This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

solution to decrypted files [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Step 1

My computer was infected by something called RSA-2048 using CryptoWall 3.0. Now all my files are unreadable

Step 2

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:11-10-2015 02

Ran by [removed] (administrator) on USER-PC (12-10-2015 18:33:13)

Running from C:\Users\[removed]\Downloads

[removed]

Platform: Microsoft Windows 7 Ultimate  (X86) Language: English (United States)

Internet Explorer Version 8 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe

(Beijing Rising Information Technology Co., Ltd.) C:\Program Files\Rising\RSD\RsMgrSvc.exe

(Beijing Rising Information Technology Co., Ltd.) C:\Program Files\Rising\RIS\RavMonD.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe

(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe

(Visicom Media Inc.) C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filteringb.exe

(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe

(Beijing Rising Information Technology Co., Ltd.) C:\Program Files\Rising\RSD\popwndexe.exe

(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

(Intel Corporation) C:\Windows\System32\igfxtray.exe

(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe

(Microsoft Corp.) C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe

(Intel Corporation) C:\Windows\System32\igfxsrvc.exe

(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe

(Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE

(Beijing Rising Information Technology Co., Ltd.) C:\Program Files\Rising\RIS\RsTray.exe

(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe

(BitTorrent Inc.) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

() C:\Windows\System32\Codecs\UpdateChecker.exe

() C:\Windows\System32\Codecs\TrayMenu.exe

(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

(BitTorrent Inc.) C:\Users\user\AppData\Roaming\BitTorrent\updates\7.9.5_41203\utorrentie.exe

(BitTorrent Inc.) C:\Users\user\AppData\Roaming\BitTorrent\updates\7.9.5_41203\utorrentie.exe

(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe

(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

(Microsoft Corporation) C:\Windows\System32\prevhost.exe

(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

(AVAST Software) C:\Users\user\Downloads\aswMBR.exe

 

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [RSDTRAY] => C:\Program Files\Rising\RSD\popwndexe.exe [126808 2015-03-25] (Beijing Rising Information Technology Co., Ltd.)

HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)

HKLM\…\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)

HKLM\…\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54576 2009-11-18] (Hewlett-Packard)

HKLM\…\Run: [] => [X]

HKLM\…\Run: [Bing Bar] => C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe [243544 2010-04-27] (Microsoft Corp.)

HKLM\…\Run: [Microsoft Default Manager] => C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)

HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)

HKLM\…\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)

HKLM\…\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)

HKLM\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-28] (Adobe Systems Incorporated)

HKLM\…\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [815512 2011-09-28] (Adobe Systems Inc.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157992 2015-06-29] (Apple Inc.)

HKLM\…\Run: [Codec Settings UAC Manager] => C:\Windows\system32\Codecs\CodecUACManager.exe [60416 2015-09-04] ()

HKLM\…\Run: [RISTRAY] => C:\Program Files\Rising\RIS\RSTRAY.EXE [178840 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

HKLM\…\Run: [PSUAMain] => C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe [54520 2015-07-28] (Panda Security, S.L.)

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\Run: [AdobeBridge] => [X]

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\Run: [BitTorrent] => C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe [1977192 2015-10-11] (BitTorrent Inc.)

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\Run: [Codec Pack Update Checker] => C:\Windows\system32\Codecs\UpdateChecker.exe [55992 2015-09-04] ()

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\CurrentVersion\Windows: [Load]   <===== ATTENTION

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\MountPoints2: {c76349b3-dc40-11e4-be64-806e6f6e6963} - J:\setup.exe

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…409d6c4515e9\InprocServer32: [Default-shell32] C:\Users\user\AppData\Local\AXWworks\mnrzezwd.dllATTENTION! ====> ZeroAccess?

ShellIconOverlayIdentifiers: [0PerformanceMonitor] -> {3B5B973C-92A4-4855-9D3F-0F3D23332208} =>  No File

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2015-10-05]

ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\System32\Codecs\TrayMenu.exe ()

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2015-04-06]

ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2015-05-05]

ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

BootExecute: autocheck autochk *  bsmain

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{8FA10199-59FC-42EA-A0FB-7E33517736CF}: [NameServer] 196.202.139.242 196.202.139.238

Tcpip\..\Interfaces\{AE3B4350-5900-4A64-8DFF-814D3A476DAB}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pandasecurity.mystart.com/?pr=vmn&id;=pandasecuritytb&v;=4_3&utm;_campaign=671&idate;=2015-10-11&ent;=hp_671&u;=69DA8D291C14639E2B934B561A446648

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/ar-ae/?ocid=iehp

URLSearchHook: [S-1-5-21-2773704555-2083345569-1616236315-1000] ATTENTION => Default URLSearchHook is missing

URLSearchHook: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000 - Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll No File

SearchScopes: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen;=ms&id;=pandasecuritytb&v;=4_3&idate;=2015-10-11&ent;=ch_671&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen;=ms&id;=pandasecuritytb&v;=4_3&idate;=2015-10-11&ent;=ch_671&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000 -> {93FD470E-AD16-46B8-AE68-BD3A98F3CD18} URL = hxxp://www.bing.com/search?FORM=MSNTLB&PC;=IP2TDF&q;={searchTerms}&src;=IE-SearchBox

BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2010-05-28] (Hewlett-Packard Co.)

BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)

BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-01-14] (Microsoft Corporation)

BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)

BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)

BHO: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-28] (Adobe Systems Incorporated)

BHO: Panda Security Toolbar -> {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} -> C:\Program Files\pandasecuritytb\pandasecurityDx.dll No File

BHO: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll [2010-04-27] (Microsoft Corporation)

BHO: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-28] (Adobe Systems Incorporated)

BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2010-05-28] (Hewlett-Packard Co.)

Toolbar: HKLM - @C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll [2010-04-27] (Microsoft Corporation)

Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-28] (Adobe Systems Incorporated)

Toolbar: HKLM - Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll No File

Toolbar: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000 -> Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-28] (Adobe Systems Incorporated)

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)

 

FireFox:

========

FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default

FF NewTab: chrome://quick_start/content/index.html

FF DefaultSearchEngine: oursurfing

FF SelectedSearchEngine: oursurfing

FF Homepage: hxxp://www.oursurfing.com/?type=hp&ts;=1441904626&z;=153b4d5588cf2a28062001eg9z2z7g6tceez2q5cdg&from;=amt&uid;=SAMSUNGXHD501LJ_S0MUJ1KPA03756

FF SelectedSearchEngine: Search The Web

FF Homepage: hxxp://pandasecurity.mystart.com/?pr=vmn&id;=pandasecuritytb&v;=4_3&utm;_campaign=671&idate;=2015-10-08&ent;=hp_671&u;=69DA8D291C14639E2B934B5616A78746

FF SelectedSearchEngine: Search The Web

FF Homepage: hxxp://pandasecurity.mystart.com/?pr=vmn&id;=pandasecuritytb&v;=4_3&utm;_campaign=671&idate;=2015-10-11&ent;=hp_671&u;=69DA8D291C14639E2B934B561A446648

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-04-04] ()

FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll [2009-08-17] ( Microsoft Corporation)

FF Plugin: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll [2010-04-27] (Microsoft Corporation)

FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-28] (Adobe Systems Inc.)

FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-02-16] (Adobe Systems Inc.)

FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\searchplugins\oursurfing.xml [2015-10-08]

FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-10-11]

FF Extension: Microsoft Default Manager - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\Extensions\DefaultManager@Microsoft [2015-08-20]

FF Extension: Default SearchProtected  - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\Extensions\[removed] [2015-09-10]

FF Extension: No Name - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\Extensions\[removed] [2015-09-10]

FF Extension: No Name - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\Extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} [2015-10-11]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2015-04-06]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\Firefox

FF Extension: Bing Bar - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\Firefox [2015-04-06]

FF HKLM\…\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension

FF Extension: Search Helper Extension - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2015-04-06]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn

FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-04-25]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\extensions\[removed]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dxe6zvt8.default\extensions\[removed]

FF HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-10-06]

 

Chrome:

=======

CHR StartupUrls: Default -> "hxxps://www.google.com/", "hxxps://www.youtube.com/", "hxxps://mail.google.com/mail/u/0/h/1un6vr8ks4zsg/?tab=wm&zy;=g&f;=1", "hxxps://translate.google.com/?hl=en&tab;=wT", "hxxps://www.google.com/calendar/render?tab=wc#main_7"

CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default

CHR Extension: (Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-25]

CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx

StartMenuInternet: Google Chrome.VR5QDXLP2P55OKWACAISZDRHTY - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 NanoServiceMain; C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe [142072 2015-07-29] (Panda Security, S.L.)

R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [File not signed]

R2 PandaAgent; C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe [73464 2015-07-23] (Panda Security, S.L.)

R2 panda_url_filtering; C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filteringb.exe [283448 2014-09-19] (Visicom Media Inc.)

R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [File not signed]

R2 PSUAService; C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe [38136 2015-07-28] (Panda Security, S.L.)

R2 RsMgrSvc; C:\Program Files\Rising\RSD\RsMgrSvc.exe [196288 2015-08-06] (Beijing Rising Information Technology Co., Ltd.)

R2 RsRISMon; C:\Program Files\Rising\RIS\RavMonD.exe [264448 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [771968 2015-10-11] (Enigma Software Group USA, LLC.)

S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-12-11] (VIA Technologies, Inc.)

S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

S2 NMSAccess; "C:\Program Files\Blaze Media Pro\NMSAccess32.exe"  [X]

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [16432 2015-10-11] (Enigma Software Group USA, LLC.)

S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2015-10-11] ()

R1 hooksys; C:\Windows\system32\drivers\Hooksys.sys [176088 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

R1 HookTdi; C:\Windows\system32\drivers\HookTdi.sys [24280 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

R1 HyperVM; C:\Windows\system32\drivers\hvm.sys [32568 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

S3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [110280 2013-11-29] (Qualcomm Atheros Co., Ltd.)

R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [87032 2015-07-09] (Panda Security, S.L.)

R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [202104 2015-07-09] (Panda Security, S.L.)

R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [109688 2015-07-09] (Panda Security, S.L.)

R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [121720 2015-07-09] (Panda Security, S.L.)

R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [50992 2015-05-20] (Panda Security, S.L.)

R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [102264 2015-07-09] (Panda Security, S.L.)

R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [64760 2015-07-09] ()

R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [120568 2015-07-09] (Panda Security, S.L.)

R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [281720 2015-07-09] (Panda Security, S.L.)

R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [209016 2015-07-09] (Panda Security, S.L.)

R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [108408 2015-07-09] (Panda Security, S.L.)

R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [240376 2015-07-09] (Panda Security, S.L.)

R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [94968 2015-07-09] (Panda Security, S.L.)

R3 panda_url_filteringd; C:\ProgramData\Panda Security URL Filtering\panda_url_filteringd.sys [40024 2014-02-18] (Visicom Media Inc.)

R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [140024 2015-07-19] (Panda Security, S.L.)

R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [105208 2015-07-19] (Panda Security, S.L.)

R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [168696 2015-07-19] (Panda Security, S.L.)

R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [113912 2015-07-19] (Panda Security, S.L.)

R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [124664 2015-07-19] (Panda Security, S.L.)

R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [100600 2015-07-19] (Panda Security, S.L.)

R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50832 2015-05-22] (Panda Security, S.L.)

R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [45968 2011-11-03] (Rovi Corporation)

R1 RFWNDIS; C:\Windows\System32\DRIVERS\rfwndis.sys [16024 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

R2 rfwtdi; C:\Program Files\Rising\RIS\rfwtdi.sys [25880 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

R2 rsdsys; C:\Windows\system32\drivers\protreg.sys [24120 2015-03-25] (Beijing Rising Information Technology Co., Ltd.)

R2 rsfwdrv; C:\Program Files\Rising\RIS\rsfwdrv.sys [60952 2015-10-08] (Beijing Rising Information Technology Co., Ltd.)

S3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [565424 2013-12-16] (VIA Technologies, Inc.)

U3 aswMBR; \??\C:\Users\user\AppData\Local\Temp\aswMBR.sys [X]

U3 aswVmm; \??\C:\Users\user\AppData\Local\Temp\aswVmm.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-10-12 18:33 - 2015-10-12 18:34 - 00023665 _____ C:\Users\user\Downloads\FRST.txt

2015-10-12 18:32 - 2015-10-12 18:33 - 00000000 ____D C:\FRST

2015-10-12 18:30 - 2015-10-12 18:31 - 02195968 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe

2015-10-12 18:30 - 2015-10-12 18:31 - 01699840 _____ (Farbar) C:\Users\user\Downloads\FRST.exe

2015-10-12 18:10 - 2015-10-12 18:12 - 05198336 _____ (AVAST Software) C:\Users\user\Downloads\aswMBR.exe

2015-10-11 18:54 - 2015-05-22 11:45 - 00050832 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys

2015-10-11 18:32 - 2015-10-11 18:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kernel for Word Evaluation Ver

2015-10-11 18:32 - 2015-10-11 18:32 - 00000000 ____D C:\Program Files\Kernel for Word Evaluation Ver

2015-10-11 18:32 - 2004-10-17 04:08 - 00835584 _____ () C:\Windows\system32\AxImage.ocx

2015-10-11 17:33 - 2015-10-11 17:33 - 00018944 ___SH C:\Users\user\AppData\Thumbs.db

2015-10-11 17:33 - 2015-10-11 17:33 - 00018944 ___SH C:\Users\user\AppData\Roaming\Thumbs.db

2015-10-11 17:23 - 2015-10-11 17:24 - 02904208 _____ (Lepide Software Pvt.Ltd. ) C:\Users\user\Downloads\Nucleus-Kernel-Word.exe

2015-10-11 15:33 - 2015-10-11 15:33 - 00001244 _____ C:\Users\user\Desktop\SpyHunter.lnk

2015-10-11 15:33 - 2015-10-11 15:33 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter

2015-10-11 15:33 - 2015-10-11 15:33 - 00000000 ____D C:\Users\user\AppData\Roaming\Enigma Software Group

2015-10-11 15:30 - 2015-10-11 15:32 - 00000000 ____D C:\sh4ldr

2015-10-11 15:07 - 2015-10-11 15:07 - 00019984 _____ C:\Windows\system32\Drivers\EsgScanner.sys

2015-10-11 15:03 - 2015-10-11 15:03 - 00000000 ____D C:\Program Files\Enigma Software Group

2015-10-11 14:52 - 2015-10-11 14:53 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer (1).exe

2015-10-11 14:18 - 2015-10-11 14:18 - 00000000 ____D C:\ProgramData\Panda Security URL Filtering

2015-10-11 14:16 - 2015-10-11 14:17 - 00000000 ____D C:\Users\user\AppData\LocalLow\pandasecuritytb

2015-10-11 14:13 - 2015-10-11 17:36 - 00000000 ____D C:\Program Files\pandasecuritytb

2015-10-11 14:12 - 2015-10-11 14:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free Antivirus

2015-10-11 08:57 - 2015-10-11 08:57 - 00011756 _____ C:\Users\user\Downloads\[kat.cr]cambridge.ielts.10.with.audio.torrent

2015-10-11 08:30 - 2015-10-11 08:30 - 00011401 _____ C:\Users\user\Downloads\Cambridge-IELTS-10.pdf - ThePirateBay.TO (2).torrent

2015-10-11 08:29 - 2015-10-11 08:29 - 00011401 _____ C:\Users\user\Downloads\Cambridge-IELTS-10.pdf - ThePirateBay.TO (1).torrent

2015-10-11 08:18 - 2015-10-11 08:18 - 00011401 _____ C:\Users\user\Downloads\bittorrents.biz Cambridge-IELTS-10.pdf.torrent

2015-10-11 08:06 - 2015-10-11 08:06 - 00018944 ___SH C:\Users\user\Thumbs.db

2015-10-08 20:57 - 2015-10-08 20:57 - 00001244 _____ C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk

2015-10-08 20:54 - 2015-10-08 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security

2015-10-08 20:38 - 2015-10-12 11:24 - 00000784 _____ C:\Windows\setupact.log

2015-10-08 20:38 - 2015-10-12 08:02 - 00262144 _____ C:\Windows\system32\Ikeext.etl

2015-10-08 20:30 - 2015-10-12 14:18 - 00000000 ____D C:\ProgramData\panda_url_filtering

2015-10-08 20:27 - 2015-10-11 14:13 - 00000000 ____D C:\Users\user\AppData\Roaming\Panda Security

2015-10-08 20:25 - 2015-10-11 14:13 - 00000000 ____D C:\Program Files\Panda Security

2015-10-08 20:13 - 2015-10-08 20:13 - 00013948 _____ C:\Users\user\Downloads\AvastProAntivirus201510.0.2206Crack - ThePirateBay.TO.torrent

2015-10-08 19:50 - 2015-10-11 14:13 - 00000000 ____D C:\ProgramData\Panda Security

2015-10-08 19:49 - 2015-10-08 19:49 - 02113152 _____ C:\Users\user\Downloads\PANDAFREEAV.exe

2015-10-08 17:08 - 2015-10-08 17:08 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\user\Downloads\SpyHunter-Installer.exe

2015-10-08 15:56 - 2015-10-08 15:56 - 00002076 _____ C:\Users\Public\Desktop\Rising Internet Security.lnk

2015-10-08 15:56 - 2015-10-08 15:56 - 00000132 __RSH C:\rising.ini

2015-10-08 15:56 - 2015-10-08 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rising Internet Security

2015-10-08 15:52 - 2015-10-08 15:52 - 00000122 _____ C:\Windows\system32\BsMain.ini

2015-10-08 15:52 - 2015-10-08 15:51 - 00239768 ____N (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\bsmain.exe

2015-10-08 15:52 - 2015-10-08 15:51 - 00234648 ____N (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\ravext.dll

2015-10-08 15:52 - 2015-10-08 15:51 - 00176088 ____N (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\Drivers\Hooksys.sys

2015-10-08 15:52 - 2015-10-08 15:51 - 00038552 ____N (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\Drivers\HookHelp.sys

2015-10-08 15:52 - 2015-10-08 15:51 - 00032568 ____N (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\Drivers\hvm.sys

2015-10-08 15:52 - 2015-10-08 15:51 - 00024280 ____N (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\Drivers\HookTdi.sys

2015-10-08 15:52 - 2015-10-08 15:51 - 00016024 _____ (Beijing Rising Information Technology Co., Ltd.) C:\Windows\system32\Drivers\rfwndis.sys

2015-10-08 13:00 - 2015-10-08 13:00 - 00000018 _____ C:\Users\user\Downloads\fsaidpw.txt

2015-10-08 12:00 - 2015-10-08 12:00 - 00008654 _____ C:\Users\user\Documents\HELP_DECRYPT.HTML

2015-10-08 12:00 - 2015-10-08 12:00 - 00004270 _____ C:\Users\user\Documents\HELP_DECRYPT.TXT

2015-10-08 12:00 - 2015-10-08 12:00 - 00000296 _____ C:\Users\user\Documents\HELP_DECRYPT.URL

2015-10-08 09:37 - 2015-10-08 09:37 - 00008654 _____ C:\Users\user\AppData\Local\HELP_DECRYPT.HTML

2015-10-08 09:37 - 2015-10-08 09:37 - 00004270 _____ C:\Users\user\AppData\Local\HELP_DECRYPT.TXT

2015-10-08 09:37 - 2015-10-08 09:37 - 00000296 _____ C:\Users\user\AppData\Local\HELP_DECRYPT.URL

2015-10-08 09:25 - 2015-10-08 09:25 - 00008654 _____ C:\ProgramData\HELP_DECRYPT.HTML

2015-10-08 09:25 - 2015-10-08 09:25 - 00004270 _____ C:\ProgramData\HELP_DECRYPT.TXT

2015-10-08 09:25 - 2015-10-08 09:25 - 00000296 _____ C:\ProgramData\HELP_DECRYPT.URL

2015-10-06 12:38 - 2015-10-07 16:45 - 00000000 ____D C:\Program Files\Mozilla Firefox

2015-10-06 11:45 - 2015-10-12 08:03 - 00000000 ____D C:\Users\user\AppData\LocalLow\BitTorrent

2015-10-05 19:07 - 2015-10-05 19:07 - 00000000 ____D C:\Windows\system32\Codecs

2015-10-05 19:07 - 2015-10-05 19:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player - Codec Pack

2015-10-05 19:00 - 2015-10-05 19:07 - 41636416 _____ (Media Player - Codec Pack) C:\Users\user\Downloads\media.player.codec.pack.v4.3.9.setup.exe

2015-10-05 18:58 - 2015-10-11 07:59 - 00000000 ____D C:\Users\user\AppData\Local\AXWworks

2015-10-05 18:58 - 2015-10-08 20:38 - 00000000 ____D C:\Users\user\AppData\Local\Ogkcics

2015-10-04 16:56 - 2015-10-04 16:56 - 00114501 _____ C:\Users\user\Downloads\[kat.cr]black.mass.2015.hc.hdrip.xvid.ac3.etrg.torrent

2015-10-04 16:56 - 2015-10-04 16:56 - 00114501 _____ C:\Users\user\Downloads\[kat.cr]black.mass.2015.hc.hdrip.xvid.ac3.etrg (1).torrent

2015-10-04 16:56 - 2015-10-04 16:56 - 00019429 _____ C:\Users\user\Downloads\[kat.cr]black.mass.2015.720p.hc.hdrip.900mb.mkvcage.torrent

2015-10-04 16:41 - 2015-10-04 16:41 - 00034430 _____ C:\Users\user\Downloads\Sicario 2015.torrent

2015-10-01 18:29 - 2015-10-01 18:29 - 00016898 _____ C:\Users\user\Downloads\[kat.cr]straight.outta.compton.2015.hc.hdrip.xvid.ac3.etrg.torrent

2015-10-01 08:50 - 2012-09-18 15:26 - 00365568 _____ C:\Windows\system32\ZSHP1020.EXE

2015-10-01 08:50 - 2012-09-18 15:26 - 00169472 _____ C:\Windows\system32\ZLhp1020.DLL

2015-10-01 08:50 - 2012-09-18 10:34 - 00574100 _____ C:\Windows\system32\hp1022n.img

2015-10-01 08:50 - 2012-09-18 10:34 - 00245248 _____ () C:\Windows\system32\zshp1020s.dll

2015-10-01 08:50 - 2012-09-18 10:34 - 00206768 _____ C:\Windows\system32\hp1022.img

2015-10-01 08:50 - 2012-09-18 10:34 - 00128820 _____ C:\Windows\system32\hp1020.img

2015-10-01 08:50 - 2012-09-18 10:34 - 00010632 _____ C:\Windows\system32\ZSHP1020.CHM

2015-09-30 12:14 - 2015-09-30 12:14 - 00019643 _____ C:\Users\user\Downloads\[kat.cr]mission.impossible.rogue.nation.2015.720p.webhd.x264.aac.ddr.torrent

2015-09-29 16:37 - 2015-09-29 16:37 - 00004659 _____ C:\Users\user\Downloads\[kat.cr]the.intern.2015.cam.readnote.x264.ac3.cpg.torrent

2015-09-29 16:36 - 2015-09-29 16:36 - 00014817 _____ C:\Users\user\Downloads\[kat.cr]the.intern.2015.hdcam.hqmic.700mb.mkvcage.torrent

2015-09-29 14:23 - 2015-09-29 14:23 - 00034442 _____ C:\Users\user\Downloads\The Intern 2015 (2).torrent

2015-09-29 13:49 - 2015-09-29 13:49 - 00034442 _____ C:\Users\user\Downloads\The Intern 2015 (1).torrent

2015-09-29 13:48 - 2015-09-29 13:48 - 00034442 _____ C:\Users\user\Downloads\The Intern 2015.torrent

2015-09-22 15:33 - 2015-09-22 15:33 - 00000863 _____ C:\Users\user\Desktop\YSM - Shortcut.lnk

2015-09-20 16:04 - 2015-10-12 08:53 - 00000000 ___SD C:\Users\user\AppData\LocalLow\Temp

2015-09-16 18:56 - 2015-10-12 08:58 - 00000000 ____D C:\Users\user\Downloads\Lucy 2014

2015-09-15 14:58 - 2015-10-12 08:57 - 00000000 ____D C:\Users\user\Downloads\The Beatles - The Complete Discography of Original Studio Albums

2015-09-15 14:57 - 2015-09-15 14:57 - 00036315 _____ C:\Users\user\Downloads\TheBeatles-TheCompleteDiscographyofOriginalStudioAlbums - ThePirateBay.TO.torrent

2015-09-15 14:55 - 2015-09-15 14:55 - 00554672 _____ C:\Users\user\Downloads\Discografia++Beatles__15022_i1651038586_il829946.rar

2015-09-14 15:39 - 2015-09-14 15:39 - 00233969 _____ C:\Users\user\Documents\9-14 test 1 new.wma

2015-09-14 15:05 - 2015-09-14 15:05 - 00000000 ____D C:\Users\user\AppData\Local\PackageAware

2015-09-14 12:19 - 2015-10-12 08:24 - 00000000 ____D C:\Users\user\Desktop\checkpoint

2015-09-14 12:18 - 2015-10-11 14:49 - 00000000 ____D C:\Users\user\Desktop\Presentation writing

2015-09-13 11:23 - 2015-09-13 11:23 - 00498879 _____ C:\Users\user\Documents\9-11 test 5.wma

2015-09-13 09:14 - 2015-09-13 09:14 - 00337239 _____ C:\Users\user\Documents\9-11 test 4.wma

2015-09-13 09:11 - 2015-10-08 12:00 - 00000000 ____D C:\Users\user\Documents\Speaking Files

2015-09-13 09:09 - 2015-09-13 09:09 - 00323769 _____ C:\Users\user\Documents\9-11 test 3.wma

2015-09-13 09:03 - 2015-09-13 09:03 - 00207029 _____ C:\Users\user\Documents\9-11 test 2.wma

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-10-12 18:35 - 2015-09-10 19:47 - 00000000 ____D C:\Users\user\AppData\Roaming\BitTorrent

2015-10-12 14:10 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\tracing

2015-10-12 08:57 - 2015-04-04 18:40 - 00000000 ____D C:\Users\user\Downloads\Video

2015-10-12 08:29 - 2015-04-28 20:07 - 00000000 ____D C:\Users\user\Desktop\BUSINESSand INVESTMENT raw content

2015-10-12 08:24 - 2015-09-10 18:20 - 00000000 ____D C:\Users\user\Desktop\Toefl

2015-10-12 08:23 - 2015-04-28 20:07 - 00000000 ____D C:\Users\user\Desktop\BUSINESS and INVESTMENT REPORT

2015-10-12 08:12 - 2015-04-15 14:05 - 00000000 ____D C:\Users\user\AppData\Local\Adobe

2015-10-12 08:10 - 2015-08-10 13:55 - 00000000 ____D C:\Users\user\Desktop\Bair IELTS

2015-10-12 08:10 - 2015-03-25 18:41 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI

2015-10-12 08:10 - 2009-07-14 07:34 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2015-10-12 08:10 - 2009-07-14 07:34 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2015-10-12 08:09 - 2015-04-25 18:07 - 00000000 ____D C:\Users\user\Desktop\Aviation Issue Final

2015-10-12 08:07 - 2015-09-08 13:18 - 00000000 ____D C:\Users\user\Desktop\IGCSE

2015-10-12 08:02 - 2015-03-25 18:56 - 00011194 _____ C:\Windows\PFRO.log

2015-10-12 08:02 - 2009-07-14 07:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2015-10-12 08:02 - 2009-07-14 07:33 - 05792496 _____ C:\Windows\system32\FNTCACHE.DAT

2015-10-11 17:49 - 2015-03-25 18:46 - 00000000 ____D C:\Users\user\AppData\Roaming\Mozilla

2015-10-11 14:25 - 2015-03-25 18:39 - 00000000 __RSD C:\RavBin

2015-10-11 14:13 - 2015-04-05 16:40 - 00138856 _____ C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT

2015-10-11 09:17 - 2015-08-01 15:51 - 00000000 ____D C:\Users\user\Desktop\IELTS  22

2015-10-08 17:04 - 2015-08-23 11:53 - 00000000 ____D C:\Users\user\Desktop\New folder (3)

2015-10-08 12:49 - 2015-03-25 18:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service

2015-10-08 12:43 - 2015-03-25 18:39 - 00000000 ____D C:\Program Files\Common Files\Adobe

2015-10-08 11:58 - 2015-07-08 15:12 - 00000000 ____D C:\Users\user\Desktop\OFAC

2015-10-08 11:58 - 2015-04-30 16:35 - 00000000 ____D C:\Users\user\Documents\KSDStore

2015-10-08 11:58 - 2015-04-09 18:45 - 00000000 ____D C:\Users\user\Documents\for Abbas April 9

2015-10-08 11:58 - 2015-04-09 12:38 - 00000000 ____D C:\Users\user\Documents\independence days

2015-10-08 11:56 - 2015-07-08 12:51 - 00000000 __SHD C:\Users\user\Desktop\mikal's flash

2015-10-08 11:56 - 2015-06-02 12:24 - 00000000 ____D C:\Users\user\Desktop\New folder

2015-10-08 11:17 - 2015-04-05 18:26 - 00000000 ____D C:\ProgramData\boost_interprocess

2015-10-08 10:54 - 2015-06-02 12:42 - 00000000 ____D C:\Users\user\Desktop\issue2

2015-10-08 10:54 - 2015-04-30 16:09 - 00000000 ____D C:\Users\user\Desktop\Mattresses

2015-10-08 10:54 - 2015-04-28 16:44 - 00000000 ____D C:\Users\user\Desktop\Issue 3 For translation

2015-10-08 09:39 - 2015-04-25 15:49 - 00000000 ____D C:\Users\user\Desktop\2 airlines

2015-10-08 09:39 - 2015-03-25 18:36 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype

2015-10-08 09:38 - 2015-04-30 16:35 - 00000000 ____D C:\Users\user\AppData\Roaming\kingsoft

2015-10-08 09:38 - 2015-04-06 13:03 - 00000000 ____D C:\Users\user\AppData\Roaming\HP

2015-10-08 09:38 - 2015-04-04 17:41 - 00000000 ____D C:\Users\user\AppData\Roaming\Adobe

2015-10-08 09:38 - 2015-03-25 18:37 - 00000000 ____D C:\Users\user\AppData\Roaming\CometPlayer

2015-10-08 09:37 - 2015-04-06 16:39 - 00000000 ____D C:\Users\user\AppData\Local\Microsoft Games

2015-10-08 09:37 - 2015-03-25 18:36 - 00000000 ____D C:\Users\user\AppData\Local\Skype

2015-10-08 09:32 - 2015-03-25 18:47 - 00000000 ____D C:\Users\user\AppData\Local\Google

2015-10-08 09:31 - 2015-04-11 17:11 - 00000000 ____D C:\Users\user\AppData\Local\Apple Computer

2015-10-08 09:25 - 2015-04-11 17:09 - 00000000 ____D C:\ProgramData\Apple Computer

2015-10-08 09:25 - 2015-03-25 18:38 - 00000000 ____D C:\ProgramData\Adobe

2015-10-08 09:25 - 2015-03-25 18:36 - 00000000 ____D C:\ProgramData\Rising

2015-10-08 09:22 - 2015-03-26 04:30 - 00733230 _____ C:\Windows\WindowsUpdate.log

2015-10-01 08:50 - 2015-04-06 12:44 - 00000000 ____D C:\Program Files\HP

 

==================== Files in the root of some directories =======

 

2015-10-11 17:33 - 2015-10-11 17:33 - 0018944 ___SH () C:\Users\user\AppData\Roaming\Thumbs.db

2015-10-08 09:37 - 2015-10-08 09:37 - 0008654 _____ () C:\Users\user\AppData\Local\HELP_DECRYPT.HTML

2015-10-08 09:37 - 2015-10-08 09:37 - 0045880 _____ () C:\Users\user\AppData\Local\HELP_DECRYPT.PNG

2015-10-08 09:37 - 2015-10-08 09:37 - 0004270 _____ () C:\Users\user\AppData\Local\HELP_DECRYPT.TXT

2015-10-08 09:37 - 2015-10-08 09:37 - 0000296 _____ () C:\Users\user\AppData\Local\HELP_DECRYPT.URL

2015-10-08 09:25 - 2015-10-08 09:25 - 0008654 _____ () C:\ProgramData\HELP_DECRYPT.HTML

2015-10-08 09:25 - 2015-10-08 09:25 - 0045880 _____ () C:\ProgramData\HELP_DECRYPT.PNG

2015-10-08 09:25 - 2015-10-08 09:25 - 0004270 _____ () C:\ProgramData\HELP_DECRYPT.TXT

2015-10-08 09:25 - 2015-10-08 09:25 - 0000296 _____ () C:\ProgramData\HELP_DECRYPT.URL

2015-04-06 12:43 - 2015-04-06 13:03 - 0000794 _____ () C:\ProgramData\hpzinstall.log

 

Some files in TEMP:

====================

C:\Users\user\AppData\Local\Temp\candidiasis.dll

C:\Users\user\AppData\Local\Temp\KB00209041.exe

C:\Users\user\AppData\Local\Temp\{04DE4C18-3449-4443-A60C-5A4C7A67F531}.exe

C:\Users\user\AppData\Local\Temp\{B9F558C4-B202-4D89-9BE4-C3BD677B3058}.exe

 

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2015-10-11 12:20

 

==================== End of FRST.txt ============================

 

Additional.txt

Additional scan result of Farbar Recovery Scan Tool (x86) Version:11-10-2015 02

Ran by [removed] (2015-10-12 18:37:40)

Running from C:\Users\[removed]\Downloads

Microsoft Windows 7 Ultimate  (X86) (2015-03-25 15:32:58)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-2773704555-2083345569-1616236315-500 - Administrator - Disabled)

Guest (S-1-5-21-2773704555-2083345569-1616236315-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-2773704555-2083345569-1616236315-1005 - Limited - Enabled)

user (S-1-5-21-2773704555-2083345569-1616236315-1000 - Administrator - Enabled) => C:\Users\user

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden

7000E809a (Version: 140.0.000.000 - Hewlett-Packard) Hidden

7000E809a_eDocs (Version: 140.0.000.000 - Hewlett-Packard) Hidden

7000E809a_Help (Version: 1.00.0000 - Hewlett-Packard) Hidden

Adobe Acrobat X Professional - Arabic, Hebrew, French, Greek (HKLM\…\{AC76BA86-1037-0000-7760-000000000005}) (Version: 10.1.1 - Adobe Systems)

Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)

Adobe Creative Suite 6 Master Collection (HKLM\…\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)

Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)

Adobe Flash Player 16 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)

Adobe Help Manager (HKLM\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)

Adobe Reader XI (11.0.02) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.02 - Adobe Systems Incorporated)

Adobe Widget Browser (HKLM\…\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)

Apple Application Support (32-bit) (HKLM\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)

Apple Mobile Device Support (HKLM\…\{538227C6-C74B-4A74-99E1-2C0B4F9DA5E1}) (Version: 8.2.1.3 - Apple Inc.)

Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

Bing Bar (HKLM\…\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 5.0.1449.0 - Microsoft Corporation)

Bing Bar Platform (Version: 5.0.1449.0 - Microsoft Corporation) Hidden

BitTorrent (HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\BitTorrent) (Version: 7.9.5.41203 - BitTorrent Inc.)

bl (Version: 1.0.0 - Your Company Name) Hidden

Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)

BPDSoftware (Version: 140.0.000.000 - Hewlett-Packard) Hidden

BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden

BufferChm (Version: 140.0.213.000 - Hewlett-Packard) Hidden

DeviceDiscovery (Version: 140.0.213.000 - Hewlett-Packard) Hidden

Google Chrome (HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\…\Google Chrome) (Version: 38.0.2125.104 - Google Inc.)

GPBaseService2 (Version: 140.0.212.000 - Hewlett-Packard) Hidden

HP Customer Participation Program 14.0 (HKLM\…\HPExtendedCapabilities) (Version: 14.0 - HP)

HP Imaging Device Functions 14.0 (HKLM\…\HP Imaging Device Functions) (Version: 14.0 - HP)

HP Officejet 7000 E809a Series (HKLM\…\{44E1D9AA-2A0E-48B8-BA26-136C2149C8AD}) (Version: 14.0 - HP)

HP Smart Web Printing 4.60 (HKLM\…\HP Smart Web Printing) (Version: 4.60 - HP)

HP Solution Center 14.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)

HP Update (HKLM\…\{74DC0593-6BC6-4001-AD5F-D810AFB68D86}) (Version: 5.002.002.002 - Hewlett-Packard)

HPProductAssistant (Version: 140.0.213.000 - Hewlett-Packard) Hidden

HPSSupply (Version: 140.0.212.000 - Hewlett-Packard) Hidden

Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)

Intel(R) TV Wizard (HKLM\…\TVWiz) (Version:  - Intel Corporation)

iTunes (HKLM\…\{A3875CED-8B9B-47F5-9AB9-0C36DD2D8D18}) (Version: 12.2.0.145 - Apple Inc.)

Kernel for Word Evaluation ver 11.01.01 (HKLM\…\Kernel for Word  Evaluation ver_is1) (Version:  - Lepide Software Pvt.Ltd.)

MarketResearch (Version: 140.0.214.000 - Hewlett-Packard) Hidden

Media Player Codec Pack 4.3.9 (HKLM\…\Media Player - Codec Pack) (Version: 4.3.9 - Media Player Codec Pack)

Microsoft Office Enterprise 2007 (HKLM\…\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)

Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (HKLM\…\{90120000-00B2-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)

Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 3.0.40818.0 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Mozilla Firefox 41.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 41.0.1 (x86 en-US)) (Version: 41.0.1 - Mozilla)

MpcStar 5.4 (HKLM\…\MpcStar) (Version: 5.4 - www.mpcstar.com)

Network (Version: 140.0.215.000 - Hewlett-Packard) Hidden

Panda Cloud Cleaner (HKLM\…\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.0.107 - Panda Security)

Panda Devices Agent (Version: 1.03.05 - Panda Security) Hidden

Panda Devices Agent (Version: 1.06.00 - Panda Security) Hidden

Panda Free Antivirus (HKLM\…\Panda Universal Agent Endpoint) (Version: 16.00.01.0000 - Panda Security)

Panda Free Antivirus (Version: 8.03.00.0000 - Panda Security) Hidden

Panda Security Toolbar (HKLM\…\pandasecuritytb) (Version: 4.3.0.4 - Panda Security)

PDF Settings CS6 (Version: 11.0 - Adobe Systems Incorporated) Hidden

ph (Version: 1.0.0 - Your Company Name) Hidden

ProductContext (Version: 140.0.000.000 - Hewlett-Packard) Hidden

Rising Internet Security (HKLM\…\RIS) (Version: 23.01.37.15 - Beijing Rising Information Technology, Inc.)

Rising Software Deployment System (HKLM\…\RSD) (Version: 23.00.01.02 - Beijing Rising Information Technology, Inc.)

Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 14.0 - HP)

Skype™ 6.20 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)

SmartWebPrinting (Version: 140.0.213.000 - Hewlett-Packard) Hidden

SolutionCenter (Version: 140.0.214.000 - Hewlett-Packard) Hidden

SpyHunter 4 (HKLM\…\SpyHunter) (Version: 4.20.9.4533 - Enigma Software Group, LLC)

Status (Version: 140.0.256.000 - Hewlett-Packard) Hidden

Toolbox (Version: 140.0.428.000 - Hewlett-Packard) Hidden

TrayApp (Version: 140.0.213.000 - Hewlett-Packard) Hidden

WebReg (Version: 140.0.213.017 - Hewlett-Packard) Hidden

Windows Live ID Sign-in Assistant (HKLM\…\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)

WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\user\AppData\Local\Google\Chrome\Application\38.0.2125.104\delegate_execute.exe (Google Inc.)

CustomCLSID: HKU\S-1-5-21-2773704555-2083345569-1616236315-1000_Classes\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\InprocServer32 -> C:\Users\user\AppData\Local\AXWworks\mnrzezwd.dll => No File

 

==================== Restore Points =========================

 

12-10-2015 08:42:51 Windows Backup

 

==================== Hosts content: ==========================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2009-07-14 05:04 - 2009-06-11 00:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {53F83415-D4C3-4FD3-A17D-DA7AA0DC20DF} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-10-11] (Enigma Software Group USA, LLC.)

Task: {6A57BCDA-49DD-42C9-87B6-C3E33D51F4FB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

Task: {A1A0790F-AFF2-4742-9C79-7687B4379C9E} - System32\Tasks\AdobeAAMUpdater-1.0-user-PC-user => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

 

==================== Loaded Modules (Whitelisted) ==============

 

2015-10-01 08:50 - 2012-09-18 15:26 - 00169472 _____ () C:\Windows\System32\zlhp1020.dll

2015-10-01 08:50 - 2012-09-18 15:26 - 00059904 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\pphp1020.dll

2015-10-01 08:50 - 2012-09-18 15:26 - 02223104 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\suhp1020.dll

2015-10-01 08:50 - 2012-09-18 15:26 - 00949248 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\gchp1020.dll

2014-07-31 12:16 - 2014-07-31 12:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-05-15 16:27 - 2015-05-15 16:27 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2013-04-12 20:23 - 2013-04-12 20:23 - 00612664 _____ () C:\Program Files\Panda Security\Panda Security Protection\SQLite3.dll

2015-03-25 18:36 - 2008-09-16 20:18 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll

2015-09-04 02:28 - 2015-09-04 02:28 - 00055992 _____ () C:\Windows\System32\Codecs\UpdateChecker.exe

2015-10-12 08:02 - 2015-10-12 08:02 - 00011264 _____ () C:\Users\user\AppData\Local\Temp\nsv1A07.tmp\System.dll

2014-12-21 05:07 - 2014-12-21 05:07 - 00208415 _____ () C:\Windows\System32\Codecs\TrayMenu.exe

2015-10-01 08:50 - 2012-09-18 15:26 - 00532992 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\sdhp1020.dll

2012-09-23 20:43 - 2012-09-23 20:43 - 00313992 _____ () C:\Program Files\Adobe\Reader 11.0\Reader\sqlite.dll

2015-03-25 18:47 - 2014-10-10 05:03 - 01042760 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\38.0.2125.104\libglesv2.dll

2015-03-25 18:47 - 2014-10-10 05:03 - 00211272 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\38.0.2125.104\libegl.dll

2015-03-25 18:47 - 2014-10-10 05:04 - 08910664 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\38.0.2125.104\pdf.dll

2015-03-25 18:47 - 2014-10-10 05:03 - 01681224 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll

2006-10-26 13:56 - 2006-10-26 13:56 - 00757008 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-2773704555-2083345569-1616236315-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

DNS Servers: [removed] - [removed]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)

mpsdrv => Firewall Service is not running.

MpsSvc => Firewall Service is not running.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [{F7D3C2F3-EF7C-495C-81B4-7095FA8AD00D}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe

FirewallRules: [{76383DA1-54BF-4FA3-B8C2-D0A58E509DFD}] => (Allow) C:\Program Files\Rising\RIS\RavMonD.exe

FirewallRules: [{4028D460-6B47-41C1-B8C5-CBBDD5C50DDD}] => (Allow) C:\Program Files\Rising\RIS\RavMonD.exe

FirewallRules: [{9479B0E3-D395-4D1E-B32E-7A0A7CDD7A1B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe

FirewallRules: [{78B5D0C3-2754-432E-9F2E-077F4FC49DF7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe

FirewallRules: [TCP Query User{7EC146E6-3B2A-4F21-82AF-3D83A0058D8B}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe

FirewallRules: [UDP Query User{A7360FDB-30C7-4600-BA67-87F2F561A81B}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe

FirewallRules: [{9F297ABF-3B6F-4B84-8A85-0F2C0F6C792B}] => (Allow) E:\setup\hpznui01.exe

FirewallRules: [{570DF358-55A3-4131-A66B-A67B12A3AC46}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

FirewallRules: [{59F6F6AF-4E4B-4063-B143-1C31EAAB3FE5}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe

FirewallRules: [{6F422DE5-6F87-4F14-8F51-7B51FF877DF7}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposid01.exe

FirewallRules: [{51C67A7E-B9A4-46AB-9B17-FB2AB46D5A09}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe

FirewallRules: [{AC744909-0979-4E81-B390-D4E07E3A6185}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe

FirewallRules: [{65D10B07-F74B-4E16-AA97-4BBA1767A2EF}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe

FirewallRules: [{F7896F1E-6547-41E2-BD29-80F8A44FC5CB}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe

FirewallRules: [{C2370A04-B879-4DAA-A957-7E6EA3DF48C5}] => (Allow) C:\Program Files\HP\hp software update\hpwucli.exe

FirewallRules: [{554DF22D-B396-45ED-817B-1400390C8FDD}] => (Allow) C:\Program Files\HP\digital imaging\smart web printing\smartwebprintexe.exe

FirewallRules: [{908F7D33-AC57-49C0-8571-E4A792C97CB1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{1CA798F2-5209-4AA1-892D-F3A081210C42}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{53511300-05E6-4281-AB84-AF988BCFC36C}] => (Allow) C:\Program Files\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe

FirewallRules: [{B4645493-35A6-435B-99B2-91920E1237E2}] => (Allow) C:\Program Files\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe

FirewallRules: [{CBCE71DD-F4F0-40C5-8D20-2CA85546B983}] => (Allow) LPort=7935

FirewallRules: [{737A7311-D889-4F22-891A-8C499B2166B5}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{A9FCFEE0-B8EC-43AC-9D8F-DD63E0B82071}] => (Allow) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{AE4B9F78-F4D7-4796-84DD-5BC59EBA885D}] => (Allow) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{8E9182A2-37BA-4D03-B568-5D472FC7C749}] => (Allow) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{C59B6C1B-28D1-4095-9C33-465E38ED82D8}] => (Allow) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{9F8B212F-2C87-4F0A-9FF1-DD001E3FA5AD}] => (Allow) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{67CDD81D-6289-4BF2-90AF-0384B2910DCD}] => (Allow) C:\Users\user\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{532D5C85-AE97-4DD4-8186-8C11D50C7F88}] => (Allow) C:\Windows\explorer.exe

FirewallRules: [{056B90BA-AADA-4279-912C-F1FDD4BF270C}] => (Allow) C:\Windows\system32\rundll32.exe

 

==================== Faulty Device Manager Devices =============

 

Name: Teredo Tunneling Pseudo-Interface

Description: Microsoft Teredo Tunneling Adapter

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: Microsoft

Service: tunnel

Problem: : This device cannot start. (Code10)

Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.

On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

 

Name: Officejet 7000 E809a

Description: Officejet 7000 E809a

Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}

Manufacturer: HP

Service:

Problem: : This device is disabled. (Code 22)

Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

 

Could not list Devices. Check "winmgmt" service or repair WMI.

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (10/12/2015 08:11:06 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: PCloudCleaner.exe, version: 1.0.0.1533, time stamp: 0x00000000

Faulting module name: ntdll.dll, version: 6.1.7600.16385, time stamp: 0x4a5bdadb

Exception code: 0xc0000005

Fault offset: 0x00055d70

Faulting process id: 0x458

Faulting application start time: 0xPCloudCleaner.exe0

Faulting application path: PCloudCleaner.exe1

Faulting module path: PCloudCleaner.exe2

Report Id: PCloudCleaner.exe3

 

Error: (10/11/2015 07:03:53 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: PCloudCleaner.exe, version: 1.0.0.1533, time stamp: 0x00000000

Faulting module name: ntdll.dll, version: 6.1.7600.16385, time stamp: 0x4a5bdadb

Exception code: 0xc0000005

Fault offset: 0x00055b17

Faulting process id: 0x1554

Faulting application start time: 0xPCloudCleaner.exe0

Faulting application path: PCloudCleaner.exe1

Faulting module path: PCloudCleaner.exe2

Report Id: PCloudCleaner.exe3

 

Error: (10/11/2015 12:33:45 PM) (Source: SideBySide) (EventID: 59) (User: )

Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.

Invalid Xml syntax.

 

Error: (10/11/2015 12:27:47 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

 

Details:

AddLegacyDriverFiles: Unable to back up image of binary PSKMAD.

 

System Error:

The system cannot find the file specified.

.

 

Error: (10/08/2015 08:02:54 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: tmp477B.exe, version: 0.0.0.0, time stamp: 0x5612628b

Faulting module name: tmp477B.exe, version: 0.0.0.0, time stamp: 0x5612628b

Exception code: 0xc0000005

Fault offset: 0x0001ca90

Faulting process id: 0x25f0

Faulting application start time: 0xtmp477B.exe0

Faulting application path: tmp477B.exe1

Faulting module path: tmp477B.exe2

Report Id: tmp477B.exe3

 

Error: (10/08/2015 07:25:47 PM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program Explorer.EXE version 6.1.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

 

Process ID: 73c

 

Start Time: 01d101e5741e7c68

 

Termination Time: 921

 

Application Path: C:\Windows\Explorer.EXE

 

Report Id: 2f9200de-6dd9-11e5-aad4-9ad78d6de164

 

Error: (10/08/2015 12:45:45 PM) (Source: RasClient) (EventID: 20227) (User: )

Description: CoId={2700B1F4-09F4-4A32-85BE-8F967644EE14}: The user user-PC\user dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.

 

Error: (10/08/2015 09:22:00 AM) (Source: VSS) (EventID: 13) (User: )

Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied.

]

 

Error: (10/08/2015 09:21:55 AM) (Source: VSS) (EventID: 13) (User: )

Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied.

]

 

Error: (10/07/2015 07:14:51 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: tmp8BED.exe, version: 3.7.0.44, time stamp: 0x56143202

Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000

Exception code: 0xc0000005

Fault offset: 0x01b30000

Faulting process id: 0x3a0

Faulting application start time: 0xtmp8BED.exe0

Faulting application path: tmp8BED.exe1

Faulting module path: tmp8BED.exe2

Report Id: tmp8BED.exe3

 

 

System errors:

=============

Error: (10/12/2015 06:38:13 PM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 06:38:12 PM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:29:51 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:29:50 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:12:03 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:12:02 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:11:01 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:11:00 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:09:59 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

Error: (10/12/2015 10:09:58 AM) (Source: Disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk2\DR2.

 

 

CodeIntegrity:

===================================

  Date: 2015-10-11 17:02:42.958

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.20861_none_c2ed720c41436932\MsMpEng.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.938

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.20861_none_c2ed720c41436932\MsMpEng.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.918

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.20861_none_c2ed720c41436932\MsMpEng.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.908

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.20861_none_c2ed720c41436932\MpCmdRun.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.888

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.20861_none_c2ed720c41436932\MpCmdRun.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.818

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.20861_none_c2ed720c41436932\MpCmdRun.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.310

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.16750_none_c26da4e3281e9420\MsMpEng.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.290

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.16750_none_c26da4e3281e9420\MsMpEng.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:42.270

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.16750_none_c26da4e3281e9420\MsMpEng.exe because the set of per-page image hashes could not be found on the system.

 

  Date: 2015-10-11 17:02:41.968

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\WinSxS\x86_windows-defender-service_31bf3856ad364e35_6.2.9200.16750_none_c26da4e3281e9420\MpCmdRun.exe because the set of per-page image hashes could not be found on the system.

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz

Percentage of memory in use: 68%

Total physical RAM: 3062.24 MB

Available physical RAM: 972.94 MB

Total Virtual: 6120.7 MB

Available Virtual: 3228.02 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:66.76 GB) (Free:15.46 GB) NTFS ==>[drive with boot components (obtained from BCD)]

Drive d: (New Volume) (Fixed) (Total:195.31 GB) (Free:194.45 GB) NTFS

Drive e: () (Fixed) (Total:31.25 GB) (Free:1.31 GB) NTFS ==>[system with boot components (obtained from drive)]

Drive f: (New Volume) (Fixed) (Total:203.69 GB) (Free:105.8 GB) NTFS

Drive g: (KRT Second) (Fixed) (Total:39.06 GB) (Free:2.94 GB) NTFS

Drive h: (KRT Materials) (Fixed) (Total:39.06 GB) (Free:0.23 GB) NTFS

Drive i: (KRT Software) (Fixed) (Total:39.67 GB) (Free:0.73 GB) NTFS

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C3F3C3F3)

Partition 1: (Active) - (Size=31.3 GB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=39.1 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=39.1 GB) - (Type=07 NTFS)

Partition 4: (Not Active) - (Size=39.7 GB) - (Type=07 NTFS)

 

========================================================

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 681D2D95)

Partition 1: (Active) - (Size=66.8 GB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=195.3 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=203.7 GB) - (Type=07 NTFS)

 

==================== End of Addition.txt ============================

 

 

:welcome:

 

Let me tell you how you infected your computer and got yourself into this mess, your using P2P (File Sharing) your using BitTorrent to download all kinds of garbage to your PC. Almost 100% of files/programs downloaded via the torrents are infected. Look at the FRST Additions log under Firewall rules, BitTorrent has permission to to freely enter your PC bringing whatever it wants with it…NOT GOOD

 

You need to go to Programs and Features in the Control Panel and uninstall BitTorrent, if you disagree let me know and I will close this thread as I dont have the time or patience to help you only to see you get infected again.

 

 

 
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
  •  

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI