c970e443cf5} - "C:\Windows\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL D:\setup.exe
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\MountPoints2: {5355d29f-65a8-11e4-825b-c0143dc1280e} - "C:\Windows\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL D:\start.exe
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\MountPoints2: {5d1b3056-ecf4-11e4-8294-3c970e443cf5} - "D:\AutoRun.exe"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\Winlogon: [Shell] C:\Windows\explorer.exe [2501368 2015-01-28] (Microsoft Corporation) <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-05-09]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [!BTSync2.0.105Done] -> {581FFA04-FC33-0069-0002-95003A5CDE89} => C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll [2015-04-19] ()
ShellIconOverlayIdentifiers: [!BTSync2.0.105RO] -> {581FFA03-FC33-0069-0002-95003A5CDE89} => C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll [2015-04-19] ()
ShellIconOverlayIdentifiers: [!BTSync2.0.105RW] -> {581FFA02-FC33-0069-0002-95003A5CDE89} => C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll [2015-04-19] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2014-12-02] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2014-12-02] (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-30] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-12-03] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-30] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-12-03] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2014-12-02] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-12-03] (Adobe Systems Incorporated)
Tcpip\Parameters: [DhcpNameServer] 172.17.36.5 172.17.36.9 4.2.2.2
Tcpip\..\Interfaces\{C1390199-E5BC-451C-8970-93067C2AE4E5}: [NameServer] 172.17.36.5,172.17.36.9,4.2.2.2
FireFox:
========
FF ProfilePath: C:\Users\VDG\AppData\Roaming\Mozilla\Firefox\Profiles\u6trjwno.default
FF NetworkProxy: "backup.ftp", ""
FF NetworkProxy: "backup.ftp_port", 0
FF NetworkProxy: "backup.socks", ""
FF NetworkProxy: "backup.socks_port", 0
FF NetworkProxy: "backup.ssl", ""
FF NetworkProxy: "backup.ssl_port", 0
FF NetworkProxy: "ftp", "127.0.0.1"
FF NetworkProxy: "ftp_port", 48100
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "127.0.0.1"
FF NetworkProxy: "socks_port", 48100
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 48100
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-25] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-25] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2013-10-02] ( )
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
FF Plugin HKU\S-1-5-21-504121640-2405822300-1051111340-1001: gingersoftware.com/gingerPlugin -> C:\Program Files (x86)\Ginger\GingerServices\GingerServicesProxy.dll [2014-09-09] (Ginger Software)
FF Extension: Avira Browser Safety - C:\Users\VDG\AppData\Roaming\Mozilla\Firefox\Profiles\u6trjwno.default\Extensions\[removed] [2015-05-20]
FF Extension: BitTorrent TorqueChrome Plugin - C:\Users\VDG\AppData\Roaming\Mozilla\Firefox\Profiles\u6trjwno.default\Extensions\[removed] [2015-04-27]
FF Extension: Torrent Tornado - C:\Users\VDG\AppData\Roaming\Mozilla\Firefox\Profiles\u6trjwno.default\Extensions\[removed] [2015-04-20]
FF Extension: BitTorrent Surf (Beta) - C:\Users\VDG\AppData\Roaming\Mozilla\Firefox\Profiles\u6trjwno.default\Extensions\[removed] [2015-04-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Ginger\Mozilla\[removed]
FF Extension: Ginger - C:\Program Files (x86)\Ginger\Mozilla\[removed] [2014-11-05]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-11-13]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: No Name - C:\Users\VDG\AppData\Roaming\IDM\idmmzcc5 [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR Profile: C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3
CHR Extension: (Google Docs) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-20]
CHR Extension: (Google Drive) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-20]
CHR Extension: (YouTube) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-20]
CHR Extension: (Google Search) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-20]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2015-05-20]
CHR Extension: (Avira Browser Safety) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-05-20]
CHR Extension: (Bookmark Manager) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-20]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-20]
CHR Extension: (Google Wallet) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-20]
CHR Extension: (Gmail) - C:\Users\VDG\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-20]
CHR HKLM\…\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [Not Found]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-12-03]
CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [Not Found]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [206584 2015-05-07] (Avira Operations GmbH & Co. KG)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-05] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [976600 2013-09-04] (Broadcom Corporation.)
R2 Crypkey License; C:\Windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [File not signed]
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-05] (Microsoft Corporation)
S4 GingerUpdateService; C:\Program Files (x86)\Ginger\GingerUpdateService\GingerUpdateService.exe [417168 2014-09-09] (Ginger Software)
S4 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S4 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [317640 2015-03-30] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S4 Mobile Partner. RunOuc; C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [655712 2014-10-23] ()
S4 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-03-10] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-03-12] (Razer Inc.)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-07-02] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S4 RIM MDNS; "C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswTap; C:\Windows\system32\DRIVERS\aswTap.sys [44640 2014-04-22] (The OpenVPN Project)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-05] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6957744 2015-05-10] (Broadcom Corporation)
S3 blackberryncm; C:\Windows\system32\DRIVERS\blackberryncm6_AMD64.sys [25088 2014-09-08] (BlackBerry)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-05-20] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2014-05-06] (BlackBerry Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [18432 2015-03-19] (BlackBerry Limited)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-03-10] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-15] (Synaptics Incorporated)
S3 tap-tb-0901; C:\Windows\system32\DRIVERS\tap-tb-0901.sys [38656 2014-08-12] (The OpenVPN Project)
S3 tap0901_openvpn_accl; C:\Windows\system32\DRIVERS\tap0901_openvpn_accl.sys [37912 2015-01-13] (The OpenVPN Project)
S3 tapSF0901; C:\Windows\system32\DRIVERS\tapSF0901.sys [39104 2015-01-23] (Spotflux, Inc.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 TEACCESS; \??\c:\SWTOOLS\FLASH\H9ET90WW\Access64.sys [X]
S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 17:35 - 2015-05-20 17:36 - 00021528 _____ () C:\Users\VDG\Downloads\FRST.txt
2015-05-20 17:35 - 2015-05-20 17:35 - 02107904 _____ (Farbar) C:\Users\VDG\Downloads\FRST64.exe
2015-05-20 17:35 - 2015-05-20 17:35 - 00000000 ____D () C:\FRST
2015-05-20 17:18 - 2014-10-21 11:11 - 00013062 _____ () C:\Users\VDG\Desktop\Voice000.amr
2015-05-20 17:10 - 2015-05-20 17:20 - 00000000 ____D () C:\Users\VDG\Downloads\Anti-CryptorBitV2
2015-05-20 17:08 - 2015-05-20 17:10 - 10868379 _____ () C:\Users\VDG\Downloads\Anti-CryptorBitV2.zip
2015-05-20 16:49 - 2015-05-20 17:07 - 207206296 _____ () C:\Users\VDG\Downloads\avira_antivirus_en-us.exe
2015-05-20 10:28 - 2015-05-20 10:28 - 00000000 _____ () C:\Recovery.txt
2015-05-20 09:34 - 2015-05-20 09:34 - 41095398 _____ () C:\Users\VDG\Desktop\SPWDR Scan 20-May-2015_09 34 11 AM.IMG
2015-05-20 04:38 - 2015-05-20 04:38 - 00001219 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-05-20 04:37 - 2015-05-20 04:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-05-20 04:37 - 2015-05-20 04:37 - 00000000 ____D () C:\ProgramData\Avira
2015-05-20 04:37 - 2015-05-20 04:37 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-05-20 04:34 - 2015-05-20 04:35 - 04737144 _____ (Avira Operations GmbH & Co. KG) C:\Users\VDG\Downloads\avira_en_av_555bbfd0d8130__ws.exe
2015-05-20 03:47 - 2015-05-20 03:47 - 00010123 _____ () C:\Users\VDG\Downloads\cybertools-malware_tools-21f34181756d.zip
2015-05-20 03:35 - 2015-05-20 03:35 - 00000000 _____ () C:\FileRecovery.log
2015-05-20 03:18 - 2015-05-20 03:18 - 00043664 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
2015-05-20 03:11 - 2015-05-20 03:11 - 00000980 _____ () C:\Windows\system32\.crusader
2015-05-20 03:09 - 2015-05-20 04:19 - 00000000 ____D () C:\ProgramData\ParetoLogic
2015-05-20 03:09 - 2015-05-20 04:19 - 00000000 ____D () C:\Program Files (x86)\ParetoLogic
2015-05-20 03:07 - 2015-05-20 03:08 - 02936752 _____ (ParetoLogic) C:\Users\VDG\Downloads\Pareto_DR_Setup_RW.exe
2015-05-20 02:58 - 2015-05-20 02:58 - 00001865 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2015-05-20 02:58 - 2015-05-20 02:58 - 00000000 ____D () C:\Program Files\HitmanPro
2015-05-20 02:52 - 2015-05-20 02:54 - 11024496 _____ (SurfRight B.V.) C:\Users\VDG\Downloads\HitmanPro_x64.exe
2015-05-20 02:32 - 2015-05-20 02:32 - 00262144 ____N () C:\Windows\Minidump\052015-25718-01.dmp
2015-05-20 02:27 - 2015-05-20 02:27 - 00000034 _____ () C:\Users\VDG\Documents\bit.txt
2015-05-20 01:40 - 2015-05-20 01:41 - 02760672 _____ () C:\Users\VDG\Downloads\pandaunransom.exe
2015-05-20 01:21 - 2015-05-20 01:21 - 00026312 _____ () C:\Users\VDG\Downloads\kaspersky-coinvault-decryptor.exe
2015-05-20 01:10 - 2015-05-20 01:10 - 00000000 _____ () C:\autoexec.bat
2015-05-20 00:55 - 2015-05-20 00:55 - 00006200 ____H () C:\Users\&zduklsjtmjklwkxeguscg;\!grtklsjtmjklwkxehtgnz.tiff
2015-05-20 00:55 - 2015-05-20 00:55 - 00000000 ___HD () C:\Users\VDG\Documents\#dthaklsjtmjklwkxeapjt
2015-05-20 00:55 - 2015-05-20 00:55 - 00000000 ___HD () C:\Users\VDG\AAODFzduklsjtmjklwkxeguscg
2015-05-20 00:55 - 2015-05-20 00:55 - 00000000 ___HD () C:\Users\&zduklsjtmjklwkxeguscg;
2015-05-20 00:53 - 2015-05-20 00:59 - 00003408 _____ () C:\Windows\System32\Tasks\CryptoMonitor_SU
2015-05-20 00:53 - 2015-05-20 00:53 - 00000000 ____D () C:\Users\VDG\AppData\Local\EasySync_Solutions
2015-05-20 00:53 - 2015-05-20 00:53 - 00000000 ____D () C:\ProgramData\Caphyon
2015-05-20 00:51 - 2015-05-20 00:51 - 10091352 _____ (EasySync Solutions) C:\Users\VDG\Downloads\EasySync_CryptoMonitor_Setup.exe
2015-05-20 00:38 - 2015-05-19 05:34 - 00843479 _____ () C:\Users\VDG\Desktop\filelist.locklst
2015-05-20 00:38 - 2015-05-19 05:20 - 00000065 _____ () C:\Users\VDG\Desktop\sfile
2015-05-20 00:36 - 2015-05-19 22:31 - 00775596 _____ () C:\Users\VDG\Desktop\BitCryptorFileList.txt
2015-05-20 00:16 - 2015-05-20 00:16 - 00137737 _____ () C:\Users\VDG\Downloads\ShadowExplorer-0.9-portable (1).zip
2015-05-20 00:12 - 2015-05-20 17:21 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-20 00:12 - 2015-05-20 00:12 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-20 00:12 - 2015-05-20 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-20 00:11 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-20 00:11 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-20 00:11 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-20 00:08 - 2015-05-20 00:10 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\VDG\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-20 00:07 - 2015-05-20 00:07 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\VDG\Downloads\SpyHunter-Installer.exe
2015-05-20 00:01 - 2015-05-20 09:34 - 00000000 ____D () C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery
2015-05-20 00:01 - 2015-05-20 03:18 - 00000248 _____ () C:\Windows\error.log
2015-05-20 00:01 - 2015-05-20 03:17 - 00000112 _____ () C:\Windows\errord.log
2015-05-20 00:01 - 2015-05-20 00:02 - 00000081 _____ () C:\Windows\spwdrt.INI
2015-05-20 00:01 - 2015-05-20 00:01 - 00001210 _____ () C:\Users\VDG\Desktop\Stellar Phoenix Windows Data Recovery - Technical.lnk
2015-05-20 00:01 - 2015-05-20 00:01 - 00000077 _____ () C:\Windows\Crypkey.ini
2015-05-20 00:01 - 2015-05-20 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Phoenix Windows Data Recovery - Technical
2015-05-20 00:01 - 2012-12-06 11:27 - 06131200 _____ (Advanced Messaging Systems LLC) C:\Windows\SysWOW64\PhoenixDll.dll
2015-05-20 00:01 - 2012-12-04 21:29 - 00791680 _____ (Advanced Messaging Systems LLC) C:\Windows\SysWOW64\StellarProfile.dll
2015-05-20 00:01 - 2008-05-08 04:59 - 00122880 _____ (CrypKey (Canada) Ltd.) C:\Windows\system32\Crypserv.exe
2015-05-20 00:01 - 2008-03-17 22:42 - 00028664 _____ () C:\Windows\system32\Ckldrv.sys
2015-05-20 00:01 - 1999-06-19 02:19 - 00165888 _____ (Kenonic Controls) C:\Windows\Ckconfig.exe
2015-05-20 00:01 - 1996-05-03 21:51 - 00027648 ____R () C:\Windows\Setup_ck.exe
2015-05-20 00:01 - 1996-05-03 20:06 - 00018432 _____ () C:\Windows\Setup_ck.dll
2015-05-20 00:01 - 1995-07-04 23:03 - 00011776 _____ () C:\Windows\Ckrfresh.exe
2015-05-19 23:58 - 2015-05-20 03:11 - 00000000 ____D () C:\Users\VDG\Downloads\Stellar.Phoenix.Windows.Data.Recovery.v6.0.Technical.Edition-NGEN
2015-05-19 23:57 - 2015-05-19 23:57 - 01994592 _____ (BitTorrent Inc.) C:\Users\VDG\Downloads\uTorrent.exe
2015-05-19 23:44 - 2015-05-19 23:44 - 00000000 ____D () C:\Log
2015-05-19 23:43 - 2015-05-19 23:45 - 12444088 _____ () C:\Users\VDG\Downloads\testdisk-7.0.win.zip
2015-05-19 23:43 - 2015-05-19 23:43 - 03893048 _____ (Stellar Information Systems Ltd ) C:\Users\VDG\Downloads\StellarPhoenixWindowsDataRecovery-Home.exe
2015-05-19 21:34 - 2015-05-20 01:50 - 00016196 _____ () C:\Users\VDG\Downloads\PandaRamsonwareDecrypt.log
2015-05-19 20:51 - 2015-05-19 20:51 - 00137737 _____ () C:\Users\VDG\Downloads\ShadowExplorer-0.9-portable.zip
2015-05-19 15:26 - 2015-05-19 22:28 - 00000000 ____D () C:\Program Files (x86)\FILE RECOVERY for Windows
2015-05-19 15:26 - 2015-05-19 15:26 - 00000000 ____D () C:\Users\VDG\Documents\R-TT
2015-05-19 15:26 - 2015-05-19 15:26 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FILE RECOVERY for Windows
2015-05-19 06:50 - 2015-05-20 03:18 - 00001490 _____ () C:\Windows\setupact.log
2015-05-19 06:50 - 2015-05-19 06:50 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-19 06:44 - 2015-05-20 03:11 - 00000000 ____D () C:\ProgramData\HitmanPro
2015-05-19 06:26 - 2015-05-20 00:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-19 06:26 - 2015-05-19 06:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-19 06:25 - 2015-05-20 02:30 - 00004406 _____ () C:\Windows\PFRO.log
2015-05-19 06:02 - 2015-05-20 17:33 - 00391981 _____ () C:\Windows\WindowsUpdate.log
2015-05-19 05:01 - 2015-05-19 05:01 - 00133763 _____ () C:\Users\VDG\Downloads\CHURCH OF GOD(FULL GOSPEL) (1) (1).pptx
2015-05-19 05:01 - 2015-05-19 05:01 - 00042849 _____ () C:\Users\VDG\Downloads\Rural Litigation and Entitlement Kendra v - Copy.pptx
2015-05-19 04:44 - 2015-05-20 01:45 - 00000000 ____D () C:\Users\VDG\Desktop\New folder
2015-05-19 03:05 - 2015-05-19 03:05 - 00016484 _____ () C:\Users\VDG\Downloads\[kat.cr]dil.bhi.tera.hum.bhi.tere.1960.dvdrip.x264.ac3.esubs.ddr.torrent
2015-05-19 02:57 - 2015-05-19 02:57 - 00012239 _____ () C:\Users\VDG\Downloads\[kat.cr]love.ke.liye.kuch.bhi.karega.2001.hindi.720p.dvdrip.ac3.5.1.hon3y.torrent
2015-05-19 02:40 - 2015-05-19 02:40 - 00020947 _____ () C:\Users\VDG\Downloads\[kat.cr]waisa.bhi.hota.hai.part.ii.2003.hdrip.720p.x264.manudil.silverrg.torrent
2015-05-17 03:56 - 2015-05-19 22:28 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TorrenTV
2015-05-17 03:56 - 2015-05-17 03:56 - 00002158 _____ () C:\Users\VDG\Desktop\TorrenTV.lnk
2015-05-17 03:55 - 2015-05-19 22:28 - 00000000 ____D () C:\Users\VDG\AppData\Local\TorrenTV
2015-05-16 18:30 - 2015-05-01 02:05 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-16 18:30 - 2015-05-01 02:05 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-16 18:13 - 2015-04-21 22:44 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-16 18:13 - 2015-04-21 22:20 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-16 18:13 - 2015-04-21 22:20 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-16 18:13 - 2015-04-21 22:19 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-16 18:13 - 2015-04-21 22:07 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-16 18:13 - 2015-04-21 22:05 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-16 18:13 - 2015-04-21 22:01 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-16 18:13 - 2015-04-21 21:54 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-16 18:13 - 2015-04-21 21:43 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-16 18:13 - 2015-04-21 21:41 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-16 18:13 - 2015-04-21 21:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-16 18:13 - 2015-04-21 21:38 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-16 18:13 - 2015-04-21 21:37 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-16 18:13 - 2015-04-21 21:35 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-16 18:13 - 2015-04-21 21:34 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-16 18:13 - 2015-04-21 21:29 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-16 18:13 - 2015-04-21 21:28 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-16 18:13 - 2015-04-21 21:22 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-16 18:13 - 2015-04-21 21:19 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-16 18:13 - 2015-04-21 21:19 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-16 18:13 - 2015-04-21 21:19 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-16 18:13 - 2015-04-21 21:16 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-16 18:13 - 2015-04-21 21:10 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-16 18:13 - 2015-04-21 21:08 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-16 18:13 - 2015-04-21 21:07 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-16 18:13 - 2015-04-21 21:06 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-16 18:13 - 2015-04-21 21:02 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-16 18:13 - 2015-04-21 21:01 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-16 18:13 - 2015-04-21 20:58 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-16 18:13 - 2015-04-21 20:57 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-16 18:13 - 2015-04-21 20:56 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-16 18:13 - 2015-04-21 20:56 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-16 18:13 - 2015-04-21 20:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-16 18:13 - 2015-04-21 20:47 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-16 18:13 - 2015-04-21 20:45 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-16 18:13 - 2015-04-21 20:33 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-16 18:13 - 2015-04-21 20:32 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-16 18:13 - 2015-04-21 20:28 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-16 18:13 - 2015-04-21 20:26 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-16 18:08 - 2015-05-01 04:35 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-16 18:08 - 2015-05-01 04:18 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-16 18:08 - 2015-04-14 04:18 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-16 18:08 - 2015-04-10 06:30 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-16 18:08 - 2015-04-10 06:20 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-16 18:08 - 2015-04-10 05:56 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-16 18:08 - 2015-04-09 04:25 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-16 18:06 - 2015-03-30 11:17 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-16 18:06 - 2015-03-27 08:57 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-16 18:06 - 2015-03-27 08:20 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-16 18:06 - 2015-03-27 08:18 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-16 17:36 - 2015-05-20 17:10 - 00000000 ____D () C:\Users\VDG\Desktop\New folder (2)
2015-05-16 17:30 - 2015-05-16 17:30 - 00001213 _____ () C:\Users\VDG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grand Theft Auto IV - Episodes From Liberty City.lnk
2015-05-15 04:30 - 2015-05-15 04:30 - 00001390 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-05-15 04:30 - 2015-05-15 04:30 - 00001321 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-05-15 04:30 - 2015-05-15 04:30 - 00000000 ____D () C:\Windows\en
2015-05-15 04:29 - 2015-05-15 04:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-05-15 04:28 - 2015-05-15 04:28 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-05-15 03:35 - 2015-05-15 03:35 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\MP3 Cutter Joiner Free
2015-05-15 03:35 - 2002-01-05 16:37 - 00344064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2015-05-15 03:34 - 2015-05-15 03:34 - 07106048 _____ (TechTouch Soft Co., Ltd. ) C:\Users\VDG\Downloads\MP3CutterJoinerFree [1].exe
2015-05-12 23:16 - 2015-05-12 23:16 - 00013172 _____ () C:\Users\VDG\Downloads\9493CB6A697B1D97178ACFB968CAE10B9AF1C556.torrent
2015-05-12 07:27 - 2015-05-12 07:27 - 00102376 _____ (Lenovo.) C:\Windows\system32\ibmpmsvc.exe
2015-05-12 07:27 - 2015-05-12 07:27 - 00074728 _____ (Lenovo.) C:\Windows\system32\ibmpmctl.exe
2015-05-12 07:27 - 2015-05-12 07:27 - 00063464 _____ (Lenovo.) C:\Windows\system32\Drivers\ibmpmdrv.sys
2015-05-12 07:27 - 2015-05-12 07:27 - 00042472 _____ (Lenovo.) C:\Windows\system32\tpinspm.dll
2015-05-12 02:57 - 2015-04-25 03:02 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-12 02:57 - 2015-04-10 06:04 - 02256896 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-12 02:57 - 2015-04-10 05:41 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-11 01:45 - 2015-05-11 01:47 - 00000000 ____D () C:\Users\VDG\Documents\Total Overdose
2015-05-10 21:45 - 2015-05-10 21:45 - 00000000 ____D () C:\Users\VDG\Documents\Bluetooth Exchange Folder
2015-05-10 21:45 - 2015-05-10 21:45 - 00000000 ____D () C:\Users\VDG\AppData\Local\Broadcom
2015-05-10 19:05 - 2015-05-10 19:05 - 06957744 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL63a.SYS
2015-05-10 19:05 - 2015-05-10 19:05 - 04395008 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2015-05-10 19:05 - 2015-05-10 19:05 - 03659264 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2015-05-10 19:05 - 2015-05-10 19:05 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\InstallShield
2015-05-10 19:05 - 2015-05-10 19:05 - 00000000 ____D () C:\Program Files\Broadcom
2015-05-10 19:05 - 2015-05-10 19:05 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-05-10 17:39 - 2015-05-10 17:39 - 00052736 _____ () C:\Users\VDG\Downloads\4-10 may.xls
2015-05-10 16:27 - 2015-05-10 16:27 - 00000000 ____D () C:\Users\VDG\Documents\Road Redemption
2015-05-09 22:58 - 2015-05-17 03:01 - 00001164 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZenVPN.lnk
2015-05-09 14:14 - 2015-05-09 14:14 - 00000000 ____D () C:\Users\VDG\AppData\Local\Lenovo
2015-05-09 01:29 - 2015-05-09 01:29 - 00000000 ____D () C:\Users\VDG\AppData\Local\Tvsukernel
2015-05-09 01:01 - 2013-07-12 05:11 - 00228568 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-05-09 01:01 - 2013-07-12 05:11 - 00186584 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-05-09 01:01 - 2013-07-12 05:11 - 00038616 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2015-05-09 01:01 - 2012-07-27 07:48 - 00040248 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-05-09 00:59 - 2015-05-09 00:59 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-05-09 00:58 - 2013-04-10 11:09 - 00801864 _____ (Realtek ) C:\Windows\system32\Drivers\Rt630x64.sys
2015-05-09 00:58 - 2013-04-10 11:09 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2015-05-08 21:07 - 2015-05-08 21:07 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ldiagio_uefi_01009.Wdf
2015-05-08 21:06 - 2015-05-09 01:40 - 00000000 ____D () C:\Program Files\Lenovo
2015-05-08 21:06 - 2015-05-08 21:06 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\LSC
2015-05-08 21:06 - 2015-05-08 21:06 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-05-08 21:06 - 2015-05-08 21:06 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-05-08 20:25 - 2015-05-09 10:30 - 00000000 ____D () C:\Windows\System32\Tasks\TVT
2015-05-08 20:24 - 2015-05-09 10:30 - 00000000 ____D () C:\ProgramData\Lenovo
2015-05-08 20:24 - 2015-05-09 10:30 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2015-05-08 20:24 - 2015-05-09 01:31 - 00000000 ____D () C:\Windows\System32\Tasks\Lenovo
2015-05-08 20:24 - 2015-05-08 21:06 - 00000000 ____D () C:\Windows\Downloaded Installations
2015-05-08 13:04 - 2015-05-08 13:04 - 00015009 _____ () C:\Users\VDG\Downloads\Internal Assessment 28042015.xlsx
2015-05-08 11:19 - 2015-05-08 11:21 - 03104210 _____ () C:\Users\VDG\Downloads\Debates on Minorities.pptx
2015-05-07 15:54 - 2015-04-17 18:54 - 160815464 _____ (BlackBerry) C:\Users\VDG\Downloads\BlackBerryDesktopSoftware_1_1_B39.exe
2015-05-07 02:01 - 2015-05-07 02:01 - 00029051 _____ () C:\Users\VDG\Downloads\[kickass.to]om.dar.ba.dar.1988.dvdrip.x264.ac3.2.0.engsubs.torrent
2015-05-07 00:50 - 2015-05-07 00:50 - 00011604 _____ () C:\Users\VDG\Downloads\[kickass.to]road.redemption.v0.826.torrent
2015-05-05 20:02 - 2015-05-05 20:02 - 00019817 _____ () C:\Users\VDG\Downloads\[kickass.to]banshee.season.2.torrent
2015-05-05 19:50 - 2015-05-05 19:50 - 00039936 _____ () C:\Users\VDG\Downloads\[kickass.to]marco.polo.2014.season.1.720p.web.dl.2ch.x265.hevc.psa.emidius.torrent
2015-05-05 11:56 - 2015-03-11 07:19 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-05 11:56 - 2015-03-11 06:39 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-05 11:55 - 2015-04-02 03:52 - 02985984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2015-05-05 11:55 - 2015-04-02 03:50 - 04417536 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2015-05-05 11:55 - 2015-04-01 09:15 - 01491456 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2015-05-05 11:55 - 2015-04-01 08:01 - 01207296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2015-05-05 11:55 - 2015-03-20 07:26 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-05-05 11:55 - 2015-03-13 05:59 - 00410017 _____ () C:\Windows\system32\ApnDatabase.xml
2015-05-04 12:58 - 2015-05-04 12:58 - 00073844 _____ () C:\Users\VDG\Downloads\Precautionary Principle.pptx
2015-05-03 18:46 - 2015-05-03 18:53 - 00000000 __SHD () C:\Users\VDG\wc
2015-05-03 18:46 - 2015-05-03 18:46 - 00000000 __SHD () C:\Users\VDG\AppData\Roaming\ViperUpdate AU
2015-05-03 18:46 - 2015-05-03 18:46 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\ViperSettingsFolder
2015-05-03 18:46 - 2015-05-03 18:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Viper
2015-05-03 18:46 - 2015-05-03 18:46 - 00000000 ____D () C:\Program Files (x86)\All Answers Ltd
2015-05-03 17:39 - 2015-05-03 17:39 - 00000000 ____D () C:\Users\VDG\Downloads\cpu-z_1.72-en
2015-05-03 17:38 - 2015-05-03 17:38 - 02262312 _____ () C:\Users\VDG\Downloads\cpu-z_1.72-en.zip
2015-05-03 03:51 - 2015-05-03 03:57 - 00000000 ____D () C:\ProgramData\Razer
2015-05-01 21:19 - 2015-05-01 21:19 - 00292184 _____ (Microsoft Corporation) C:\Users\VDG\Downloads\dxwebsetup.exe
2015-04-30 23:27 - 2015-05-19 05:50 - 00000000 ____D () C:\Program Files (x86)\hide.me VPN
2015-04-30 16:03 - 2015-03-30 15:32 - 00187844 _____ () C:\Windows\system32\resTHA.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00180644 _____ () C:\Windows\system32\resELL.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00176500 _____ () C:\Windows\system32\resRUS.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00162356 _____ () C:\Windows\system32\resARA.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00161812 _____ () C:\Windows\system32\resHEB.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00161764 _____ () C:\Windows\system32\resJPN.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00157172 _____ () C:\Windows\system32\resFRA.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00157156 _____ () C:\Windows\system32\resHUN.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00155460 _____ () C:\Windows\system32\resKOR.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00155364 _____ () C:\Windows\system32\resITA.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00155364 _____ () C:\Windows\system32\resDEU.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00155204 _____ () C:\Windows\system32\resROM.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00155092 _____ () C:\Windows\system32\resESN.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00154660 _____ () C:\Windows\system32\resPLK.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00154516 _____ () C:\Windows\system32\resSKY.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00154324 _____ () C:\Windows\system32\resNLD.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00153764 _____ () C:\Windows\system32\resPTB.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00153620 _____ () C:\Windows\system32\resTRK.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00153604 _____ () C:\Windows\system32\resCSY.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00153460 _____ () C:\Windows\system32\resPTG.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00153060 _____ () C:\Windows\system32\resFIN.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00152612 _____ () C:\Windows\system32\resHRV.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00152164 _____ () C:\Windows\system32\resSVE.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00152004 _____ () C:\Windows\system32\resSLV.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00151060 _____ () C:\Windows\system32\resNOR.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00150548 _____ () C:\Windows\system32\resDAN.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00149236 _____ () C:\Windows\system32\resENU.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00147460 _____ () C:\Windows\system32\resCHT.cui
2015-04-30 16:03 - 2015-03-30 15:32 - 00146628 _____ () C:\Windows\system32\resCHS.cui
2015-04-30 16:03 - 2015-03-30 15:31 - 22905344 _____ (Intel Corporation) C:\Windows\system32\igdfcl64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 17837568 _____ (Intel Corporation) C:\Windows\SysWOW64\igdfcl32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 08520192 _____ (Intel Corporation) C:\Windows\system32\ig7icd64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 06503424 _____ (Intel Corporation) C:\Windows\SysWOW64\ig7icd32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 04360392 _____ (Intel Corporation) C:\Windows\system32\Gfxv4_0.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 04356808 _____ (Intel Corporation) C:\Windows\system32\Gfxv2_0.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 03787704 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
2015-04-30 16:03 - 2015-03-30 15:31 - 02479472 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiVAD64.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 01984000 _____ (Intel Corporation) C:\Windows\system32\igdrcl64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 01783808 _____ (Intel Corporation) C:\Windows\SysWOW64\igdrcl32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 01137120 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 01133000 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00958152 _____ (Intel Corporation) C:\Windows\system32\GfxUIEx.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00545216 _____ (Intel Corporation) C:\Windows\system32\DPTopologyApp.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00543944 _____ (Intel Corporation) C:\Windows\system32\DPTopologyAppv2_0.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00529096 _____ (Intel Corporation) C:\Windows\system32\igfxEM.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00454760 _____ (Intel Corporation) C:\Windows\system32\igdmd64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00433088 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiUMS64.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00399296 _____ (Intel Corporation) C:\Windows\system32\CustomModeApp.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00398784 _____ (Intel Corporation) C:\Windows\system32\CustomModeAppv2_0.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00383424 _____ (Intel Corporation) C:\Windows\system32\igfxTray.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00376832 _____ (Intel Corporation) C:\Windows\system32\IntelOpenCL64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00366680 _____ (Intel Corporation) C:\Windows\SysWOW64\igdmd32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00365568 _____ (Intel Corporation) C:\Windows\system32\igdbcl64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00320512 _____ (Intel Corporation) C:\Windows\SysWOW64\igdbcl32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00317640 _____ (Intel Corporation) C:\Windows\system32\igfxCUIService.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00286720 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelOpenCL32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00279240 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00255488 _____ () C:\Windows\system32\igfxCPL.cpl
2015-04-30 16:03 - 2015-03-30 15:31 - 00245960 _____ (Intel Corporation) C:\Windows\system32\igfxHK.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00223232 _____ () C:\Windows\system32\igdde64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00218848 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00193984 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00188496 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00184832 _____ () C:\Windows\SysWOW64\igdde32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00183840 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00183296 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4176.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00162304 _____ () C:\Windows\system32\igdail64.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00159096 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00154048 _____ (Intel Corporation) C:\Windows\system32\difx64.exe
2015-04-30 16:03 - 2015-03-30 15:31 - 00143872 _____ () C:\Windows\SysWOW64\igdail32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00086528 _____ () C:\Windows\system32\igfxCUIServicePS.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00069632 _____ ( ) C:\Windows\system32\igfxDHLibv2_0.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00059392 _____ ( ) C:\Windows\system32\igfxDHLib.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00031448 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00030720 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00010752 _____ ( ) C:\Windows\system32\igfxDILib.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00010240 _____ ( ) C:\Windows\system32\igfxEMLibv2_0.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00010240 _____ ( ) C:\Windows\system32\igfxEMLib.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00010240 _____ ( ) C:\Windows\system32\igfxDILibv2_0.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00005120 _____ ( ) C:\Windows\system32\igfxLHMLibv2_0.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00005120 _____ ( ) C:\Windows\system32\igfxLHMLib.dll
2015-04-30 16:03 - 2015-03-30 15:31 - 00002564 _____ () C:\Windows\system32\iglhxs64.vp
2015-04-30 15:06 - 2015-05-19 22:28 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
2015-04-30 14:48 - 2015-04-19 19:34 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-04-30 03:53 - 2015-04-30 03:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2015-04-30 00:01 - 2015-04-30 00:01 - 00023200 _____ (Western Digital Technologies) C:\Windows\system32\Drivers\wdcsam64.sys
2015-04-28 11:33 - 2015-05-19 05:21 - 00000346 _____ () C:\Users\VDG\Desktop\TORRENT.txt
2015-04-27 19:58 - 2015-04-27 19:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cygwin
2015-04-26 11:07 - 2015-04-26 11:07 - 00000921 _____ () C:\Windows\QSFVExit.bat
2015-04-25 22:59 - 2015-04-25 22:59 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-25 22:59 - 2015-04-25 22:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-25 22:59 - 2015-04-25 22:59 - 00000000 ____D () C:\Program Files\WinRAR
2015-04-25 19:59 - 2015-04-25 19:59 - 00018603 _____ () C:\Users\VDG\Downloads\[kickass.to]bas.ek.pal.original.motion.picture.soundtrack.2006.320.kbps.torrent
2015-04-25 04:18 - 2014-04-22 17:10 - 00044640 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\aswTap.sys
2015-04-25 01:55 - 2015-05-07 15:47 - 00003250 _____ () C:\Windows\System32\Tasks\Defendemus - VPN Shield
2015-04-25 01:49 - 2010-05-11 13:17 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll
2015-04-24 16:09 - 2015-01-06 08:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2015-04-24 16:09 - 2015-01-06 08:29 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2015-04-24 16:09 - 2015-01-06 06:42 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2015-04-24 16:09 - 2015-01-06 06:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2015-04-24 16:05 - 2015-04-03 06:05 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll
2015-04-24 16:05 - 2015-04-03 05:44 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoMetadataHandler.dll
2015-04-24 16:05 - 2015-03-17 22:56 - 00467776 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-04-24 16:05 - 2015-03-13 07:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2015-04-24 16:05 - 2015-03-13 06:41 - 02162176 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2015-04-24 16:05 - 2015-03-13 06:09 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2015-04-24 16:05 - 2015-03-09 07:32 - 00057856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-04-24 16:05 - 2015-03-04 07:02 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2015-04-24 16:05 - 2015-03-04 06:42 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-04-24 16:05 - 2015-01-30 06:23 - 02819584 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-04-24 16:04 - 2015-03-24 03:29 - 07476032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-24 16:04 - 2015-03-24 03:29 - 01733952 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-24 16:04 - 2015-03-24 03:29 - 00360480 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-04-24 16:04 - 2015-03-24 03:28 - 01498872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-04-24 16:04 - 2015-03-24 03:15 - 00257216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-04-24 16:04 - 2015-03-20 09:42 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
2015-04-24 16:04 - 2015-03-20 09:40 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-04-24 16:04 - 2015-03-20 09:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-04-24 16:04 - 2015-03-20 08:47 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-04-24 16:04 - 2015-03-20 08:11 - 00369152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-04-24 16:04 - 2015-03-20 08:10 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-04-24 16:04 - 2015-03-20 07:46 - 00749568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-04-24 16:04 - 2015-03-14 14:24 - 00133256 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-24 16:04 - 2015-03-14 07:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-24 16:04 - 2015-03-14 07:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-24 16:04 - 2015-03-14 07:21 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-24 16:04 - 2015-03-14 07:07 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-24 16:04 - 2015-03-14 06:44 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-24 16:04 - 2015-03-14 05:52 - 03678720 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-24 16:04 - 2015-03-14 05:42 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-24 16:04 - 2015-03-14 05:42 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-24 16:04 - 2015-03-14 05:39 - 00200192 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2015-04-24 16:04 - 2015-03-14 05:38 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-04-24 16:04 - 2015-03-14 05:38 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-24 16:04 - 2015-03-14 05:36 - 02373632 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-24 16:04 - 2015-03-14 05:36 - 00891392 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-24 16:04 - 2015-03-14 05:32 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-24 16:04 - 2015-03-14 05:32 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-24 16:04 - 2015-03-14 05:29 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-24 16:04 - 2015-03-14 05:29 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-24 16:04 - 2015-03-13 09:33 - 00239424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2015-04-24 16:04 - 2015-03-13 09:33 - 00154432 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2015-04-24 16:04 - 2015-03-13 08:28 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2015-04-24 16:04 - 2015-03-13 08:07 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2015-04-24 16:04 - 2015-03-06 08:17 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-04-24 16:04 - 2015-02-24 14:02 - 00991552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-24 16:04 - 2015-02-18 04:49 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2015-04-24 16:03 - 2015-03-06 08:38 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-04-24 16:03 - 2015-03-06 08:13 - 01969664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-04-24 16:03 - 2015-03-05 04:39 - 01429504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-04-24 16:03 - 2015-03-04 15:55 - 00377152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2015-04-24 16:03 - 2015-03-04 08:34 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-24 16:03 - 2015-03-04 07:49 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-24 15:38 - 2015-04-24 15:38 - 00016936 _____ () C:\Users\VDG\Downloads\Tagore (2003) Telugu Movie 720p DVD9 Rip With AC3 Audio torrent.torrent
2015-04-20 14:01 - 2015-04-20 14:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicISO
2015-04-20 13:48 - 2015-03-16 17:36 - 00922704 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-04-20 13:47 - 2015-03-16 17:35 - 00128592 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-04-20 06:05 - 2015-01-23 22:58 - 00052992 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\netfilter2.sys
2015-04-20 05:23 - 2015-04-20 05:23 - 00000000 ____D () C:\Users\VDG\AppData\Local\Mozilla
2015-04-20 05:23 - 2015-04-20 05:23 - 00000000 ____D () C:\ProgramData\Mozilla
2015-04-20 05:17 - 2015-04-20 05:23 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\Mozilla
2015-04-20 05:16 - 2015-04-20 05:16 - 00000000 _____ () C:\Windows\nsreg.dat
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 17:30 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\system32\sru
2015-05-20 17:27 - 2014-03-18 15:32 - 01004854 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 17:15 - 2014-10-21 14:24 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-504121640-2405822300-1051111340-1001
2015-05-20 16:22 - 2014-10-21 14:23 - 00003910 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5CBCC226-600B-433F-AF0F-8C386BD05F63}
2015-05-20 06:23 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\rescache
2015-05-20 04:37 - 2014-11-21 11:51 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-20 03:24 - 2015-04-19 19:36 - 00000000 ____D () C:\Users\VDG\Documents\Rockstar Games
2015-05-20 03:18 - 2013-08-22 20:15 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-20 02:32 - 2015-03-02 04:20 - 00000000 ____D () C:\Windows\Minidump
2015-05-20 01:46 - 2014-12-23 23:04 - 00824832 ___SH () C:\Users\VDG\Desktop\Thumbs.db
2015-05-20 01:28 - 2014-10-21 14:26 - 00000000 ____D () C:\Users\VDG\AppData\Local\Microsoft Help
2015-05-20 00:55 - 2014-10-21 14:19 - 00000000 ____D () C:\Users\VDG
2015-05-20 00:32 - 2014-12-03 21:59 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\uTorrent
2015-05-19 22:29 - 2014-11-13 02:32 - 00000000 ____D () C:\Users\.NET v4.5 Classic
2015-05-19 22:29 - 2014-11-13 02:32 - 00000000 ____D () C:\Users\.NET v2.0 Classic
2015-05-19 22:29 - 2013-08-22 20:14 - 00409600 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-19 22:28 - 2015-04-08 13:23 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-19 22:28 - 2014-12-22 05:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-05-19 22:28 - 2014-12-22 05:25 - 00000000 ____D () C:\Program Files (x86)\Java
2015-05-19 22:28 - 2014-11-16 21:54 - 00000000 ____D () C:\Users\DefaultAppPool
2015-05-19 22:28 - 2014-11-13 02:32 - 00000000 ____D () C:\Users\Classic .NET AppPool
2015-05-19 22:28 - 2014-11-13 02:32 - 00000000 ____D () C:\Users\.NET v4.5
2015-05-19 22:28 - 2014-11-13 02:32 - 00000000 ____D () C:\Users\.NET v2.0
2015-05-19 22:25 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\registration
2015-05-19 22:24 - 2014-12-22 05:25 - 00000000 ____D () C:\ProgramData\Oracle
2015-05-19 05:45 - 2014-10-22 03:00 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\DMCache
2015-05-19 05:41 - 2014-12-19 09:17 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-05-19 05:21 - 2014-12-19 23:45 - 00000069 _____ () C:\Users\VDG\Desktop\subjects.txt
2015-05-18 00:32 - 2013-08-22 18:55 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-18 00:30 - 2015-04-08 13:23 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-05-17 04:18 - 2015-02-12 21:10 - 00508928 ___SH () C:\Users\VDG\Downloads\Thumbs.db
2015-05-16 18:34 - 2013-08-22 20:50 - 00000000 ____D () C:\Windows\CbsTemp
2015-05-16 18:30 - 2014-10-21 15:40 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-16 18:20 - 2014-10-21 15:40 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-16 18:14 - 2014-03-18 15:13 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-16 17:59 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-15 04:27 - 2015-02-25 11:00 - 00000000 ____D () C:\Users\VDG\AppData\Local\Windows Live
2015-05-13 15:13 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-10 18:32 - 2014-10-21 23:56 - 00002990 _____ () C:\Windows\System32\Tasks\Synaptics TouchPad Enhancements
2015-05-09 10:27 - 2014-10-22 00:12 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-09 10:27 - 2014-10-22 00:12 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-09 01:02 - 2014-10-22 05:12 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-09 00:58 - 2014-10-22 05:12 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-05-08 21:06 - 2014-11-13 11:42 - 00000000 ____D () C:\Users\VDG\AppData\Local\Adobe
2015-05-08 21:06 - 2014-11-13 11:39 - 00000000 ____D () C:\ProgramData\Adobe
2015-05-08 21:06 - 2014-11-13 11:39 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-05-08 21:06 - 2014-10-21 14:19 - 00000000 ____D () C:\Users\VDG\AppData\Roaming\Adobe
2015-05-07 15:47 - 2015-04-19 16:10 - 00002702 _____ () C:\Windows\System32\Tasks\arp_flush
2015-05-07 15:47 - 2015-02-25 15:00 - 00003376 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-504121640-2405822300-1051111340-1001
2015-05-07 15:47 - 2015-02-25 11:50 - 00003356 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-504121640-2405822300-1051111340-1001
2015-05-07 15:47 - 2015-02-25 11:50 - 00003302 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-504121640-2405822300-1051111340-1001
2015-05-07 15:46 - 2014-10-22 00:12 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-07 15:46 - 2014-10-22 00:12 - 00003658 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-07 15:31 - 2015-04-17 19:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry Link
2015-05-05 23:29 - 2014-10-21 16:08 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-05 23:29 - 2014-10-21 16:08 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-05-03 00:40 - 2014-10-29 02:21 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-05-02 18:06 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-05-02 18:04 - 2014-03-18 15:00 - 00000000 ____D () C:\Windows\system32\0409
2015-05-02 18:04 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\SysWOW64\inetsrv
2015-05-01 21:20 - 2014-12-10 18:49 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-04-30 16:10 - 2014-11-21 15:53 - 00016304 _____ () C:\Windows\system32\results.xml
2015-04-30 16:09 - 2014-10-21 16:09 - 00000451 _____ () C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2015-04-30 16:05 - 2014-11-21 15:51 - 00000724 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2015-04-30 15:38 - 2015-03-31 14:34 - 00000000 ____D () C:\Users\VDG\AppData\Local\Rockstar Games
2015-04-30 02:01 - 2014-12-22 05:25 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-04-26 02:10 - 2014-10-21 14:19 - 00000000 ____D () C:\Users\VDG\AppData\Local\VirtualStore
2015-04-26 01:27 - 2013-08-22 21:06 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2015-04-26 01:27 - 2013-08-22 19:06 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-04-25 06:10 - 2013-08-22 21:06 - 00000000 ____D () C:\Windows\tracing
2015-04-24 16:04 - 2014-11-02 23:45 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-04-20 13:39 - 2014-12-14 03:43 - 00000000 ____D () C:\Program Files\BitTorrent Sync
==================== Files in the root of some directories =======
2014-11-30 04:53 - 2014-11-30 04:53 - 0000778 _____ () C:\Users\VDG\AppData\Local\recently-used.xbel
2015-02-02 22:22 - 2015-02-02 22:22 - 0000017 _____ () C:\Users\VDG\AppData\Local\resmon.resmoncfg
2014-10-22 05:13 - 2014-10-22 05:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\VDG\AppData\Local\Temp\EsgInstallerx64Stub.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-17 19:21
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-05-2015
Ran by [removed] at 2015-05-20 17:37:45
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-504121640-2405822300-1051111340-500 - Administrator - Disabled)
Guest (S-1-5-21-504121640-2405822300-1051111340-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-504121640-2405822300-1051111340-1003 - Limited - Enabled)
VDG (S-1-5-21-504121640-2405822300-1051111340-1001 - Administrator - Enabled) => C:\Users\VDG
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat XI Pro (HKLM-x32\…\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.10 - Adobe Systems)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\…\AmUStor) (Version: 3.17.3042.73586 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.17.3042.73586 - Alcor Micro Corp.) Hidden
Assassin's Creed Unity (HKLM-x32\…\Assassin's Creed Unity_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Avira (HKLM-x32\…\{022ef99f-0db2-4efc-964d-5dd2da3151f6}) (Version: 1.1.37.30000 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.37.30000 - Avira Operations GmbH & Co. KG) Hidden
BlackBerry Blend (x32 Version: 1.1.0.23 - BlackBerry Ltd.) Hidden
BlackBerry Communication Drivers (x32 Version: 8.0.0.119 - BlackBerry Ltd.) Hidden
BlackBerry Device Drivers (x32 Version: 8.0.0.119 - BlackBerry Ltd.) Hidden
BlackBerry Link (x32 Version: 1.2.4.28 - BlackBerry) Hidden
BlackBerry Link Remover (x32 Version: 1.2.4.0 - BlackBerry Ltd.) Hidden
Broadcom 802.11 Network Adapter (HKLM\…\Broadcom 802.11 Network Adapter) (Version: 6.30.59.151 - Broadcom Corporation)
CCleaner (HKLM\…\CCleaner) (Version: 4.16 - Piriform)
Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Hidden
Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Hidden
Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Ginger (HKLM-x32\…\InstallShield_{1EBF9A59-F4E3-4EA7-BA97-76703C1432F6}) (Version: 3.5.223 - Ginger Software)
Ginger (x32 Version: 3.5.223 - Ginger Software) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Grand Theft Auto IV - Episodes From Liberty City (HKLM-x32\…\{8ED35B48-AFBD-4F32-8271-2257AD8B907E}_is1) (Version: - )
Grand Theft Auto V version 1.0.0 (HKLM-x32\…\Grand Theft Auto V_is1) (Version: 1.0.0 - Rockstar Games)
Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0003.135 - Rockstar Games Inc.) Hidden
HitmanPro 3.7 (HKLM\…\HitmanPro37) (Version: 3.7.9.241 - SurfRight B.V.)
Intel(R) Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4176 - Intel Corporation)
Intel® Driver Update Utility (HKLM-x32\…\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel)
Java 8 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
K-Lite Codec Pack 11.0.5 Full (HKLM-x32\…\KLiteCodecPack_is1) (Version: 11.0.5 - )
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\…\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.7850 - Broadcom Corporation)
Lenovo Power Management Driver (HKLM\…\Power Management Driver) (Version: 1.67.10.07 - )
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Metric Collection SDK (x32 Version: 1.1.0005.00 - Lenovo Group Limited) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\…\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mobile Partner (HKLM-x32\…\Mobile Partner) (Version: 23.001.07.06.910 - Huawei Technologies Co.,Ltd)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
Nokia Connectivity Cable Driver (HKLM-x32\…\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
Nokia Music Player (HKLM-x32\…\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player)
Nokia Suite (HKLM-x32\…\Nokia Suite) (Version: 3.8.48.0 - Nokia)
Nokia Suite (x32 Version: 3.8.48.0 - Nokia) Hidden
Nokia_Multimedia_Common_Components_2_5 (HKLM-x32\…\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia)
PC Connectivity Solution (HKLM-x32\…\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
Razer Cortex (HKLM-x32\…\Razer Cortex_is1) (Version: 5.4.15.0 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.15.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7040 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\…\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\…\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
SpyHunter 4 (HKLM-x32\…\SpyHunter) (Version: 4.19.13.4482 - Enigma Software Group, LLC)
Stellar Phoenix Windows Data Recovery - Technical (HKLM-x32\…\Stellar Phoenix Windows Data Recovery - Technical_is1) (Version: 6.0.0.0 - Stellar Information Systems Ltd)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.9.1 - Synaptics Incorporated)
Viper Plagiarism Scanner (HKLM-x32\…\{2D9F8754-84AB-4C46-8243-9EADF23A63EE}_is1) (Version: 4.1.90.1039 - All Answers Ltd)
Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\…\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.21 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-504121640-2405822300-1051111340-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
20-05-2015 06:21:48 Scheduled Checkpoint
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 18:55 - 2013-08-22 18:55 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {01AAC62E-C973-4669-A7BD-B63C6FC6F126} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-22] (Google Inc.)
Task: {06DD4419-1229-4F1C-B583-BB1FF473A800} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {2C036840-C959-4A41-806C-9B414B88D814} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-15] (Synaptics Incorporated)
Task: {2FDD166F-69C8-4378-99F6-1CED4833ECEC} - System32\Tasks\{926C99B2-BA67-4A10-AD65-B7C2F3FC2371} => pcalua.exe -a "C:\Program Files (x86)\Real\RealPlayer\Update\r1puninst.exe" -d "C:\Program Files (x86)\Real\RealPlayer\Update"
Task: {3832A34E-E6BB-4D57-924B-54205DD971C5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-07-23] (Piriform Ltd)
Task: {3FD7118F-C4E2-4708-A795-AB3D4C5E7A17} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-504121640-2405822300-1051111340-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {4DE12585-0D00-4D8A-99D8-41969A52A405} - System32\Tasks\CryptoMonitor_SU => C:\Program Files\EasySync Solutions\EasySync CryptoMonitor\CryptoMonitor.exe
Task: {5A17C187-24BB-4D22-96DC-FE566DF1DF7A} - System32\Tasks\Defendemus - VPN Shield => C:\Program Files (x86)\Defendemus\VPN Shield\VpnShield.exe
Task: {6949433E-86AC-4357-A615-D58A3C4D4670} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-02-13] (Lenovo)
Task: {8B797500-F73B-4E4D-B4DD-9A674F880220} - System32\Tasks\arp_flush => C:\Program Files (x86)\hide.me VPN\FlushArpCache.exe
Task: {94EFE06F-40A0-4748-BA43-643FB2B59162} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-504121640-2405822300-1051111340-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {AA9C90F6-806E-435A-B0AF-A831059AA71E} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation)
Task: {D211BFA1-EE31-4554-9242-AD1DD7536C27} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-05-16] (Microsoft Corporation)
Task: {E02DFAC9-E9C3-44E4-A4C7-494805180A37} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-504121640-2405822300-1051111340-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
Task: {EEFDF596-9C6C-4841-A87A-67B759D1956D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-22] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-09-04 20:13 - 2013-09-04 20:13 - 00049368 _____ () C:\Program Files\Lenovo\Bluetooth Software\btwleapi.dll
2015-04-19 13:49 - 2015-04-19 13:49 - 00359936 _____ () C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll
2015-05-20 16:49 - 2015-05-20 17:07 - 207206296 _____ () C:\Users\VDG\Downloads\avira_antivirus_en-us.exe
2015-05-02 05:12 - 2015-04-28 07:37 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libglesv2.dll
2015-05-02 05:12 - 2015-04-28 07:37 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libegl.dll
2015-05-02 05:12 - 2015-04-28 07:37 - 14980424 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
AlternateDataStreams: C:\ProgramData\TEMP:58A5270D
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 172.17.36.5 - 172.17.36.9
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: BlackBerry Device Manager => 3
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: GingerUpdateService => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HWDeviceService64.exe => 2
MSCONFIG\Services: IBMPMSVC => 2
MSCONFIG\Services: ICCS => 3
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: Mobile Partner. RunOuc => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: OpenVPNService => 3
MSCONFIG\Services: Razer Game Scanner Service => 2
MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2
MSCONFIG\Services: RealPlayer Cloud Service => 2
MSCONFIG\Services: RealPlayerUpdateSvc => 2
MSCONFIG\Services: RIM MDNS => 2
MSCONFIG\Services: RIM Tunnel Service => 2
MSCONFIG\Services: RzKLService => 2
MSCONFIG\Services: ServiceLayer => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SUService => 3
MSCONFIG\Services: TeamViewer => 2
MSCONFIG\Services: TunnelBearMaintenance => 3
HKLM\…\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk"
HKLM\…\StartupApproved\StartupFolder: => "avast! SecureLine.lnk"
HKLM\…\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\…\StartupApproved\Run: => "ProxyCap"
HKLM\…\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "RIM PeerManager"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "RIMBBLaunchAgent.exe"
HKLM\…\StartupApproved\Run32: => "RealDownloader"
HKLM\…\StartupApproved\Run32: => "TkBellExe"
HKLM\…\StartupApproved\Run32: => "NokiaMServer"
HKLM\…\StartupApproved\Run32: => "NokiaMusic FastStart"
HKLM\…\StartupApproved\Run32: => "zenvpn"
HKLM\…\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKLM\…\StartupApproved\Run32: => "AmIcoSinglun64"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "NokiaSuite.exe"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "BlackBerryLink.exe"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "IDMan"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "TunnelBear"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "Hide.me"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "SOS_Agent"
HKU\S-1-5-21-504121640-2405822300-1051111340-1001\…\StartupApproved\Run: => "SOS Browser Monitor"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [TCP Query User{B21DBDBD-6929-413F-B754-D97A376BED20}C:\program files (x86)\utorrent\utorrent.exe] => (Allow) C:\program files (x86)\utorrent\utorrent.exe
FirewallRules: [UDP Query User{73741AAF-C41D-42C5-AC49-90598B5250A9}C:\program files (x86)\utorrent\utorrent.exe] => (Allow) C:\program files (x86)\utorrent\utorrent.exe
FirewallRules: [{31D60508-7F4E-472D-8F2B-80616F9BDA77}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{B967A47D-B4FD-472E-B1D1-F69473AF6C42}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{81E607AC-0E61-4238-B1D6-A1EDD375A214}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{C676E1F9-09A1-4D97-BCFC-7BE4B1540016}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{9494C9BF-D77E-4E32-8D28-0033793D572B}] => (Allow) C:\Users\VDG\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{B191BDB2-C912-4752-BD6C-7F1476FCF051}] => (Allow) C:\Users\VDG\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{EE9FD50C-037C-497E-8AF0-EA2A16677760}C:\users\vdg\appdata\roaming\utorrent\updates\3.4.2_38397.exe] => (Allow) C:\users\vdg\appdata\roaming\utorrent\updates\3.4.2_38397.exe
FirewallRules: [UDP Query User{58DE5E5B-1D27-4467-AB61-62813B6EC31B}C:\users\vdg\appdata\roaming\utorrent\updates\3.4.2_38397.exe] => (Allow) C:\users\vdg\appdata\roaming\utorrent\updates\3.4.2_38397.exe
FirewallRules: [TCP Query User{5B1F1C56-5074-472F-995F-CD8496A4C295}E:\software\rtmpdumphelper121\rtmpsuck.exe] => (Allow) E:\software\rtmpdumphelper121\rtmpsuck.exe
FirewallRules: [UDP Query User{73E0E908-57C9-4208-8643-49178F4F067C}E:\software\rtmpdumphelper121\rtmpsuck.exe] => (Allow) E:\software\rtmpdumphelper121\rtmpsuck.exe
FirewallRules: [TCP Query User{A4264D90-9279-4407-9340-CE5FF7CB932F}E:\software\rtmpdump-2.4\rtmpsuck.exe] => (Allow) E:\software\rtmpdump-2.4\rtmpsuck.exe
FirewallRules: [UDP Query User{FA5D7949-C8D8-491F-A560-14AD4C4F84D7}E:\software\rtmpdump-2.4\rtmpsuck.exe] => (Allow) E:\software\rtmpdump-2.4\rtmpsuck.exe
FirewallRules: [TCP Query User{10235A0F-B8EF-410B-896D-2B45A580084A}E:\software\rtmpdump-2.4\rtmpsrv.exe] => (Allow) E:\software\rtmpdump-2.4\rtmpsrv.exe
FirewallRules: [UDP Query User{B5C0ACA3-91FD-4862-A6C4-F2CC95EEB736}E:\software\rtmpdump-2.4\rtmpsrv.exe] => (Allow) E:\software\rtmpdump-2.4\rtmpsrv.exe
FirewallRules: [{74EBD99E-96DD-4CE6-B557-D472F7C8DFF0}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{1E69547E-4D13-480C-84E1-E72C6AA12FF8}] => (Allow) tunmgr.exe
FirewallRules: [{931E52A7-2F74-4BB0-8BF8-0AE467C74998}] => (Allow) tunmgr.exe
FirewallRules: [{A29B1132-98AF-4FBB-A1E2-4FC5E2D48EC7}] => (Allow) mDNSResponder.exe
FirewallRules: [{0B1AC580-2EFD-4365-8F61-8D3008FBAFD3}] => (Allow) mDNSResponder.exe
FirewallRules: [{EE8C0CBD-F6DE-4667-A52D-75777D802218}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{ACD1C561-8145-436E-9C17-832CE7D9955D}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{7F77E5E9-9FC7-4000-B6B5-C4264E2A5F4E}C:\program files (x86)\java\jre1.8.0_45\bin\jp2launcher.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\jp2launcher.exe
FirewallRules: [UDP Query User{DBD643F9-E775-4111-B9B3-13CA4697928A}C:\program files (x86)\java\jre1.8.0_45\bin\jp2launcher.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\jp2launcher.exe
FirewallRules: [{30F890FB-222D-4925-B05A-560EB1433EDA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{D9BF9E24-9478-40BB-9ADB-1D6037A2C737}] => (Allow) E:\Games\Grand Theft Auto V\GTA5.exe
FirewallRules: [{98AF1134-8A42-4575-A80B-AB23E191F545}] => (Allow) E:\Games\Grand Theft Auto V\GTA5.exe
FirewallRules: [{EE233F3F-91BE-40E7-B6E8-1617996D8A00}] => (Allow) E:\Games\Grand Theft Auto V\GTA5.exe
FirewallRules: [{9C0FC8BE-D107-4864-AF0C-6DB7D1C94F60}] => (Allow) E:\Games\Grand Theft Auto V\GTA5.exe
FirewallRules: [{2F01B269-0D8F-4F4D-AF94-783A062B4659}] => (Allow) E:\Games\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{C965E78B-B743-4F03-B289-BC90275FD7BD}] => (Allow) E:\Games\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{86F13CD7-8EEB-4AF5-B846-2D1AC996CE8C}] => (Allow) E:\Games\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{E9B2215F-730B-4124-B212-2CA8E7513505}] => (Allow) E:\Games\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{E0C6A62E-85A1-4C9D-BB10-A1145F72C541}] => (Allow) E:\Games\Grand Theft Auto V\Launcher.exe
FirewallRules: [{D1CE19BF-79EF-407F-9CD2-4BC285FEDC9D}] => (Allow) E:\Games\Grand Theft Auto V\Launcher.exe
FirewallRules: [{1D08050F-996D-404C-A185-A2E550DD093F}] => (Allow) E:\Games\Grand Theft Auto V\Launcher.exe
FirewallRules: [{BFF4CA08-6ADC-43AC-AA1C-C938536E6D7A}] => (Allow) E:\Games\Grand Theft Auto V\Launcher.exe
FirewallRules: [{F18CCAD3-B60B-4886-B565-9D3510DC5F33}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{A9C9A8FC-A871-4FCF-84C2-9A774F9714EF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0CBFEEF4-5E4E-4061-B47F-9542E3511495}] => (Allow) LPort=2869
FirewallRules: [{04A68E1B-AB4F-4E70-BBA6-7468F13FDCCB}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{9381FA52-36DC-416E-AB73-EC384E9BA282}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe
FirewallRules: [UDP Query User{6C5D5CC0-CC1E-4ECE-9A03-9574F47F7384}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe
FirewallRules: [{8E4AA736-2F1C-48D1-A7A3-A4DCEA4D30ED}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{8DB869E7-A85B-435F-A80F-04B0E5B06C01}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{30E9D3D4-7797-41F4-94E9-A62DFF719CEC}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{E88B18D2-8729-4A08-B580-EB3563D4ED83}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{7FDBAA60-A225-4904-BC67-3E0C5E78C353}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{AA96A36E-553E-468B-A709-702BBF74D781}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [TCP Query User{138C2F7E-DCEE-4524-AF4F-BA087C631B44}C:\program files (x86)\popcorn time\chromecast\node.exe] => (Allow) C:\program files (x86)\popcorn time\chromecast\node.exe
FirewallRules: [UDP Query User{A27EE967-C4B5-4F14-8B9E-8640362AA61A}C:\program files (x86)\popcorn time\chromecast\node.exe] => (Allow) C:\program files (x86)\popcorn time\chromecast\node.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe] => Enabled:Flashget3
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/20/2015 03:11:36 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\VDG\Downloads\HitmanPro_x64.exe ; Description = Checkpoint by HitmanPro; Error = 0x8007043c).
Error: (05/20/2015 03:10:45 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\VDG\Downloads\HitmanPro_x64.exe ; Description = Checkpoint by HitmanPro; Error = 0x8007043c).
Error: (05/20/2015 02:34:13 AM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]
Error: (05/20/2015 02:34:12 AM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]
Error: (05/20/2015 01:19:03 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied.
]
Error: (05/20/2015 01:06:35 AM) (Source: MsiInstaller) (EventID: 1013) (User: Vishal)
Description: Product: EasySync CryptoMonitor – Error Text!
Error: (05/20/2015 00:52:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SpyHunter-Installer.exe version 1.0.304.468 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 50c
Start Time: 01d0926386bdb34b
Termination Time: 4294967295
Application Path: C:\Users\VDG\Downloads\SpyHunter-Installer.exe
Report Id: 52a6dd14-fe5c-11e4-82bc-3c970e443cf5
Faulting package full name:
Faulting package-relative application ID:
Error: (05/20/2015 00:11:58 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database
Error: (05/19/2015 11:36:11 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied.
]
Error: (05/19/2015 11:34:17 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied.
]
System errors:
=============
Error: (05/20/2015 05:51:12 AM) (Source: DCOM) (EventID: 10010) (User: Vishal)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (05/20/2015 05:50:42 AM) (Source: DCOM) (EventID: 10010) (User: Vishal)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (05/20/2015 03:19:07 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor APIC ID: 0
The details view of this entry contains further information.
Error: (05/20/2015 03:19:06 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor APIC ID: 0
The details view of this entry contains further information.
Error: (05/20/2015 03:19:06 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:
Error: (05/20/2015 03:19:06 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:
Error: (05/20/2015 03:18:51 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Net.Tcp Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error:
%%3
Error: (05/20/2015 03:18:51 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error:
%%3
Error: (05/20/2015 03:18:46 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Process Activation Service service terminated with the following error:
%%3
Error: (05/20/2015 03:18:45 AM) (Source: WAS) (EventID: 5005) (User: )
Description: Windows Process Activation Service (WAS) is stopping because it encountered an error. The data field contains the error number.
Microsoft Office Sessions:
=========================
Error: (05/20/2015 03:11:36 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Users\VDG\Downloads\HitmanPro_x64.exe Checkpoint by HitmanPro0x8007043c
Error: (05/20/2015 03:10:45 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Users\VDG\Downloads\HitmanPro_x64.exe Checkpoint by HitmanPro0x8007043c
Error: (05/20/2015 02:34:13 AM) (Source: VSS) (EventID: 18) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}Coordinator0x8007043c, This service cannot be started in Safe Mode
Error: (05/20/2015 02:34:12 AM) (Source: VSS) (EventID: 18) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}Coordinator0x8007043c, This service cannot be started in Safe Mode
Error: (05/20/2015 01:19:03 AM) (Source: VSS) (EventID: 13) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}Coordinator0x80070005, Access is denied.
Error: (05/20/2015 01:06:35 AM) (Source: MsiInstaller) (EventID: 1013) (User: Vishal)
Description: Product: EasySync CryptoMonitor – Error Text!(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (05/20/2015 00:52:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: SpyHunter-Installer.exe1.0.304.46850c01d0926386bdb34b4294967295C:\Users\VDG\Downloads\SpyHunter-Installer.exe52a6dd14-fe5c-11e4-82bc-3c970e443cf5
Error: (05/20/2015 00:11:58 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: -2147024883
Error: (05/19/2015 11:36:11 PM) (Source: VSS) (EventID: 13) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}Coordinator0x80070005, Access is denied.
Error: (05/19/2015 11:34:17 PM) (Source: VSS) (EventID: 13) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}Coordinator0x80070005, Access is denied.
CodeIntegrity Errors:
===================================
Date: 2015-05-20 05:53:46.835
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-15 16:45:48.990
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-12 14:58:44.933
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-12 01:41:25.044
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-10 23:32:39.895
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-08 03:55:40.761
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-07 02:27:44.208
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-04 22:37:28.838
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-04 00:16:23.436
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-02 04:18:00.342
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz
Percentage of memory in use: 54%
Total physical RAM: 3854.22 MB
Available physical RAM: 1737.21 MB
Total Pagefile: 22286.22 MB
Available Pagefile: 19350.89 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:50.44 GB) (Free:14.69 GB) NTFS
Drive e: (Vishal) (Fixed) (Total:414.98 GB) (Free:60.59 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5CA5ECDE)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=50.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=415 GB) - (Type=07 NTFS)
==================== End Of Log ============================