Hi. Just recently, I have noticed a few folders inside my user folder include files with the file extention *.crypto. In addition, the files have been converted to icon image files. Meaning, by double-clicking the file, it opens Windows Previewer, instead the actual file it should be, such as an exe file. I then saw a DecryptMyFiles.html. Opening this file gives me the directions to download BitCoin to get my files back. I did some research, and at first glance, I found that this is from the CryptoLocker virus, which is ransomware. Odd to say however, I have not seen any pop-up notices with a timer, which was the allotted time to payup before loosing your private key, like most websites have explained. I then saw on this forum that CryptoLocker has been dead for more than a year now. So I am not exactly sure which ransomware is on my PC. The only thing I could tell you, it looks like this virus continues to crypt more and more files as the PC is running. Therefore, I have shut down the computer, until I can get this resolved. I do have to admit however, I do have a geeksquad account, but they have not been successful in other things they have tried accomplishing. So if anyone of the techs here could help me out finding which type of ransomware is installed on my pc, maybe I could explain myself better to the idiotsquad, when I get a chance to drop-off my PC at BestBuy.
need help finding type of ransomware is installed on my PC [Closed]
19 min read
![]()
Ransomeware has become a major problem, most tech experts and the Government suggest not paying the ransom because it just makes these thieves more bolder to go out and infect more people, also, paying them is no guarantee you will get your files back, your dealing with thieves that could care less about you and more about money then can make off of you.
Do you have any of your files backed up to maybe and external drive or an online file backup service ?
The problem we are seeing is that as soon as one of our helpers in the malware removal community writes a program to get your files back its just a matter or time before the bad guys update there program and then the fix doesnt work. Your more than welcome to look around various malware removal forums for help, as of this date I dont see to much being posted to get your files back.
If you want to follow my instructions and give it a shot your more than welcome. First what I would do is run Malwarebytes Anti Malware to remove this infection so that it cant encrypt any more files, then I would try Shadow Explorer and see if you can export some of or all of your files back, its totally up to you if you want to try this
- Windows XP : Double click on the icon to run it.
- Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
- On the Dashboard click on Update Now
- Go to the Setting Tab
- Under Setting go to Detection and Protection
- Under PUP and PUM make sure both are set to show Treat Detections as Malware
- Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
- Then on the Dashboard click on Scan
- Make sure to select THREAT SCAN
- Then click on Scan
- When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
- Please paste the log back into this thread for review
- Exit Malwarebytes
- First right click on your desktop and select New Folder and name it something you will remember like Retrieved Files
- Right click on Shadow Explorer Setup and select RUN AS ADMINISTATOR to install.
- When Shadow Explorer opens
- Pick a date prior to the infection
- Click on your C: drive ( or whatever drive your documents are saved in )
- On the left click on Users
- Then on your Username
- Then click on Documents ( or whatever folder the documents that you want to retrieve are in )
- In that folder click on a document that you want to retrieve
- It will load in the pane on the right
- Right click on that file and select Export and export it to your new folder
- OR***** Right click on the Folder that you want to keep and select Export
- When your done retrieving the files that you want exit Shadow Explorer
Hi Ken,
I have completed the malwarebytes scan as instructed, which has found 2 Trojans. Down below is my scan….
However, I did not start the Shadow Explorer because if I assume correctly, you have not told me to click on Remove Threats.In addition, you have asked if I have a backup stored on an external hard drive. I am actually glad that you have asked this. Yes I do have a backup. However, this backup is from a Dell recovery that I created before formatting my hard drive, sometime last month. Therefore I am not sure if the virus came from the recovery image or this infection happened afterwards, and I am not sure how I could check these files, since these files can only be recovered through Dell Recovery software. I am actually wondering if there is a way to check this.
Anywho, here is my MBAM scan….
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 5/5/2016
Scan Time: 11:24 PM
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.05.05.05
Rootkit Database: v2016.04.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Bob's PC
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 338426
Time Elapsed: 4 min, 0 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 1
Trojan.Clicker.FMS, C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}, , [9faa6c666732e94de69367b1c340aa56],
Files: 1
Trojan.Clicker.FMS, C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\8afc49b02429a, , [9faa6c666732e94de69367b1c340aa56],
Physical Sectors: 0
(No malicious items detected)
(end)
Good Morning
That Dell Recovery will restore your system but you may lose all your files. The instructions i posted about Malwarebytes would have automatically removed those threats.
- Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Or you can fix it this way
- You can highlight one of the detections by left clicking on it.
- Then, right click on the highlighted detection, and select 'Check All Items'.
- Next, click 'Remove Selected'. That should remove them all
- Right click the aswMBR icon and select Run as Administrator
- XP users just Double Click it to run
- If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
- Click the Scan button to start scan.
- Select Quickscan on the dropdown list
- If you are asked to update the Avast Virus database please allow it to do so.
- The scan could take 20 minutes or more , please be patient and let it finish
- It will say Scan Finished when its done.
- When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
- Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
- Just keep the defaults as in the picture checkmarked
- Press Scan button.
- It will produce a log called FRST.txt in the same directory the tool is run from.
- Please copy and paste log back here.
- The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Ken, I completed the tasks that you have asked….
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-05-06 08:56:12
—————————–
08:56:12.467 OS Version: Windows x64 6.1.7601 Service Pack 1
08:56:12.467 Number of processors: 4 586 0x2A07
08:56:12.467 ComputerName: BOBSPC-PC UserName: Bob's PC
08:56:14.027 Initialize success
08:56:14.027 VM: initialized successfully
08:56:14.027 VM: Intel CPU supported
08:56:19.500 VM: supported disk I/O ataport.SYS
08:59:11.994 AVAST engine defs: 16050600
08:59:24.396 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
08:59:24.412 Disk 0 Vendor: WDC_WD10EZEX-00ER1A0 80.00A80 Size: 953869MB BusType: 3
08:59:24.458 VM: Disk 0 MBR read successfully
08:59:24.458 Disk 0 MBR scan
08:59:24.474 Disk 0 Windows 7 default MBR code
08:59:24.474 Disk 0 Partition 1 00 DE Dell Utility MSDOS5.0 39 MB offset 63
08:59:24.490 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 12542 MB offset 81920
08:59:24.490 Disk 0 Boot: NTFS code=1
08:59:24.490 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 941286 MB offset 25767936
08:59:24.505 Disk 0 scanning C:\Windows\system32\drivers
08:59:29.216 Service scanning
08:59:39.575 Modules scanning
08:59:39.575 Disk 0 trace - called modules:
08:59:39.590 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
08:59:39.590 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004d38060]
08:59:39.606 3 CLASSPNP.SYS[fffff8800191843f] -> nt!IofCallDriver -> [0xfffffa8004747520]
08:59:39.606 5 ACPI.sys[fffff88000f9f7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004749060]
08:59:41.057 AVAST engine scan C:\Windows
08:59:43.022 AVAST engine scan C:\Windows\system32
09:01:00.024 AVAST engine scan C:\Windows\system32\drivers
09:01:06.951 AVAST engine scan C:\Users\Bob's PC
09:04:47.145 AVAST engine scan C:\ProgramData
09:05:28.922 Disk 0 statistics 3892141/0/21 @ 6.77 MB/s
09:05:28.922 Scan finished successfully
09:29:37.135 Disk 0 MBR has been saved successfully to "C:\Users\Bob's PC\Downloads\MBR.dat"
09:29:37.135 The log file has been saved successfully to "C:\Users\Bob's PC\Downloads\aswMBR.txt"
..end..
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-05-2016 02
Ran by [removed] (administrator) on BOBSPC-PC (06-05-2016 09:34:21)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Webroot) C:\Program Files\Webroot\WRSA.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
(Akamai Technologies, Inc.) C:\Users\Bob's PC\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(Akamai Technologies, Inc.) C:\Users\Bob's PC\AppData\Local\Akamai\netsession_win.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10o_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [1802472 2011-01-25] ()
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Dell Registration] => C:\Program Files (x86)\System Registration\prodreg.exe /boot
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\…\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\…\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [873072 2016-04-23] (Webroot)
HKLM-x32\…\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1627032 2015-01-28] (Autodesk, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Run: [Akamai NetSession Interface] => C:\Users\Bob's PC\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-04-23]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-06-21]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-06-21]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{9E1B8B58-55FD-45BC-A6A9-7BD5334B4140}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/USCON/1
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/USCON/1
SearchScopes: HKLM -> DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKLM -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1653179536-2399911319-13676569-1000 -> DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll [2016-04-23] (Webroot)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2016-04-23] (Webroot)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-06-21] (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08] (Skype Technologies S.A.)
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll [2016-04-23] (Webroot)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2016-04-23] (Webroot)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-06-21] (Sun Microsystems, Inc.)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll [2016-04-23] (Webroot)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll [2016-04-23] (Webroot)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2010-05-13] (Skype Technologies)
FireFox:
========
FF Plugin: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll [2010-10-13] (Best Buy)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-06-21] (Sun Microsystems, Inc.)
FF Plugin-x32: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll [2010-10-13] (Best Buy)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2011-06-21] (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2016-04-18] [not signed]
Chrome:
=======
CHR HKLM-x32\…\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [873072 2016-04-23] (Webroot)
S2 0096361461457411mcinstcleanup; C:\Users\BOB'SP~1\AppData\Local\Temp\009636~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [117728 2016-04-23] (Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [54512 2016-04-23] (Webroot)
U0 SR; no ImagePath
U2 srservice; no ImagePath
U3 aswMBR; \??\C:\Users\BOB'SP~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\BOB'SP~1\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-06 09:34 - 2016-05-06 09:34 - 00022553 _____ C:\Users\Bob's PC\Downloads\FRST.txt
2016-05-06 09:33 - 2016-05-06 09:34 - 00000000 ____D C:\FRST
2016-05-06 09:32 - 2016-05-06 09:32 - 02379776 _____ (Farbar) C:\Users\Bob's PC\Downloads\FRST64.exe
2016-05-06 09:29 - 2016-05-06 09:29 - 00002315 _____ C:\Users\Bob's PC\Downloads\aswMBR.txt
2016-05-06 09:29 - 2016-05-06 09:29 - 00000512 _____ C:\Users\Bob's PC\Downloads\MBR.dat
2016-05-06 08:54 - 2016-05-06 08:54 - 05198336 _____ (AVAST Software) C:\Users\Bob's PC\Downloads\aswMBR.exe
2016-05-05 23:35 - 2016-05-05 23:35 - 00001253 _____ C:\Users\Bob's PC\Desktop\mbam-threats_5-5-2016.txt
2016-05-05 23:18 - 2016-05-05 23:20 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-05 23:18 - 2016-05-05 23:18 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-05-05 23:18 - 2016-05-05 23:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-05-05 23:18 - 2016-05-05 23:18 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-05-05 23:18 - 2016-05-05 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-05-05 23:18 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-05-05 23:18 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-05-05 23:18 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-05-03 00:41 - 2016-05-03 00:41 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Adobe.ExMan
2016-05-02 08:28 - 2016-05-02 08:28 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Autodesk
2016-05-02 08:28 - 2016-05-02 08:28 - 00000000 ____D C:\ProgramData\Autodesk
2016-05-01 04:17 - 2016-05-01 04:58 - 00000000 ____D C:\Autodesk
2016-05-01 04:15 - 2016-05-01 04:15 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Autodesk
2016-05-01 04:15 - 2016-05-01 04:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2016-05-01 04:13 - 2016-05-01 04:14 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Akamai
2016-05-01 04:13 - 2016-05-01 04:13 - 10697112 _____ (Autodesk, Inc.) C:\Users\Bob's PC\Downloads\AutodeskDownloadManagerSetup.exe
2016-05-01 04:13 - 2016-05-01 04:13 - 00000000 ____D C:\ProgramData\Applications
2016-04-29 03:51 - 2016-04-29 03:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2016-04-27 04:26 - 2016-04-27 04:26 - 00000000 ____D C:\Windows\SysWOW64\Dell
2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\Downloads\de_crypt_readme.html
2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\Desktop\de_crypt_readme.html
2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\de_crypt_readme.html
2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\Downloads\de_crypt_readme.txt
2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\Desktop\de_crypt_readme.txt
2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\de_crypt_readme.txt
2016-04-25 22:27 - 2016-04-25 22:27 - 00000003 _____ C:\ProgramData\20F08A29047C.dat
2016-04-23 19:33 - 2016-04-23 19:33 - 00000020 ___SH C:\Users\Bob's PC\ntuser.ini
2016-04-23 19:20 - 2016-04-25 22:31 - 00000000 ____D C:\Users\Bob's PC\AppData\LocalLow\LastPass
2016-04-23 19:20 - 2016-04-23 19:20 - 00054512 ____T (Webroot) C:\Windows\system32\Drivers\wrUrlFlt.sys
2016-04-23 19:20 - 2016-04-23 19:20 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\lptmp
2016-04-23 19:20 - 2016-04-23 19:20 - 00000000 ____D C:\Program Files\Common Files\Webroot
2016-04-23 19:19 - 2016-05-05 23:19 - 00000000 ____D C:\ProgramData\WRData
2016-04-23 19:19 - 2016-04-23 19:19 - 00181688 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2016-04-23 19:19 - 2016-04-23 19:19 - 00117728 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2016-04-23 19:19 - 2016-04-23 19:19 - 00117304 _____ (Webroot) C:\Windows\system32\WRusr.dll
2016-04-23 19:19 - 2016-04-23 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2016-04-23 19:19 - 2016-04-23 19:19 - 00000000 ____D C:\Program Files\Webroot
2016-04-23 14:21 - 2016-04-23 14:21 - 00000132 _____ C:\Users\Bob's PC\AppData\Roaming\Adobe Targa Format CS6 Prefs
2016-04-23 12:48 - 2016-05-01 02:20 - 00000000 ____D C:\Users\Bob's PC\AppData\LocalLow\Adobe
2016-04-21 12:08 - 2016-04-21 12:08 - 00000000 _____ C:\Windows\invcol.tmp
2016-04-21 11:50 - 2016-04-21 11:50 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2016-04-21 00:49 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.html.crypt
2016-04-21 00:49 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.txt.crypt
2016-04-21 00:49 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.vbs.crypt
2016-04-21 00:48 - 2016-04-21 00:48 - 00012834 _____ C:\Users\Default\# DECRYPT MY FILES #.html
2016-04-21 00:48 - 2016-04-21 00:48 - 00011382 _____ C:\Users\Default\# DECRYPT MY FILES #.txt
2016-04-21 00:48 - 2016-04-21 00:48 - 00000204 _____ C:\Users\Default\# DECRYPT MY FILES #.vbs
2016-04-21 00:16 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.html.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.html.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.txt.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.txt.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.vbs.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.vbs.crypt
2016-04-21 00:11 - 2016-04-21 00:11 - 00000000 _____ C:\Windows\magueys
2016-04-21 00:11 - 2016-04-21 00:11 - 00000000 _____ C:\Windows\carronade
2016-04-19 21:15 - 2016-04-29 20:20 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\ElevatedDiagnostics
2016-04-19 00:10 - 2016-04-19 00:10 - 00003510 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-BobsPC-PC-Bob's PC
2016-04-18 23:58 - 2016-04-19 00:07 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-04-18 23:54 - 2016-04-18 23:54 - 00000000 ____D C:\Windows\system32\Macromed
2016-04-18 23:54 - 2016-04-18 23:54 - 00000000 ____D C:\ProgramData\ALM
2016-04-18 23:52 - 2016-04-18 23:52 - 00002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2016-04-18 23:52 - 2016-04-18 23:52 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2016-04-18 23:52 - 2016-04-18 23:52 - 00002028 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2016-04-18 23:52 - 2016-04-18 23:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2016-04-18 23:50 - 2016-04-18 23:50 - 00001099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2016-04-18 23:49 - 2016-04-18 23:57 - 00000000 ____D C:\Program Files\Adobe
2016-04-18 23:48 - 2016-04-18 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Design and Web Premium CS6
2016-04-18 23:48 - 2016-04-18 23:48 - 00000999 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2016-04-18 23:48 - 2016-04-18 23:48 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-04-18 23:48 - 2016-04-18 23:48 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-04-18 23:46 - 2016-04-18 23:57 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-04-18 23:35 - 2016-04-18 23:35 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Macromedia
2016-04-18 23:34 - 2016-05-06 02:00 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Adobe
2016-04-18 19:35 - 2016-04-18 19:42 - 00000000 ____D C:\Users\Bob's PC\Desktop\Adobe CS6 Design and Web Premium
2016-04-18 17:07 - 2016-04-18 19:35 - 01043440 _____ (Adobe Systems Incorporated) C:\Users\Bob's PC\Downloads\DesignWebPremium_CS6_LS16.exe
2016-04-18 17:03 - 2016-04-18 17:03 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Best Buy pc app
2016-04-18 16:56 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2016-04-18 16:51 - 2016-04-23 19:27 - 00000000 __SHD C:\Users\Bob's PC\AppData\Roaming\{38D26692-2CEC-3862-9440-8DD6EEBE75A2}
2016-04-18 16:51 - 2016-04-18 16:51 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-04-18 16:51 - 2016-04-18 16:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-04-18 16:51 - 2016-04-18 16:51 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-04-18 16:51 - 2016-04-18 16:51 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-04-18 16:51 - 2016-04-18 16:51 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2016-04-18 16:51 - 2016-04-18 16:51 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2016-04-18 16:51 - 2016-04-18 16:51 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2016-04-18 16:51 - 2016-04-18 16:51 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2016-04-18 16:51 - 2016-04-18 16:51 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-04-18 16:51 - 2016-04-18 16:51 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2016-04-18 16:51 - 2016-04-18 16:51 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-04-18 16:51 - 2016-04-18 16:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2016-04-18 16:51 - 2016-04-18 16:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2016-04-18 16:51 - 2016-04-18 16:51 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2016-04-18 16:51 - 2016-04-18 16:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-04-18 16:51 - 2016-04-18 16:51 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-18 16:51 - 2016-04-18 16:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-04-18 16:49 - 2016-04-18 16:49 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2016-04-18 16:49 - 2016-04-18 16:49 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2016-04-18 16:48 - 2016-04-18 16:56 - 02077392 _____ (Microsoft Corporation) C:\Users\Bob's PC\Downloads\IE11-Windows6.1.exe
2016-04-18 00:52 - 2016-04-18 00:52 - 00000184 ___SH C:\MSSTBJ.CAT
2016-04-17 22:01 - 2016-04-25 22:38 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\VirtualStore
2016-04-17 22:01 - 2016-04-25 22:38 - 00000000 ____D C:\Users\Bob's PC
2016-04-17 22:01 - 2016-04-23 19:33 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\SoftThinks
2016-04-17 22:01 - 2016-04-19 00:07 - 00074792 _____ C:\Users\Bob's PC\AppData\Local\GDIPFONTCACHEV1.DAT
2016-04-17 22:01 - 2016-04-17 22:01 - 00001975 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
2016-04-17 22:01 - 2016-04-17 22:01 - 00000000 _SHDL C:\Users\Bob's PC\My Documents
2016-04-17 22:01 - 2016-04-17 22:01 - 00000000 _SHDL C:\Users\Bob's PC\Documents\My Videos
2016-04-17 22:01 - 2016-04-17 22:01 - 00000000 _SHDL C:\Users\Bob's PC\Documents\My Pictures
2016-04-17 22:01 - 2016-04-17 22:01 - 00000000 _SHDL C:\Users\Bob's PC\Documents\My Music
2016-04-17 22:01 - 2016-04-17 22:01 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Dell Edoc Viewer
2016-04-17 22:01 - 2010-11-21 02:16 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Media Center Programs
2016-04-17 21:47 - 2016-04-17 21:47 - 00000000 ____D C:\report
2016-04-17 21:15 - 2016-04-17 21:15 - 00000000 ____D C:\Users\Bob's PC\Downloads\Dell
2016-04-17 21:14 - 2016-04-17 21:14 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Roxio Burn
2016-04-17 21:09 - 2016-04-21 18:59 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Adobe
2016-04-17 21:04 - 2016-04-17 21:04 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Mozilla
2016-04-17 21:01 - 2016-04-17 21:01 - 00000398 _____ C:\Users\Bob's PC\Desktop\pc app.appref-ms
2016-04-17 21:01 - 2016-04-17 21:01 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy
2016-04-17 21:01 - 2016-04-17 21:01 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Dell
2016-04-17 21:00 - 2016-04-27 04:04 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Deployment
2016-04-17 21:00 - 2016-04-18 17:03 - 00001415 _____ C:\Users\Bob's PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-17 21:00 - 2016-04-17 21:00 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Roxio
2016-04-17 21:00 - 2016-04-17 21:00 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Leadertech
2016-04-17 21:00 - 2016-04-17 21:00 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Dell Touch Zone
2016-04-17 21:00 - 2016-04-17 21:00 - 00000000 ____D C:\Users\Bob's PC\AppData\Roaming\Dell
2016-04-17 21:00 - 2016-04-17 21:00 - 00000000 ____D C:\Users\Bob's PC\AppData\Local\Apps\2.0
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-05 23:18 - 2009-07-13 23:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-05 23:18 - 2009-07-13 23:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-05 23:17 - 2011-06-21 13:45 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2016-05-05 23:16 - 2011-06-21 14:18 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2016-05-05 23:16 - 2011-06-21 14:18 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2016-05-05 23:16 - 2009-07-14 00:13 - 00778150 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-05 23:16 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2016-05-05 23:13 - 2011-06-21 14:02 - 00000000 ____D C:\ProgramData\Sonic
2016-05-05 23:11 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-01 02:20 - 2011-06-21 13:59 - 00000000 ____D C:\ProgramData\Adobe
2016-04-27 04:26 - 2011-06-21 13:49 - 00000000 ____D C:\Program Files (x86)\Dell
2016-04-25 22:38 - 2011-06-21 13:47 - 00000000 ____D C:\ProgramData\Best Buy pc app
2016-04-23 19:33 - 2009-07-13 23:45 - 04942888 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-18 23:56 - 2011-06-21 13:59 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-04-18 23:46 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-04-18 17:49 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2016-04-18 16:59 - 2011-06-21 13:56 - 00000000 ____D C:\Program Files (x86)\McAfee
2016-04-18 16:59 - 2011-02-10 09:01 - 00000000 ____D C:\dell
2016-04-18 16:57 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-04-17 22:40 - 2011-06-21 13:56 - 00000000 ____D C:\ProgramData\McAfee
2016-04-17 21:53 - 2011-02-10 09:02 - 00000000 ____D C:\Windows\panther
==================== Files in the root of some directories =======
2016-04-23 14:21 - 2016-04-23 14:21 - 0000132 _____ () C:\Users\Bob's PC\AppData\Roaming\Adobe Targa Format CS6 Prefs
2016-04-25 22:27 - 2016-04-25 22:27 - 0000003 _____ () C:\ProgramData\20F08A29047C.dat
Files to move or delete:
====================
C:\ProgramData\20F08A29047C.dat
C:\Users\Default\# DECRYPT MY FILES #.vbs
Some files in TEMP:
====================
C:\Users\Bob's PC\AppData\Local\Temp\AcDeltree.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-28 00:41
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:06-05-2016 02
Ran by [removed] (2016-05-06 09:34:42)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2016-04-18 03:01:06)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1653179536-2399911319-13676569-500 - Administrator - Disabled)
Bob's PC (S-1-5-21-1653179536-2399911319-13676569-1000 - Administrator - Enabled) => C:\Users\Bob's PC
Guest (S-1-5-21-1653179536-2399911319-13676569-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Webroot SecureAnywhere (Enabled - Up to date) {4646A877-74EB-CD3B-8FDB-210DB94FA61A}
AS: Webroot SecureAnywhere (Enabled - Up to date) {FD274993-52D1-C2B5-B56B-1A7FC2C8ECA7}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.1 - Adobe Systems)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe CS6 Design and Web Premium (HKLM-x32\…\{402F6F2E-5683-491C-977D-0CA599A07CAF}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 10.2.153.1 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Reader X MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
Adobe Widget Browser (HKLM-x32\…\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Akamai NetSession Interface (HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Akamai) (Version: - Akamai Technologies, Inc)
Autodesk Download Manager (HKLM-x32\…\{EC92633C-8F08-470A-BCDF-3FE5FD778C8D}) (Version: 4.0.14.0 - Autodesk, Inc.)
Best Buy pc app (HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\48e4cff94f039634) (Version: 3.1.0.0 - Best Buy)
Best Buy pc app (Version: 3.1.0.0 - Best Buy) Hidden
Best Buy pc app (x32 Version: 3.1.0.0 - Best Buy) Hidden
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.50.4.0 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell MusicStage (HKLM-x32\…\{F336F89D-8C5A-432C-8EA9-DA19377AD591}) (Version: 1.4.162.0 - Fingertapps)
Dell PhotoStage (HKLM-x32\…\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.30 - ArcSoft)
Dell Product Registration (HKLM-x32\…\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.0.6 - Dell Inc.)
Dell Stage (HKLM-x32\…\{D770F4B4-C422-45D9-8CEE-1B4C66E68CA8}) (Version: 1.4.173.0 - Fingertapps)
Dell System Detect (HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\58d94f3ce2c27db0) (Version: 7.4.0.3 - Dell)
Dell VideoStage (HKLM-x32\…\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.1.1.1408 - CyberLink Corp.)
Dell VideoStage (x32 Version: 1.1.1.1408 - CyberLink Corp.) Hidden
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation)
Java(TM) 6 Update 24 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Java(TM) 6 Update 24 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Roxio Creator Starter (HKLM-x32\…\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Skype Toolbars (HKLM-x32\…\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.)
Skype™ 4.2 (HKLM-x32\…\{D103C4BA-F905-437A-8049-DB24763BBE36}) (Version: 4.2.169 - Skype Technologies S.A.)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Webroot SecureAnywhere (HKLM-x32\…\WRUNINST) (Version: 9.0.8.80 - Webroot)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1653179536-2399911319-13676569-1000_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32 -> C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\apds.dll => No File <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {41D93F6F-7225-41EC-A6D2-8622B1AE3C21} - System32\Tasks\AdobeAAMUpdater-1.0-BobsPC-PC-Bob's PC => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2011-06-21 15:18 - 2011-01-27 10:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-01-25 15:14 - 2011-01-25 15:14 - 01802472 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
2010-11-17 10:35 - 2010-11-17 10:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
2011-06-21 13:45 - 2011-08-18 10:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2011-01-25 15:14 - 2011-01-25 15:14 - 01534184 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
2011-01-25 15:10 - 2011-01-25 15:10 - 16124416 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\libumajin.dll
2011-01-25 15:10 - 2011-01-25 15:10 - 07938048 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll
2011-01-25 15:10 - 2011-01-25 15:10 - 02225664 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll
2010-11-24 22:44 - 2010-11-24 22:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\dell.com -> dell.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Bob's PC\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{5009E2B4-4437-41B8-AD01-A3B5444513AB}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{99F956EC-D429-4394-BA94-0AFDF77430B4}] => (Allow) c:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
FirewallRules: [{843D0F62-9B70-4320-8A7F-33A1B467B61F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{C9D9F5D7-06DD-4D5E-9D9D-8A446832EBBF}] => (Allow) LPort=2869
FirewallRules: [{288007FB-9486-45B5-B010-A758EC6FF57A}] => (Allow) LPort=1900
FirewallRules: [{CC07ABFC-5E84-42E0-AE91-3671E934AB3F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{1646524C-2DBE-4039-A6DD-B4AAA2760EEA}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [TCP Query User{27481BC7-146D-43BC-AE97-DE7F8A85CE2A}C:\users\bob's pc\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\bob's pc\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{DBC2E58D-2723-4F26-8CF1-91517AC945C9}C:\users\bob's pc\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\bob's pc\appdata\local\akamai\netsession_win.exe
==================== Restore Points =========================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/06/2016 02:22:37 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).
Error: (05/05/2016 11:13:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/03/2016 12:37:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17840, time stamp: 0x555fe1bb
Faulting module name: LPPlugin.dll_unloaded, version: 0.0.0.0, time stamp: 0x566edcc5
Exception code: 0xc0000005
Fault offset: 0x090cd000
Faulting process id: 0x23dc
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3
Error: (05/03/2016 12:00:02 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).
Error: (05/02/2016 10:25:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17840, time stamp: 0x555fe1bb
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0a0d0000
Faulting process id: 0x1cfc
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3
Error: (05/02/2016 12:00:01 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).
Error: (05/01/2016 04:15:02 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\msiexec.exe /V; Description = Installed Autodesk Download Manager; Error = 0x80070422).
Error: (05/01/2016 04:15:02 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\msiexec.exe /V; Description = Installed Autodesk Download Manager; Error = 0x80070422).
Error: (05/01/2016 01:46:59 AM) (Source: TOASTER.EXE) (EventID: 0) (User: )
Description: An Unhandled Exception occured.
Width and Height must be non-negative.
at System.Windows.Rect..ctor(Double x, Double y, Double width, Double height)
at Toaster.Core.AppBarFunctions.ABSetPos(ABEdge edge, Window appbarWindow)
at Toaster.Core.AppBarFunctions.RegisterInfo.WndProc(IntPtr hwnd, Int32 msg, IntPtr wParam, IntPtr lParam, Boolean& handled)
at System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr hwnd, Int32 msg, IntPtr wParam, IntPtr lParam, Boolean& handled)
at MS.Win32.HwndWrapper.WndProc(IntPtr hwnd, Int32 msg, IntPtr wParam, IntPtr lParam, Boolean& handled)
at MS.Win32.HwndSubclass.DispatcherCallbackOperation(Object o)
at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Boolean isSingleParameter)
at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error: (05/01/2016 12:00:02 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).
System errors:
=============
Error: (05/05/2016 11:17:14 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
Error: (05/01/2016 02:07:15 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:07:15 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:07:15 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:07:15 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:07:15 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:07:15 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:05:27 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:05:27 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (05/01/2016 02:05:27 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
Percentage of memory in use: 51%
Total physical RAM: 4008.63 MB
Available physical RAM: 1939.53 MB
Total Virtual: 8015.44 MB
Available Virtual: 5676.89 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:919.22 GB) (Free:756.79 GB) NTFS
Drive d: (Rosetta Stone) (CDROM) (Total:0.39 GB) (Free:0 GB) CDFS
Drive f: () (Removable) (Total:1.86 GB) (Free:1.83 GB) FAT
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E3C73E1F)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=12.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=919.2 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 1.9 GB) (Disk ID: 6F20736B)
No partition Table on disk 2.
Disk 2 is a removable device.
==================== End of Addition.txt ============================
Did you run Malwarebytes again and remove both those entries that it found ????
All our tools and scanners work better from the desktop in lieu of being buried in a folder, so go to your downloads folder and right click on FRST64 and select CUT, come back to the desktop and right click on a blank space and select PASTE
Here is a quick fix, make sure you download Fixlist to your desktop where FRST64 now resides or the fix wont work
Start CloseProcesses: CreateRestorePoint: HKLM-x32\…\Run: [] => [X] HKLM\…\Policies\Explorer: [NoViewOnDrive] 0 HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0 HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0 HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKLM\…\Policies\Explorer: [NoViewContextMenu] 0 HKLM\…\Policies\Explorer: [NoShellSearchButton] 0 HKLM\…\Policies\Explorer: [NoFind] 0 HKLM\…\Policies\Explorer: [NoFile] 0 HKLM\…\Policies\Explorer: [HideClock] 0 HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0 HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0 HKLM\…\Policies\Explorer: [NoSetFolders] 0 HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\…\Policies\Explorer: [NoSetTaskbar] 0 HKLM\…\Policies\Explorer: [NoDeletePrinter] 0 HKLM\…\Policies\Explorer: [NoDFSTab] 0 HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\…\Policies\Explorer: [NoLogoff] 0 HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0 HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\…\Policies\Explorer: [NoResolveSearch] 0 HKLM\…\Policies\Explorer: [NoSaveSettings] 0 HKLM\…\Policies\Explorer: [NoHardwareTab] 0 HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0 HKLM\…\Policies\Explorer: [NoDesktop] 0 HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0 HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0 HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0 HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0 HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [DisableCMD] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoFind] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoFile] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [HideClock] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0 HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0 HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0 CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION 2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\Downloads\de_crypt_readme.html 2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\Desktop\de_crypt_readme.html 2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\de_crypt_readme.html 2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\Downloads\de_crypt_readme.txt 2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\Desktop\de_crypt_readme.txt 2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\de_crypt_readme.txt 2016-04-21 00:49 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.html.crypt 2016-04-21 00:49 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.txt.crypt 2016-04-21 00:49 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.vbs.crypt 2016-04-21 00:48 - 2016-04-21 00:48 - 00012834 _____ C:\Users\Default\# DECRYPT MY FILES #.html 2016-04-21 00:48 - 2016-04-21 00:48 - 00011382 _____ C:\Users\Default\# DECRYPT MY FILES #.txt 2016-04-21 00:48 - 2016-04-21 00:48 - 00000204 _____ C:\Users\Default\# DECRYPT MY FILES #.vbs 2016-04-21 00:16 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.html.crypt 2016-04-21 00:16 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.html.crypt 2016-04-21 00:16 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.txt.crypt 2016-04-21 00:16 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.txt.crypt 2016-04-21 00:16 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.vbs.crypt 2016-04-21 00:16 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.vbs.crypt C:\Users\Default\# DECRYPT MY FILES #.vbs HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION EmptyTemp: End
Here is my fixlog
Fix result of Farbar Recovery Scan Tool (x64) Version:06-05-2016 03
Ran by [removed] (2016-05-07 02:45:36) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\…\Run: [] => [X]
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\Downloads\de_crypt_readme.html
2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\Desktop\de_crypt_readme.html
2016-04-25 22:38 - 2016-04-25 22:38 - 00003318 _____ C:\Users\Bob's PC\de_crypt_readme.html
2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\Downloads\de_crypt_readme.txt
2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\Desktop\de_crypt_readme.txt
2016-04-25 22:38 - 2016-04-25 22:38 - 00001641 _____ C:\Users\Bob's PC\de_crypt_readme.txt
2016-04-21 00:49 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.html.crypt
2016-04-21 00:49 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.txt.crypt
2016-04-21 00:49 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.vbs.crypt
2016-04-21 00:48 - 2016-04-21 00:48 - 00012834 _____ C:\Users\Default\# DECRYPT MY FILES #.html
2016-04-21 00:48 - 2016-04-21 00:48 - 00011382 _____ C:\Users\Default\# DECRYPT MY FILES #.txt
2016-04-21 00:48 - 2016-04-21 00:48 - 00000204 _____ C:\Users\Default\# DECRYPT MY FILES #.vbs
2016-04-21 00:16 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.html.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00012834 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.html.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.txt.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00011382 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.txt.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.vbs.crypt
2016-04-21 00:16 - 2016-04-25 22:38 - 00000204 _____ C:\Users\Bob's PC\# DECRYPT MY FILES #.vbs.crypt
C:\Users\Default\# DECRYPT MY FILES #.vbs
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION
EmptyTemp:
End
*****************
Processes closed successfully.
Error: (0) Failed to create a restore point.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktop => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
C:\Users\Bob's PC\Downloads\de_crypt_readme.html => moved successfully
C:\Users\Bob's PC\Desktop\de_crypt_readme.html => moved successfully
C:\Users\Bob's PC\de_crypt_readme.html => moved successfully
C:\Users\Bob's PC\Downloads\de_crypt_readme.txt => moved successfully
C:\Users\Bob's PC\Desktop\de_crypt_readme.txt => moved successfully
C:\Users\Bob's PC\de_crypt_readme.txt => moved successfully
C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.html.crypt => moved successfully
C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.txt.crypt => moved successfully
C:\Users\Bob's PC\Desktop\# DECRYPT MY FILES #.vbs.crypt => moved successfully
C:\Users\Default\# DECRYPT MY FILES #.html => moved successfully
C:\Users\Default\# DECRYPT MY FILES #.txt => moved successfully
C:\Users\Default\# DECRYPT MY FILES #.vbs => moved successfully
C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.html.crypt => moved successfully
C:\Users\Bob's PC\# DECRYPT MY FILES #.html.crypt => moved successfully
C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.txt.crypt => moved successfully
C:\Users\Bob's PC\# DECRYPT MY FILES #.txt.crypt => moved successfully
C:\Users\Bob's PC\Downloads\# DECRYPT MY FILES #.vbs.crypt => moved successfully
C:\Users\Bob's PC\# DECRYPT MY FILES #.vbs.crypt => moved successfully
"C:\Users\Default\# DECRYPT MY FILES #.vbs" => not found.
"HKU\.DEFAULT\Software\Classes\exefile" => key removed successfully
"HKU\.DEFAULT\Software\Classes\.exe" => key removed successfully
HKU\.DEFAULT\Software\Classes\exefile => key not found.
"HKU\S-1-5-19\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-19\Software\Classes\.exe" => key removed successfully
HKU\S-1-5-19\Software\Classes\exefile => key not found.
"HKU\S-1-5-20\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-20\Software\Classes\.exe" => key removed successfully
HKU\S-1-5-20\Software\Classes\exefile => key not found.
"HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\.exe" => key removed successfully
HKU\S-1-5-21-1653179536-2399911319-13676569-1000\Software\Classes\exefile => key not found.
EmptyTemp: => 1.4 GB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 02:45:44 ====
Lets do some more clean up
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool.
- Click on Scan.
- After the scan is complete click on "Clean"
- Confirm each time with Ok.
- Your computer will be rebooted automatically. A text file will open after the restart.
- Please post the content of that logfile with your next reply.
- You can find the logfile at C:\AdwCleaner[S1].txt as well.
- Download the one from Bleeping Computer
- Shut down your protection software now to avoid potential conflicts.
- Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
- The tool will open and start scanning your system.
- Please be patient as this can take a while to complete depending on your system's specifications.
- On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
- Post the contents of JRT.txt into your next message.
Hi Ken, I am sorry about the delay, but I was away this weekend with my mother. Nonetheless here are my 2 logs….
# AdwCleaner v5.115 - Logfile created 07/05/2016 at 10:22:49
# Updated 01/05/2016 by Xplode
# Database : 2016-05-04.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Bob's PC - BOBSPC-PC
# Running from : C:\Users\Bob's PC\Desktop\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\ProgramData\Best Buy pc app
[#] Folder Deleted : C:\ProgramData\Application Data\Best Buy pc app
[-] Folder Deleted : C:\Users\Bob's PC\AppData\Local\Best Buy pc app
***** [ Files ] *****
***** [ DLLs ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9A1A857D-41B0-4122-9DB2-B5A9B21DE0B2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A60671D2-CC17-4FDB-8CB7-87EFC561FB2C}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Best Buy pc app
***** [ Web browsers ] *****
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [1191 bytes] - [07/05/2016 10:22:49]
C:\AdwCleaner\AdwCleaner[S1].txt - [1218 bytes] - [07/05/2016 10:18:04]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1337 bytes] ##########
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 7 Home Premium x64
Ran by [removed] (Administrator) on Sun 05/08/2016 at 13:56:17.63
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 8
Successfully deleted: C:\Users\Bob's PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33RJEAD7 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Bob's PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DS7VE9T4 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Bob's PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TVR8BG5O (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Bob's PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UFFEPNPM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33RJEAD7 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DS7VE9T4 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TVR8BG5O (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UFFEPNPM (Temporary Internet Files Folder)
Registry: 1
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\0096361461457411mcinstcleanup (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 05/08/2016 at 13:57:08.88
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Not a problem, our moms come before removing malware
Been in and out all day myself
What I am trying to do is get you as clean as possible before you attempt to retrieve your files with Shadow Explorer. So far outside of some entries we removed with the FRST fix, I dont see anything removed related to Ransomware.
Let me ask you, are you still getting the popup asking for you to pay the ransom ??
This program should root it out if its still present
First do this
Open up Malwarebytes and go to the Quarantine folder and delete it all , on the Dashboard go to History > Quarantine and delete it all
Then…..
- Click on the Uninstall button.
- Click Yes when asked are you sure you want to uninstall.
- Both AdwCleaner.exe, its folder and all logs will be removed.
- Quit all programs that you may have started.
- Please disconnect any USB or external drives from the computer before you run this scan!
- For Windows Vista, Windows 7, 8 or 10 right-click on RogueKiller and select "Run as Administrator" to start the program.
- For Windows XP, double-click on RogueKiller to start the program.
- If the program has been blocked by malware, try to rename it to winlogon.exe, or change its file extension with .com (ex: Roguekiller.com)
- If a message pops up telling you your running the 32 bit version just click on "Run Anyway"
- The free version will not allow you to change any setting so just leave it all be.
- The scan is triggered with the Start Scan button. The scan does not modify your system.
- Wait until the Status box shows "Scan Finished"
- Click on "Report" and copy/paste the content of the Notepad into your next reply.
- The log should be found in RKreport[1].txt on your Desktop
- Exit/Close RogueKiller
Ken, before I continue, you have some questions I liked to answer.
Last question you wanted to know was if I am still receiving popups to pay for the ransom?
To make things clear, I have never mentioned that I was getting a pop-up. However, I did say, and I quoted from my first post…
"….Odd to say however, I have not seen any pop-up notices with a timer, which was the allotted time to payup before loosing your private key, like most websites have explained." Now if you are referring to if I still have the file which gives me the directions to what happened to my files, then that is different. When I came here with my original problem, I explained that I had gathered information that many of my folders where attacked. I had realized this after trying to install a legit program, which use to install Autodesk 3ds Max, but now it only loads an icon in Windows Previewer. Furthermore, Autodesk 3ds Max installation along with many other files came from a Dell Restoration extraction that is compressed on my external hard drive. The question now is, when did this virus originally occurred, so that we could know if it is safe to re-extract the backup from my external hard drive. Who knows. For all we know, I could of had this virus for over a year, and unless there is a safe way to extract the files from the external hard drive, the only possible thing left is to see if we can compare dates. For example, there is one folder where I see the files with the .crypt file extension dated as of April 25, 2016, and I think I ran the Dell File Recovery about a week or so prior to that, which I am hopping that means the virus is not installed on my backup. However, once again, I cannot see what is on the external hard drive because the backup files are highly compressed files. There is approximately 40 Gigs of data compressed into I believe 10 or so compressed files, which I do not think it even adds up to more than 1 GB in total.
I hope this clears things up, and I will be back sometime tomorrow with the scan results.
A few years back we had a nasty virus going around named VIRUT, what this did was to infect all .exe files on your system including the ones in the backup folder , so it infected all his programs. Prior to this he made a legit image of his system using Norton Ghost, when he got infected it infected Ghost as well. He posted because he said he was about to lose the rest of his hair because he had formatted and re installed windows 3 times and he was still infected, what he had done was to install windows with the infected Norton image.
Whether your back up is infected is hard to tell.
http://www.goodells.net/dellrestore/image.shtml
It looks like if you do this it will restore your system to its original state as to when you purchased the computer. You will most likely lose all your files and pics. When I asked you about backing up your files, I was referring to if you just backed up your Documents and Pictures to an external drive or a USB or maybe even to a online backup service.
I think at this point lets see what RogueKiller finds and we can fix bad entries if needed , if it comes back ok then we can attempt to retrieve your files with Shadow Explorer because it would be a shame if you where able to retrieve your files and then get them infected again.
Good Afternoon Ken. I did the RoqueKiller scan, and it did find 1 true infection and 2 suspicious infections. As for the external hard drive, Yes this is only files that I had backed up prior to formatting the hard drive. I have another USB that has the Operating System Recovery. Anywho, without further due, here is my report….
RogueKiller V12.1.6.0 [May 9 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Bob's PC [Administrator]
Started from : C:\Users\Bob's PC\Desktop\RogueKiller.exe
Mode : Scan – Date : 05/09/2016 12:15:55
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\0096361461457411mcinstcleanup (C:\Users\BOB'SP~1\AppData\Local\Temp\009636~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service) -> Found
[Tr.Rosena] (X64) HKEY_USERS\S-1-5-21-1653179536-2399911319-13676569-1000\Software\classes\clsid\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A} -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 1 ¤¤¤
[Suspicious.Path][File] C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [LNK@] C:\ProgramData\Best "C:\ProgramData\Best Buy pc app\Best Buy pc app.application" -> Found
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EZEX-00ER1A0 ATA Device +++++
— User —
[MBR] 4506ccd3b8c8d1eac5d5d38e5533819c
[BSP] 708358443681acec664041eb94712f97 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 81920 | Size: 12542 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 25767936 | Size: 941286 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK
+++++ PhysicalDrive1: Generic- Multi-Card USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
Open RogueKiller and under the registry check this and select Delete
[Tr.Rosena] (X64) HKEY_USERS\S-1-5-21-1653179536-2399911319-13676569-1000\Software\classes\clsid\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A} -> Found
Then go ahead and give Shadow Explorer a shot and lets see if you can get some of those files back
Hi Ken, I tried running Shadow Explorer, but it is empty. I then looked up in the manual's FAQ, and it says this….
Q: When I start ShadowExplorer it is entirely blank, what am I doing wrong?
A: There seems to be a problem with System Restore when TrueCrypt is beeing used. The problem persists only as long as a volume is mounted. Try to dismount the disk and restart ShadowExplorer. Another solution is to mount volumes as removable media (in TrueCrypt: Settings -> Preferences… -> Mount volumes as removable media (check) -> OK).
Does this mean I would have to boot from a Virtual OS? If so, how?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI