Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

My computer is infected


  • Please log in to reply

#1
Sunshine-cures

Sunshine-cures

    New Member

  • Member
  • Pip
  • 6 posts

My computer has been infected over the years somehow. The browser when i want to go to yahoo website it goes to hongkong yahoo and does not allow me to go to the yahoo in general. When i start google chrome i find a pop up first which i close and then it allows to open the browser. If i want to open a new tab it opens up on http://www.yeadesktop.com/ Firefox has has issues and does not work well. The computer slows down while i am using halfway.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-06-2017 01
Ran by WINDOW 7 (administrator) on WINDOW7-PC (17-06-2017 11:23:07)
Running from C:\Users\WINDOW 7\Desktop
Loaded Profiles: WINDOW 7 (Available Profiles: WINDOW 7 & Guest)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ARWSRVC.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCSECSVC.EXE
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE
() C:\Program Files\D-Link\DWA-123\ALPBCSVC.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\QUHLPSVC.EXE
() C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\REPRSVC.EXE
() C:\Program Files\UCBrowser\Application\UCService.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\Real\RealDownloader\downloader2.exe
(Hewlett-Packard Company) C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(BitTorrent, Inc.) C:\Program Files\uTorrent\uTorrent.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\onlinent.exe
() C:\Program Files\Business-in-a-Box 2016\BIBLauncher.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudPhotos.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple, Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\secd.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
() C:\Program Files\UCBrowser\Application\6.1.2716.5\UCAgent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Quick Heal Core UI] => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\strtupap.exe [181392 2016-07-23] (Quick Heal Technologies Ltd.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [352648 2016-12-15] (RealNetworks, Inc.)
HKLM\...\Run: [RealDownloader] => C:\Program Files\Real\RealDownloader\downloader2.exe [730864 2017-05-05] ()
HKLM\...\Run: [HPUsageTrackingLEDM] => C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [30264 2009-10-15] (Hewlett-Packard Company)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [267064 2017-05-09] (Apple Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-05-09] (Apple Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [uTorrent] => C:\Program Files\uTorrent\uTorrent.exe [399736 2013-03-18] (BitTorrent, Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [BIBLauncher] => C:\Program Files\Business-in-a-Box 2016\BIBLauncher.exe [3129712 2016-11-07] ()
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [iCloudPhotos] => C:\Program Files\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-03-16] (Apple Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [Windscribe] => C:\Program Files\Windscribe\Windscribe.exe
HKLM\...\Providers\jymv66na: C:\Program Files\Adobe\\local32spl.dll
Lsa: [Notification Packages] scecli C:\Windows\system32\ScSecAuth.Dll
ShellExecuteHooks: No Name - {D7563EE2-AA87-11E6-B5B6-64006A5CFC23} - C:\Users\WINDOW 7\AppData\Roaming\Mtetionqucult\Nemosh.dll -> No File
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  -> No File
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2012-11-16] (Tonec Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2016-12-15]
ShortcutTarget: RealTimes.lnk -> C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall LastPass RunOnce.lnk [2016-11-06]
ShortcutTarget: Uninstall LastPass RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{0D786AF9-991C-4775-BB8A-2EFC61D28272}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{30E4D2A3-3B53-45F1-B6CF-13716D5B8168}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131261821422668700&GUID=2179420A-EC42-4971-8F6E-CCF9CD3617B0
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131261821422668700&GUID=2179420A-EC42-4971-8F6E-CCF9CD3617B0
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://malaysia.msn.com/?rd=1&ucc=MY&dcc=MY&opt=0&ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3689701632-257498136-1677522028-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3689701632-257498136-1677522028-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2013-11-30] (Internet Download Manager, Tonec Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files\Real\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2016-11-11] (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-06-22] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-22] (Oracle Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137 [2017-06-16]
FF NetworkProxy: Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137 -> autoconfig_url", "data:text/javascript,%2F*windscribe*%2Ffunction%20FindProxyForURL(url%2C%20host)%20%7B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20if%20(isPlainHostName(host)%20%7C%7C%20%20shExpMatch(host%2C%20%22*.local%22)%20%7C%7C%20shExpMatch(host%2C%20%22*.int%22)%20%7C%7C%20shExpMatch(url%2C%20%22*%3A%2F%2Fapi.windscribe.com%2F*%22))%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20%22DIRECT%22%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20var%20lanIps%20%3D%20%2F(%5E127.)%7C(%5E192.168.)%7C(%5E10.)%7C(%5E172.1%5B6-9%5D.)%7C(%5E172.2%5B0-9%5D.)%7C(%5E172.3%5B0-1%5D.)%2F%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20if(lanIps.test(host))%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20%22DIRECT%22%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20if%20(url.substring(0%2C%205)%20%3D%3D%20'http%3A'%20%7C%7C%20url.substring(0%2C%206)%20%3D%3D%20'https%3A'%20%7C%7C%20url.substring(0%2C%204)%20%3D%3D%20'ftp%3A'%20%7C%7C%20url.substring(0%2C%203)%20%3D%3D%20'ws%3A')%20%7B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20%22HTTPS%20ext-start.windscribe.com%22%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%7D%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20'DIRECT'%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%7D"
FF NetworkProxy: Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137 -> type", 2
FF Extension: (Windscribe) - C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137\Extensions\@windscribeff.xpi [2017-06-09]
FF Extension: (Pin It button) - C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137\Extensions\[email protected] [2016-12-19]
FF Extension: (uBlock Origin) - C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137\Extensions\[email protected] [2017-05-16]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [not signed]
FF HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\WINDOW 7\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\WINDOW 7\AppData\Roaming\IDM\idmmzcc5 [2014-01-20] [not signed]
FF HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\WINDOW 7\AppData\Roaming\IDM\idmmzcc5
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-17] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-06-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-06-22] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @real.com/nppl3260;version=18.1.6.161 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2016-12-15] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=18.1.6.161 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2016-12-15] (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3689701632-257498136-1677522028-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\WINDOW 7\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-30] (Unity Technologies ApS)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-05-09]
 
Chrome: 
=======
CHR DefaultProfile: ChromeDefaultData
CHR NewTab: ChromeDefaultData ->  Not-active:"chrome-extension://kdkndgfoddphljphiagiedpopmhkkinn/stubby.html", Not-active:"chrome-extension://ppgplhcfmaadpnkmnkhgadmaekeldbnh/stubby.html", Not-active:"chrome-extension://lbapdklahcjljfincdglncfpdgfhckcf/stubby.html"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://srchnet.com/search/{searchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> {searchTerms}
CHR Profile: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-06-17] <==== ATTENTION
CHR Extension: (Google Docs) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-16]
CHR Extension: (Google Drive) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-16]
CHR Extension: (YouTube) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-16]
CHR Extension: (Tampermonkey) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-06-09]
CHR Extension: (Google Docs Offline) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-16]
CHR Extension: (PDFConverterHQ) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\kdkndgfoddphljphiagiedpopmhkkinn [2017-05-29]
CHR Extension: (MyScrapNook) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lbapdklahcjljfincdglncfpdgfhckcf [2017-05-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Search for Chrome) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pdmejgdbephapagdfiondmmepkbpchhg [2017-05-03]
CHR Extension: (Gmail) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-16]
CHR Extension: (Chrome Media Router) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-16]
CHR Extension: (TelevisionFanatic) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ppgplhcfmaadpnkmnkhgadmaekeldbnh [2017-05-27]
CHR Profile: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default [2017-06-03]
CHR Extension: (Google Slides) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-15]
CHR Extension: (Google Docs) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-15]
CHR Extension: (Google Drive) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-05]
CHR Extension: (YouTube) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-15]
CHR Extension: (Tampermonkey) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-02-15]
CHR Extension: (Adobe Acrobat) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-05]
CHR Extension: (Google Sheets) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-15]
CHR Extension: (Google Docs Offline) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-05]
CHR Extension: (IDM Integration Module) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2017-02-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-05]
CHR Extension: (Gmail) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-15]
CHR Extension: (Chrome Media Router) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-26]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2013-11-30]
CHR HKU\S-1-5-21-3689701632-257498136-1677522028-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\WINDOW~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-04-10]
CHR HKU\S-1-5-21-3689701632-257498136-1677522028-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx
 
Opera: 
=======
OPR Extension: (SaveFrom.net helper) - C:\Users\WINDOW 7\AppData\Roaming\Opera Software\Opera Stable\Extensions\npdpplbicnmpoigidfdjadamgfkilaak [2016-07-15]
OPR Extension: (Fast search) - C:\Users\WINDOW 7\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha [2016-12-14]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 arwsrvc; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\arwsrvc.exe [224400 2016-10-01] (Quick Heal Technologies Ltd.)
S4 Behavior Detection System; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\bdssvc.exe [34960 2016-09-26] (Quick Heal Technologies Ltd.)
S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [437880 2015-08-19] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413304 2015-08-19] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [839288 2015-08-19] (BlueStack Systems, Inc.)
R2 Core Mail Protection; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE [51344 2016-07-23] (Quick Heal Technologies Ltd.)
R2 Core Scanning Server; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE [237712 2016-10-12] (Quick Heal Technologies Ltd.)
S3 Core Scanning ServerEx; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE [237712 2016-10-12] (Quick Heal Technologies Ltd.)
R2 D-Link DWA-123_PBC_WPS; C:\Program Files\D-Link\DWA-123\ALPBCSVC.exe [61440 2010-08-16] () [File not signed]
S4 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-10-15] (HP) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [462048 2012-04-21] (Intel® Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [166720 2012-06-26] (Intel Corporation)
S4 Online Protection System; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\opssvc.exe [53904 2016-07-23] (Quick Heal Technologies Ltd.)
R2 Quick Update Service; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\quhlpsvc.exe [136848 2016-07-23] (Quick Heal Technologies Ltd.)
R2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [35104 2016-11-11] ()
R2 RealTimes Desktop Service; C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [987408 2016-12-15] (RealNetworks, Inc.)
R2 RepairService; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\reprsvc.exe [38016 2016-11-03] (Quick Heal Technologies Ltd.)
R2 ScanWscS; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE [289504 2016-07-12] (Quick Heal Technologies Ltd.)
R2 ScSecSvc; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ScSecSvc.exe [452752 2016-07-23] (Quick Heal Technologies Ltd.)
R2 UCBrowserSvc; C:\Program Files\UCBrowser\Application\UCService.exe [599440 2017-05-11] () <==== ATTENTION
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S2 GmSvc; C:\Program Files\LDSGameCenter\GmSvc.dll [X]
S2 Pherheght; C:\Program Files\Vigaghtlterk\atifespcontrols.dll [X]
S4 WsDrvInst; C:\Program Files\Wondershare\MobileTrans\DriverInstall.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ACWINLPT; C:\Windows\system32\ACWINLPT.SYS [4080 1999-05-20] () [File not signed]
R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwf.sys [12800 2013-03-22] ()
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
R3 arwflt; C:\Windows\System32\DRIVERS\arwflt.sys [71680 2016-09-29] (Quick Heal Technologies Ltd.)
R1 ASPI32; C:\Windows\system32\Drivers\ASPI32.sys [25244 2004-08-06] (Adaptec)
R3 atkldrvr; C:\Windows\System32\DRIVERS\atkldrvr.sys [45296 2016-05-02] (Quick Heal Technologies Ltd.)
S4 bdsflt; C:\Windows\System32\DRIVERS\bdsflt.sys [279000 2016-11-18] (Quick Heal Technologies Ltd.)
S4 bdsnm; C:\Windows\System32\DRIVERS\bdsnm.sys [30992 2016-09-26] (Quick Heal Technologies Ltd.)
R3 bsfs; C:\Windows\System32\DRIVERS\bsfs.sys [76984 2016-04-12] (Quick Heal Technologies Ltd.)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [132216 2015-08-19] (BlueStack Systems)
R2 catflt; C:\Windows\System32\DRIVERS\catflt.sys [127824 2016-09-22] (Quick Heal Technologies Ltd.)
R2 EMLSS; C:\Windows\System32\drivers\emltdi.sys [42608 2016-04-12] (Quick Heal Technologies Ltd.)
R1 ggc; C:\Windows\System32\DRIVERS\ggc.sys [74784 2016-09-22] (Quick Heal Technologies Ltd.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2016-12-14] (REALiX™)
R2 IntelHaxm; C:\Windows\System32\DRIVERS\IntelHaxm.sys [90632 2015-11-16] (Intel  Corporation)
R3 kbfltr; C:\Windows\System32\DRIVERS\kbfltr.sys [27144 2016-08-16] (Quick Heal Technologies Ltd.)
S3 llio; C:\Windows\system32\DRIVERS\llio.sys [69512 2016-04-12] (Quick Heal Technologies Ltd.)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-03] (Intel Corporation)
S0 mscank; C:\Windows\System32\DRIVERS\mscank.sys [45168 2016-04-12] (Quick Heal Technologies Ltd.)
R3 netr28u; C:\Windows\System32\DRIVERS\Dnetr28u.sys [1277504 2012-01-06] (Ralink Technology Corp.)
R0 PxHelp20; C:\Windows\System32\DRIVERS\PxHelp20.sys [20016 2003-10-28] (Sonic Solutions) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [721904 2013-07-11] () [File not signed]
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2016-04-21] (The OpenVPN Project)
R1 ucdrv; C:\Windows\System32\drivers:ucdrv-x86.sys [84370 ] (UC Web Inc.) <==== ATTENTION
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [15872 2009-07-14] (Microsoft Corporation)
R0 webssx; C:\Windows\System32\drivers\webssx.sys [71656 2016-08-18] (Quick Heal Technologies Ltd.)
R1 wsnf; C:\Windows\System32\DRIVERS\wsnf.sys [52584 2016-04-12] (Quick Heal Technologies Ltd.)
U1 aswbdisk; no ImagePath
S3 ComputerZ; \??\C:\Program Files\LuDaShi\ComputerZ.sys [X] <==== ATTENTION
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
NETSVC: HpSvc -> no filepath.
NETSVC: GmSvc -> C:\Program Files\LDSGameCenter\GmSvc.dll ==> No File
NETSVC: WpSvc -> no filepath.
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-17 11:25 - 2017-06-17 11:25 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Sunny Knee
2017-06-17 11:23 - 2017-06-17 11:25 - 00028159 _____ C:\Users\WINDOW 7\Desktop\FRST.txt
2017-06-17 11:22 - 2017-06-17 11:23 - 00000000 ____D C:\FRST
2017-06-17 11:13 - 2017-06-17 11:13 - 01777152 _____ (Farbar) C:\Users\WINDOW 7\Desktop\FRST.exe
2017-06-16 16:27 - 2017-06-16 16:27 - 00000000 ____D C:\Users\WINDOW 7\Desktop\downloaded
2017-06-16 16:06 - 2017-06-16 16:27 - 1293593107 _____ C:\Users\WINDOW 7\Downloads\ebooksharing-20170616T075918Z-002.zip
2017-06-16 15:41 - 2017-06-16 15:52 - 00000000 ____D C:\Users\WINDOW 7\Desktop\new list of ebooks telegram
2017-06-16 15:07 - 2017-06-16 15:07 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Telegram Ebooks
2017-06-16 12:51 - 2017-06-16 15:30 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Ebooks CDB
2017-06-16 12:51 - 2017-06-16 12:51 - 22249753 _____ C:\Users\WINDOW 7\Desktop\2 Ek Adabhut Jeevan Kahani - Part-2.pdf
2017-06-16 10:28 - 2017-06-16 10:28 - 00021970 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-15 at 11.33.55.ogg
2017-06-16 10:28 - 2017-06-16 10:28 - 00019414 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-16 at 10.27.30.ogg
2017-06-16 10:28 - 2017-06-16 10:28 - 00018133 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-16 at 10.27.22.ogg
2017-06-16 10:28 - 2017-06-16 10:28 - 00012444 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-16 at 10.27.17.ogg
2017-06-16 09:54 - 2017-06-16 09:54 - 00574071 _____ C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture (2).pdf
2017-06-16 09:54 - 2017-06-16 09:54 - 00574071 _____ C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture (1).pdf
2017-06-16 09:22 - 2017-06-16 09:22 - 00000000 ___HD C:\Users\WINDOW 7\ScStore
2017-06-15 15:27 - 2017-06-15 15:27 - 00068952 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Image 2017-06-12 at 16.20.18.jpeg
2017-06-14 23:03 - 2017-06-14 23:03 - 22249753 _____ C:\Users\WINDOW 7\Downloads\2 Ek Adabhut Jeevan Kahani - Part-2.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 20937480 _____ C:\Users\WINDOW 7\Downloads\1 Ek Adabhut Jeevan Kahani - Part-1.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 06226936 _____ C:\Users\WINDOW 7\Downloads\Small_Big_book_English_ebook.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 01493831 _____ C:\Users\WINDOW 7\Downloads\मधुमेह (Diabetes) (1).pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00872507 _____ C:\Users\WINDOW 7\Downloads\30 Most Convincing case.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00536823 _____ C:\Users\WINDOW 7\Downloads\Hindu_Rituals_Handbook-1.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00201119 _____ C:\Users\WINDOW 7\Downloads\your-invisible-power-genevieve-behrand.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00039438 _____ C:\Users\WINDOW 7\Downloads\Beyond Reincarnation - Experience Your Past Lives And Lives Between Live - Joe Slate.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 06848813 _____ C:\Users\WINDOW 7\Downloads\Aroma-Day1-Part1.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 03019961 _____ C:\Users\WINDOW 7\Downloads\common-yoga-protocol (1).pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 00795176 _____ C:\Users\WINDOW 7\Downloads\kundalini.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 00775662 _____ C:\Users\WINDOW 7\Downloads\kundalini-yoga- -meditation.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 00505759 _____ C:\Users\WINDOW 7\Downloads\EssentialOils.pdf
2017-06-14 22:53 - 2017-06-14 22:53 - 00092837 _____ C:\Users\WINDOW 7\Desktop\E-Ticket Print.pdf
2017-06-14 21:51 - 2017-06-14 21:51 - 00390985 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.16.mp4
2017-06-14 21:51 - 2017-06-14 21:51 - 00388610 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.23.mp4
2017-06-14 21:51 - 2017-06-14 21:51 - 00270433 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.08.mp4
2017-06-14 21:51 - 2017-06-14 21:51 - 00144085 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.18.mp4
2017-06-14 21:49 - 2017-06-14 21:49 - 00055990 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-14 at 21.23.27.ogg
2017-06-10 10:55 - 2017-06-10 10:55 - 09516337 _____ C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 07782641 _____ C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 07763216 _____ C:\Users\WINDOW 7\Downloads\Combine-Reiki-with-Other-Healing-Tools-1.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 05457572 _____ C:\Users\WINDOW 7\Downloads\LIVING-WITH-THE-HIMALAYAN-MASTERS.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04430087 _____ C:\Users\WINDOW 7\Downloads\Archangels-Glory (1).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04165895 _____ C:\Users\WINDOW 7\Downloads\Tarka Sangraha- Complete Version(1)-1-1.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04105063 _____ C:\Users\WINDOW 7\Downloads\Healing-Past-and-Future-with-Reiki.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04027046 _____ C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 03696848 _____ C:\Users\WINDOW 7\Downloads\Tantrik Siddhiya - Dr. N.D.Shrimali-Compressed
2017-06-10 10:55 - 2017-06-10 10:55 - 03307723 _____ C:\Users\WINDOW 7\Downloads\HINDI.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 02511588 _____ C:\Users\WINDOW 7\Downloads\GST-Book-in-Hindi.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01659786 _____ C:\Users\WINDOW 7\Downloads\4_5895753623568122179.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01493831 _____ C:\Users\WINDOW 7\Downloads\मधुमेह (Diabetes).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01214589 _____ C:\Users\WINDOW 7\Downloads\PowerOfPositiveThinking-1.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01176887 _____ C:\Users\WINDOW 7\Downloads\Discover_Atlantis -Diana Cooper.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01101719 _____ C:\Users\WINDOW 7\Downloads\सम्पूर्ण संविधान (हिंदी).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 00909555 _____ C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 00520037 _____ C:\Users\WINDOW 7\Downloads\The Sankhya Darshana.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 00182664 _____ C:\Users\WINDOW 7\Downloads\The Mantra Book - Way of The Prayer.pdf
2017-06-10 10:54 - 2017-06-10 10:54 - 06974235 _____ C:\Users\WINDOW 7\Downloads\Tatiana Sergantova - 365 Modelos de origami.pdf
2017-06-10 10:54 - 2017-06-10 10:54 - 01910834 _____ C:\Users\WINDOW 7\Downloads\russian kids origami.pdf
2017-06-09 13:48 - 2017-06-09 13:43 - 00207957 _____ C:\Users\WINDOW 7\Desktop\9th june.jpeg
2017-06-09 12:05 - 2017-06-09 12:05 - 49148880 _____ C:\Users\WINDOW 7\Downloads\veergatha.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 05773718 _____ C:\Users\WINDOW 7\Downloads\6nbt- Gautam Buddha by Leela George.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02890550 _____ C:\Users\WINDOW 7\Downloads\Autobiography-of-a-Yogi-by-Paramahansa-Yogananda.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02861323 _____ C:\Users\WINDOW 7\Downloads\Art of Living in English.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02423979 _____ C:\Users\WINDOW 7\Downloads\buddha_a_story_of_enlightenment.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02407590 _____ C:\Users\WINDOW 7\Downloads\Gst ready.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02216567 _____ C:\Users\WINDOW 7\Downloads\Bhagwad Gita.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02034812 _____ C:\Users\WINDOW 7\Downloads\Ashwin Sanghi - Chanakyas Chant.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 01553456 _____ C:\Users\WINDOW 7\Downloads\Bruce-H.-Lipton-The-Biology-of-Belief-Unleashing-the-Power-of-Consciousness-Matter-and-Miracles-epub-TKRG
2017-06-09 12:04 - 2017-06-09 12:04 - 01276464 _____ C:\Users\WINDOW 7\Downloads\Gregg-Braden-The-Divine-Matrix.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 00585264 _____ C:\Users\WINDOW 7\Downloads\Ayn_Rand-The_Virtue_of_Selfishness.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 00368157 _____ C:\Users\WINDOW 7\Downloads\bhagwad gita (1).pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 00087824 _____ C:\Users\WINDOW 7\Downloads\ayn-rand-introduction-to-objectivist-epistemology-pdf.pdf
2017-06-09 11:03 - 2017-06-09 11:03 - 14939764 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 10.02.37.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14939012 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 09.51.59.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14885376 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 09.53.13.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14506681 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-07 at 09.40.31.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14442816 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 10.03.12.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 00179607 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-03 at 10.46.43.ogg
2017-06-09 11:03 - 2017-06-09 11:03 - 00062685 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-03 at 10.46.49.ogg
2017-06-09 11:02 - 2017-06-09 11:02 - 18833237 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-07 at 10.03.47.mp4
2017-06-09 11:02 - 2017-06-09 11:02 - 14498364 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-07 at 09.41.04.mp4
2017-06-09 11:02 - 2017-06-09 11:02 - 01845719 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-05-31 at 14.53.09.mp4
2017-06-09 11:02 - 2017-06-09 11:02 - 00000000 ____D C:\Users\WINDOW 7\Downloads\Learn Sanskrit
2017-06-08 22:20 - 2017-06-08 22:20 - 01993473 _____ C:\Users\WINDOW 7\Downloads\Practicing the Power of Now - Eckhart Tolle.compressed
2017-06-08 22:19 - 2017-06-08 22:19 - 22416275 _____ C:\Users\WINDOW 7\Downloads\patricia-mercier-the-chakra-bible-1-ebook-pdf-collated-ocr.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 09516337 _____ C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue (1).pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 07782641 _____ C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue (1).pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 04027046 _____ C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue (1).pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03768242 _____ C:\Users\WINDOW 7\Downloads\CosmicOrderingSecret.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03450842 _____ C:\Users\WINDOW 7\Downloads\The-SecretinHindi.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03412782 _____ C:\Users\WINDOW 7\Downloads\2_5280892187146453252.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03176914 _____ C:\Users\WINDOW 7\Downloads\2_722597121924005935.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 01525760 _____ C:\Users\WINDOW 7\Downloads\awakening_the_third_eyethird-eye.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 00816177 _____ C:\Users\WINDOW 7\Downloads\Switchwords - How to Use One Word to Get What You Want.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 33059906 _____ C:\Users\WINDOW 7\Downloads\The Power - Rhonda Byrne.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 20278321 _____ C:\Users\WINDOW 7\Downloads\India Today(HINDI)_June 7,2017.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 12497326 _____ C:\Users\WINDOW 7\Downloads\Barbara Brennan Light Emerging - Journey of Personal Healing (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 05912404 _____ C:\Users\WINDOW 7\Downloads\7 Galactic Invocations.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 02134449 _____ C:\Users\WINDOW 7\Downloads\what-is-my-spirit-animal-ebook-091715-2 (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 01569001 _____ C:\Users\WINDOW 7\Downloads\2_5208872801137590600.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 01324912 _____ C:\Users\WINDOW 7\Downloads\You are the Healer (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00909555 _____ C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00861873 _____ C:\Users\WINDOW 7\Downloads\Angels of Abundance - Virtue, Doreen, Virtue, Grant (2).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00831392 _____ C:\Users\WINDOW 7\Downloads\UnStuck (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00723707 _____ C:\Users\WINDOW 7\Downloads\Healing-with-the-Angels--Doreen-Virtue (1).pdf
2017-06-08 22:17 - 2017-06-08 22:18 - 00784616 _____ C:\Users\WINDOW 7\Downloads\Hoof and Paw Crystal Grids for Animals bookletpdf1-1 (1).pdf
2017-06-08 22:17 - 2017-06-08 22:18 - 00037942 _____ C:\Users\WINDOW 7\Downloads\vedic-1.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 13622243 _____ C:\Users\WINDOW 7\Downloads\The Arcturian Corridor - Part I.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 12862714 _____ C:\Users\WINDOW 7\Downloads\Barbara Brennan - Hands of Light - Guide to Healing   through the Human Energy Field [OCR]-1.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 00034535 _____ C:\Users\WINDOW 7\Downloads\Switchwords-1-2.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 00034535 _____ C:\Users\WINDOW 7\Downloads\Switchwords-1.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 05398411 _____ C:\Users\WINDOW 7\Downloads\The_Magic.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 04730239 _____ C:\Users\WINDOW 7\Downloads\Hero_by_Rhonda_Byrne_2.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 03588479 _____ C:\Users\WINDOW 7\Downloads\05. Gyanamrit-May16
2017-06-08 22:16 - 2017-06-08 22:16 - 02510896 _____ C:\Users\WINDOW 7\Downloads\virtue_angels-of-abundancethird-eye.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00791237 _____ C:\Users\WINDOW 7\Downloads\Master-Key-System.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00575683 _____ C:\Users\WINDOW 7\Downloads\switchwords-2.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00575683 _____ C:\Users\WINDOW 7\Downloads\switchwords-1-1-1.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00575683 _____ C:\Users\WINDOW 7\Downloads\switchwords-1-1.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00351748 _____ C:\Users\WINDOW 7\Downloads\bhudha thoughts.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00109433 _____ C:\Users\WINDOW 7\Downloads\Switchword_pairs-.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00034535 _____ C:\Users\WINDOW 7\Downloads\Switchwords-3.pdf
2017-06-08 22:15 - 2017-06-08 22:16 - 01016838 _____ C:\Users\WINDOW 7\Downloads\Dying to Be Me - Anita Moorjani-2.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 08632861 _____ C:\Users\WINDOW 7\Downloads\The_Power_by_Rhonda_Byrne_-1.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 05639243 _____ C:\Users\WINDOW 7\Downloads\Infallible-Vedic-Remedies-Mantras-for-Common-Problems.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 03019961 _____ C:\Users\WINDOW 7\Downloads\common-yoga-protocol.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 02452561 _____ C:\Users\WINDOW 7\Downloads\ऐ मेरे स्कूल मुझे जरा फिर से तो बुलाना.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 00263819 _____ C:\Users\WINDOW 7\Downloads\karma.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 10661128 _____ C:\Users\WINDOW 7\Downloads\Osho's Biography.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03943668 _____ C:\Users\WINDOW 7\Downloads\Outliers.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03614228 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 4.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03573455 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 1.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03499862 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 5.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03238297 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 3.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03116569 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 2.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 00652841 _____ C:\Users\WINDOW 7\Downloads\Blink- The Power of Thinking Without Thinking.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 00595145 _____ C:\Users\WINDOW 7\Downloads\Ask And It Is Given.pdf
2017-06-08 22:13 - 2017-06-08 22:13 - 00551040 _____ C:\Users\WINDOW 7\Downloads\Reiki_Parents_ebook.pdf
2017-06-08 21:42 - 2017-06-08 21:42 - 00121668 _____ C:\Users\WINDOW 7\Downloads\AMBRIELS TRUTH AND CLARITY EMPOWERMENT.pdf
2017-06-08 21:40 - 2017-06-08 21:40 - 00110480 _____ C:\Users\WINDOW 7\Downloads\ARCHANGEL_URIELS_PEACE_AND_TRANQUILITY_EMPOWERMENT.pdf
2017-06-08 21:35 - 2017-06-08 21:35 - 00226717 _____ C:\Users\WINDOW 7\Downloads\cord cutting.pdf
2017-06-08 21:32 - 2017-06-08 21:32 - 00341430 _____ C:\Users\WINDOW 7\Downloads\archangel_uriels_peace_and_tranquility_empowerment_pdf.zip
2017-06-08 21:28 - 2017-06-08 21:38 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Angel Miracles
2017-06-08 11:18 - 2017-06-17 11:23 - 00001159 _____ C:\Users\WINDOW 7\Desktop\Mozilla Firefox.lnk
2017-06-06 22:13 - 2017-06-06 22:14 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Poonam
2017-06-06 15:50 - 2017-06-06 15:50 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Neetu Jain
2017-06-06 14:52 - 2017-06-06 14:52 - 00144599 _____ C:\Users\WINDOW 7\Desktop\june 6th &7th.jpeg
2017-06-06 13:18 - 2017-06-06 13:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2017-06-05 19:05 - 2017-06-05 19:05 - 01365040 _____ C:\Users\WINDOW 7\Downloads\How the use of Mobiles are Safe.pdf
2017-06-05 19:05 - 2017-06-05 19:05 - 00464940 _____ C:\Users\WINDOW 7\Downloads\ayurveda.pdf
2017-06-05 18:40 - 2017-06-05 18:40 - 00000000 ____D C:\Users\WINDOW 7\Desktop\MIT
2017-06-05 17:47 - 2017-06-05 18:43 - 1970658553 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170605T094150Z-001.zip
2017-06-05 17:47 - 2017-06-05 18:38 - 1744351568 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170605T094150Z-002.zip
2017-06-05 17:44 - 2017-06-05 17:47 - 00000000 ____D C:\Users\WINDOW 7\Downloads\Ebooks
2017-06-05 15:25 - 2017-06-05 15:25 - 00000000 ____D C:\Users\WINDOW 7\Desktop\New folder (2)
2017-06-04 16:09 - 2017-06-04 16:09 - 10468818 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T080849Z-001.zip
2017-06-04 16:03 - 2017-06-04 16:09 - 419605277 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T080149Z-001.zip
2017-06-04 15:24 - 2017-06-04 15:26 - 94656760 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T072420Z-001.zip
2017-06-04 14:48 - 2017-06-04 15:21 - 762120720 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064502Z-001.zip
2017-06-04 14:48 - 2017-06-04 15:20 - 752254831 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064204Z-001.zip
2017-06-04 14:47 - 2017-06-04 15:09 - 762120720 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064343Z-001.zip
2017-06-04 14:42 - 2017-06-04 14:43 - 49996378 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064228Z-001.zip
2017-05-31 11:53 - 2017-05-31 13:01 - 1988520908 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034647Z-001.zip
2017-05-31 11:53 - 2017-05-31 12:58 - 1745823693 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034647Z-002.zip
2017-05-31 11:53 - 2017-05-31 12:02 - 283608723 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034647Z-003.zip
2017-05-31 11:49 - 2017-05-31 12:17 - 617489909 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034722Z-001.zip
2017-05-30 15:50 - 2017-05-30 15:50 - 02011341 _____ C:\Users\WINDOW 7\Downloads\Mom2.zip
2017-05-28 07:24 - 2017-05-28 07:58 - 2023200948 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170527T231709Z-001.zip
2017-05-27 06:36 - 2017-05-27 06:36 - 00016219 _____ C:\ProgramData\P1210OS.HTM
2017-05-27 06:36 - 2012-08-31 09:49 - 00024772 _____ C:\ProgramData\P1210DEF.css
2017-05-27 06:31 - 2017-05-27 06:31 - 00000000 ____D C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2017-05-23 13:06 - 2017-05-23 13:06 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-05-23 13:06 - 2017-05-23 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-05-23 13:04 - 2017-05-23 13:06 - 00000000 ____D C:\Program Files\iTunes
2017-05-22 10:55 - 2017-05-22 10:55 - 00844364 _____ C:\Users\WINDOW 7\Downloads\IGR-Starter.exe
2017-05-22 10:55 - 2017-05-22 10:55 - 00000000 ____D C:\Users\WINDOW 7\InfoCenter
2017-05-21 13:22 - 2017-05-21 13:19 - 00361790 _____ C:\Users\WINDOW 7\Documents\Mercury II Energy Business Plan .pdf
2017-05-21 13:19 - 2017-05-21 13:19 - 00361790 _____ C:\Users\WINDOW 7\Downloads\Mercury II Energy Business Plan .pdf
2017-05-20 12:53 - 2017-05-20 12:53 - 00000000 ____D C:\Users\WINDOW 7\Documents\Audacity
2017-05-20 12:52 - 2017-05-20 14:59 - 00000000 ____D C:\Users\WINDOW 7\AppData\Roaming\audacity
2017-05-20 12:52 - 2017-05-20 12:52 - 00000977 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2017-05-20 12:52 - 2017-05-20 12:52 - 00000965 _____ C:\Users\Public\Desktop\Audacity.lnk
2017-05-20 12:52 - 2017-05-20 12:52 - 00000000 ____D C:\Users\WINDOW 7\AppData\Local\Audacity
2017-05-20 12:52 - 2017-05-20 12:52 - 00000000 ____D C:\Program Files\Audacity
2017-05-20 12:51 - 2017-05-20 13:12 - 27113272 _____ (Audacity Team ) C:\Users\WINDOW 7\Downloads\audacity-win-2.1.3 (1).exe
2017-05-19 19:12 - 2017-05-19 19:12 - 17163336 _____ (Nullsoft, Inc.) C:\Users\WINDOW 7\Downloads\winamp5666_full_all.exe
2017-05-19 19:08 - 2017-05-19 19:09 - 27113272 _____ (Audacity Team ) C:\Users\WINDOW 7\Downloads\audacity-win-2.1.3.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-17 11:23 - 2016-12-19 17:44 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-06-17 11:23 - 2016-12-19 17:44 - 00001159 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-06-17 11:23 - 2016-12-16 11:34 - 00000286 _____ C:\Windows\Tasks\UCBrowserUpdaterCore.job
2017-06-17 11:23 - 2016-12-14 17:42 - 00001168 _____ C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-06-17 11:23 - 2016-07-12 11:11 - 00002365 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-17 11:16 - 2013-03-18 18:46 - 00000000 ____D C:\Users\WINDOW 7\AppData\Roaming\uTorrent
2017-06-17 11:01 - 2016-12-14 07:45 - 00000450 _____ C:\Windows\Tasks\UCBrowserUpdater.job
2017-06-17 10:56 - 2009-07-14 12:34 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-17 10:56 - 2009-07-14 12:34 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-17 10:44 - 2016-12-14 18:44 - 00000468 _____ C:\Windows\Tasks\Quick Heal AntiMalware Scan.job
2017-06-17 10:43 - 2016-12-14 18:43 - 00000444 _____ C:\Windows\Tasks\Resume Quickup Download.job
2017-06-16 12:33 - 2015-09-24 16:06 - 00000000 ____D C:\Program Files\Opera
2017-06-16 09:42 - 2016-11-19 19:28 - 00000000 ____D C:\Users\WINDOW 7\AppData\LocalLow\Mozilla
2017-06-16 09:28 - 2010-11-21 05:01 - 00785302 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-16 09:28 - 2009-07-14 10:37 - 00000000 ____D C:\Windows\inf
2017-06-16 09:22 - 2016-06-22 13:55 - 00000147 _____ C:\HaxLogs.txt
2017-06-16 09:22 - 2013-01-19 05:18 - 00000000 ____D C:\Users\WINDOW 7
2017-06-16 09:21 - 2017-05-17 12:03 - 00000000 ____D C:\Program Files\Common Files\AV
2017-06-16 09:21 - 2016-12-14 07:38 - 00000000 ____D C:\ProgramData\AVAST Software
2017-06-16 09:21 - 2009-07-14 12:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-09 13:43 - 2014-03-04 11:27 - 00000000 ___RD C:\Users\WINDOW 7\Documents\Scanned Documents
2017-06-08 22:05 - 2017-03-03 16:32 - 00000000 ____D C:\Users\WINDOW 7\Desktop\zen meditation and quotes
2017-06-01 12:25 - 2016-06-15 01:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-05-23 13:05 - 2016-11-02 12:15 - 00000000 ____D C:\Program Files\iPod
2017-05-21 18:56 - 2014-09-17 10:47 - 00000000 ____D C:\Users\WINDOW 7\AppData\Local\CutePDF Writer
 
==================== Files in the root of some directories =======
 
2016-07-07 17:33 - 2016-11-06 19:32 - 21737496 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2014-12-06 02:06 - 2014-12-06 02:06 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{084A6DE9-C5C8-4FED-BE02-45C7A4F3378D}
2014-11-23 14:00 - 2014-11-23 14:00 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{177B100C-9E87-48BF-B92C-D8A112B2E015}
2014-11-25 02:06 - 2014-11-25 02:06 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{1A003A31-C889-4FAA-885C-2DD8D8D8D5F7}
2015-03-07 04:12 - 2015-03-07 04:12 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{289FFCA7-4223-4225-AB47-7271BE119FAB}
2015-02-02 02:05 - 2015-02-02 02:05 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{2D8C87EF-339A-462F-8D79-E51BD0DB68E6}
2014-10-06 12:59 - 2014-10-06 12:59 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{3228A5E7-EB34-4BEE-A760-1EDEF0A764E7}
2015-02-16 02:04 - 2015-02-16 02:04 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{415DB93F-D2D4-4D6F-8D92-9DFE60DE3F31}
2015-02-14 04:12 - 2015-02-14 04:12 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{6827031D-4081-4DD3-BB67-E5AD1D1CFB46}
2014-10-23 12:53 - 2014-10-23 12:53 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{7966CC61-2967-471F-945C-F452ACD138C5}
2014-10-27 12:53 - 2014-10-27 12:53 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{C87A1114-9CEF-466E-A429-DBE188985424}
2014-10-25 00:59 - 2014-10-25 00:59 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{D48CFC2C-0E28-4557-A095-1A64345029DC}
2016-04-21 16:20 - 2016-04-21 16:20 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-03-22 14:27 - 2013-03-22 14:27 - 0199976 _____ () C:\ProgramData\NCCD.log
2017-05-27 06:36 - 2012-08-31 09:49 - 0024772 _____ () C:\ProgramData\P1210DEF.css
2017-05-27 06:36 - 2017-05-27 06:36 - 0016219 _____ () C:\ProgramData\P1210OS.HTM
2017-05-27 06:36 - 2012-08-31 09:49 - 0002944 _____ () C:\ProgramData\P1210SIG.GIF
 
Some files in TEMP:
====================
2016-12-14 07:37 - 2016-12-14 07:37 - 17156848 _____ (IObit                                                       ) C:\Users\WINDOW 7\AppData\Local\Temp\7C80.tmp.exe
2015-09-24 16:53 - 2015-09-24 16:54 - 4236616 _____ (Google) C:\Users\WINDOW 7\AppData\Local\Temp\B21F.exe
2016-12-14 07:44 - 2016-12-14 07:45 - 53124496 _____ (UCWeb Inc.) C:\Users\WINDOW 7\AppData\Local\Temp\Browser_V5.7.16400.16_f_4730_(Build1611171340).exe
2016-12-14 07:47 - 2016-12-14 07:47 - 0308538 _____ (sunnyday                                                    ) C:\Users\WINDOW 7\AppData\Local\Temp\BSIJN7ZLHH.exe
2017-01-05 10:21 - 2017-01-05 10:21 - 7596123 _____ (SoftVipDownload) C:\Users\WINDOW 7\AppData\Local\Temp\EASEUS Data Recovery Wizard Professional v5.5.1 Final Full.exe
2016-12-14 07:45 - 2016-12-14 07:46 - 1107880 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\inst_buychannel_06.exe
2016-12-14 07:37 - 2016-12-14 07:37 - 10250125 _____ (                                                            ) C:\Users\WINDOW 7\AppData\Local\Temp\jg3.6.0.exe
2014-07-12 05:12 - 2014-07-12 05:12 - 0918952 _____ (Oracle Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
2014-07-28 13:15 - 2014-07-28 13:15 - 0918440 _____ (Oracle Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
2014-09-30 01:06 - 2014-12-23 05:27 - 0937896 _____ (Oracle Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
2016-12-15 14:06 - 2016-12-15 14:06 - 2458672 _____ (The OpenSSL Project, http://www.openssl.org/)C:\Users\WINDOW 7\AppData\Local\Temp\libeay32.dll
2015-04-02 00:20 - 2016-11-10 12:25 - 0186280 _____ (RealNetworks, Inc.) C:\Users\WINDOW 7\AppData\Local\Temp\lowproc.exe
2016-12-14 07:41 - 2016-12-14 07:46 - 48156456 _____ (www.ludashi.com) C:\Users\WINDOW 7\AppData\Local\Temp\ludashisetup.exe
2016-12-14 08:05 - 2016-12-14 08:05 - 0210840 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\mininewsrepair.exe
2016-12-15 14:06 - 2016-12-15 14:06 - 0970912 _____ (Microsoft Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\msvcr120.dll
2015-09-24 16:03 - 2015-09-24 16:03 - 0724256 _____ (Opera Software) C:\Users\WINDOW 7\AppData\Local\Temp\Opera_NI_stable.exe
2014-11-08 16:33 - 2015-05-21 21:04 - 0610816 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\Quarantine.exe
2016-12-14 07:40 - 2016-12-11 23:26 - 1160549 _____ (                                                            ) C:\Users\WINDOW 7\AppData\Local\Temp\setup.exe
2016-12-15 14:06 - 2016-12-15 14:06 - 0772672 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\sqlite3.dll
2015-04-02 00:20 - 2016-11-10 12:25 - 0096496 _____ (RealNetworks, Inc.) C:\Users\WINDOW 7\AppData\Local\Temp\stubhelper.dll
2015-02-19 17:08 - 2015-02-19 17:10 - 12684696 _____ (                                                            ) C:\Users\WINDOW 7\AppData\Local\Temp\UmmyVideoDownloader.exe
2014-09-06 09:52 - 2014-09-06 09:53 - 24743106 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\vlc-2.1.5-win32.exe
2006-05-24 13:10 - 2006-05-24 13:10 - 0455600 ____R (Macrovision Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\_isA9B6.exe
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\Drivers\baa8764732b1925675da2f885b26b9b6.sys
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-06-13 20:42
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-06-2017 01
Ran by WINDOW 7 (17-06-2017 11:26:10)
Running from C:\Users\WINDOW 7\Desktop
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) (2013-01-18 21:18:26)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3689701632-257498136-1677522028-500 - Administrator - Disabled)
Guest (S-1-5-21-3689701632-257498136-1677522028-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-3689701632-257498136-1677522028-1002 - Limited - Enabled)
WINDOW 7 (S-1-5-21-3689701632-257498136-1677522028-1000 - Administrator - Enabled) => C:\Users\WINDOW 7
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Quick Heal AntiVirus Pro (Disabled - Out of date) {60EE5BF4-3309-ABA7-3A00-C88B68B340E6}
AS: Quick Heal AntiVirus Pro (Disabled - Up to date) {DB8FBA10-1533-A429-00B0-F3F913340A5B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Quick Heal Firewall (Enabled) {58D5DAD1-7966-AAFF-115F-61BE9660079D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKLM\...\uTorrent) (Version: 2.2.1 - )
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Flash Player 25 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{B9BA9CC8-B0A2-00C8-780E-B82A066E48C6}) (Version: 8.0.873.0 - Advanced Micro Devices, Inc.)
Any Video Converter Ultimate 4.5.8 (HKLM\...\Any Video Converter Ultimate_is1) (Version:  - Any-Video-Converter.com)
Apple Application Support (32-bit) (HKLM\...\{E92BB800-BCC5-4C25-8102-AC2C3B7C7C1E}) (Version: 5.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2A2C8640-5402-428A-909A-0236CB2B77C7}) (Version: 10.3.2.3 - Apple Inc.)
Apple Software Update (HKLM\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
ASUS Product Register Program (HKLM\...\{49BE9B8A-E858-4533-A74A-64306C13DB59}) (Version: 1.0.014 - ASUS)
Audacity 2.1.3 (HKLM\...\Audacity®_is1) (Version: 2.1.3 - Audacity Team)
BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.10.0.4321 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM\...\{473E82D7-79E2-43DF-8FA0-025407C93191}) (Version: 0.10.0.4321 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.)
Business-in-a-Box 2016 (HKLM\...\Business-in-a-Box 2016) (Version: 7.1.3 - Biztree Inc.)
calibre (HKLM\...\{2A795E68-BD67-40EC-899F-CEE817F723CF}) (Version: 0.8.68 - Kovid Goyal)
CD & DVD - Copy and Burn 1.0 (HKLM\...\CD & DVD - Copy and Burn_is1) (Version:  - )
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
CyberLink PowerDVD (HKLM\...\{6811AAC0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 1.00 - CyberLink)
D-Link DWA-123 (HKLM\...\{93D2C527-3C7F-4D25-8648-B5B681D16A39}) (Version:  - D-Link Corporation)
Dota 2 (HKLM\...\Steam App 570) (Version:  - Valve)
Dota 2 version 511 (HKLM\...\{11A02AEB-002F-43B2-AFD7-0D1DB406696B}_is1) (Version: 511 - Strogino CS Portal)
EASEUS Data Recovery Wizard Professional 5.5.1 (HKLM\...\EASEUS Data Recovery Wizard Professional 5.5.1_is1) (Version:  - EASEUS)
Energy Circle Creator (HKLM\...\Energy Circle Creator) (Version: 2.1 - Joe Miller)
Energy Circle Creator (Version: 2.1 - Joe Miller) Hidden
Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server UK) (Version: 2.0.1.13 - MAGIX AG)
Free Video to iPad Converter version 5.0.36.319 (HKLM\...\Free Video to iPad Converter_is1) (Version: 5.0.36.319 - DVDVideoSoft Ltd.)
Freemake Video Converter version 4.1.4 (HKLM\...\Freemake Video Converter_is1) (Version: 4.1.4 - Ellora Assets Corporation)
Google Chrome (HKLM\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Drive (HKLM\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.33.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HiDef Media Player 1.1.12 (HKLM\...\HiDef Media Player) (Version: 1.1.12 - HiDefMedia)
HP DeskJet 2130 series Basic Device Software (HKLM\...\{8BECF3A4-E3DF-4A75-BB74-C7A50443A019}) (Version: 35.0.61.54677 - Hewlett-Packard Co.)
HP DeskJet 2130 series Help (HKLM\...\{1CDFD3C9-BDF8-4DDC-BDA2-EBC53F938B5F}) (Version: 35.0.0 - Hewlett Packard)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version:  - )
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
hppLaserJetService (Version: 001.003.000145 - Hewlett-Packard) Hidden
hppM1130M1210SeriesLaserJetService (Version: 001.003.00073 - Hewlett-Packard) Hidden
hppusgM1130M1210Series (Version: 1.0.0.2 - Hewlett-Packard) Hidden
HPSSupply (HKLM\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.)
iCloud (HKLM\...\{B7BC92A8-B3E5-40A6-9B21-B25E4E1D98F1}) (Version: 6.2.2.39 - Apple Inc.)
Intel® Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel® Hardware Accelerated Execution Manager (HKLM\...\{30F3FF94-225B-4319-A13C-E307FFDA3CFB}) (Version: 6.0.1 - Intel Corporation)
Internet Download Manager (HKLM\...\Internet Download Manager) (Version:  - Tonec Inc.)
iTunes (HKLM\...\{28ECFB1B-6B8C-41D5-B5EF-87494A77C6C8}) (Version: 12.6.1.25 - Apple Inc.)
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 91 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Java SE Development Kit 8 Update 91 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0180910}) (Version: 8.0.910.15 - Oracle Corporation)
K-Lite Codec Pack 5.7.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 5.7.0 - )
Kundli - 2009 (C:\Program Files\Kun2009\) (HKLM\...\ST5UNST #2) (Version:  - )
Kundli - 2009 (HKLM\...\ST5UNST #1) (Version:  - )
Lame ACM MP3 Codec (HKLM\...\LameACM) (Version:  - )
LG Burning Tool (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.2.5218a - CyberLink Corp.)
LG Burning Tool (Version: 6.2.5218a - CyberLink Corp.) Hidden
LG CyberLink Media Suite (HKLM\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2808 - CyberLink Corp.)
LG CyberLink Media Suite (Version: 8.0.2808 - CyberLink Corp.) Hidden
MAGIX 3D Maker (embeded) (HKLM\...\MAGIX 3D Maker UK) (Version: 6.0.0.10 - MAGIX AG)
MAGIX Screenshare 4.3.6.1987 (UK) (HKLM\...\MAGIX Screenshare UK) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Xtreme PhotoStory on CD & DVD 8 deluxe Download version 8.0.3.2 (UK) (HKLM\...\MAGIX Xtreme PhotoStory on CD & DVD 8 deluxe Download version UK) (Version: 8.0.3.2 - MAGIX AG)
MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 53.0.3 (x86 en-GB) (HKLM\...\Mozilla Firefox 53.0.3 (x86 en-GB)) (Version: 53.0.3 - Mozilla)
Opera Stable 45.0.2552.898 (HKLM\...\Opera 45.0.2552.898) (Version: 45.0.2552.898 - Opera Software)
PDF to Word (HKLM\...\{E6CBC979-E613-49E6-A37B-3C342DE35235}_is1) (Version:  - Quick PDF)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Power Data Recovery 4.1.2 (HKLM\...\Power Data Recovery_is1) (Version:  - MT Solution Ltd.)
Product Improvement Study for HP DeskJet 2130 series (HKLM\...\{EFF29656-8F1A-4043-B2D0-9FB4619B45AF}) (Version: 35.0.61.54677 - Hewlett-Packard Co.)
Quick Heal AntiVirus Pro (HKLM\...\Quick Heal AntiVirus Pro) (Version: 17.00 - Quick Heal Technologies Ltd.)
Quick Heal AntiVirus Pro (Version: 17.00 - Quick Heal) Hidden
QuickTime 7 (HKLM\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RealDownloader (Version: 18.1.6.161 - RealNetworks, Inc.) Hidden
RealDownloader (Version: 18.1.6.167 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (RealTimes) (HKLM\...\RealPlayer 18.1) (Version: 18.1.6 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.52.203.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
StarBurn Version 12r10 (Build 0x20090901) (HKLM\...\StarBurn_is1) (Version:  - Rocket Division Software) <==== ATTENTION
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
System Requirements Lab Detection (HKLM\...\{A8738066-C8BD-4605-852B-5C9E48CFE1A6}) (Version: 2.2.4.0 - Husdawg, LLC)
UmmyVideoDownloader (HKLM\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.7.2.7 - ) <==== ATTENTION
Unity (HKLM\...\Unity) (Version: 4.5.5f1 - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS)
UpdateService (Version: 1.0.0 - RealNetworks, Inc.) Hidden
VBSE TOGETHER (HKLM\...\VBSE TOGETHER) (Version:  - EhDef.Com)
VBSE TOGETHER (Version: 2.3.3.2 - EhDef.Com) Hidden
vc2012_redist (Version: 1.0.0.0 - Realnetworks) Hidden
Video Downloader (Version: 1.3.0 - RealNetworks) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN)
vs2015_redist x86 (Version: 1.0.0.0 - Realnetworks) Hidden
Winamp (remove only) (HKLM\...\Winamp) (Version:  - )
WinRAR 5.40 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Wondershare Helper Compact 2.5.0 (HKLM\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.0 - Wondershare)
WOW (HKLM\...\{A7EC08D3-419E-4568-B59A-82D652450D48}) (Version:  - )
XviD MPEG-4 Video Codec (HKLM\...\XviD_is1) (Version: XviD-1.0.1-05062004 - XviD Team (Koepi))
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3689701632-257498136-1677522028-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\WINDOW 7\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-3689701632-257498136-1677522028-1000_Classes\CLSID\{5F387297-4BDB-48CD-8DB0-ACAD1415FABA}\InprocServer32 -> C:\Users\WINDOW 7\AppData\Local\Google\Update\1.3.21.129\psuser.dll => No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {034C3C28-3142-4944-82AF-2DE112F056B8} - System32\Tasks\f3bd7fee05edcde9a9d00fbc1dad42b7 => Rundll32.exe "C:\Program Files\KMSpico\ymv66n.dll",e62dc6c6547f46bda862da2d05af6862 <==== ATTENTION
Task: {035D8430-72A1-4D6B-A73A-F8DD7AE30964} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\system32\FlashPlayerUpdateService.exe
Task: {0A66697C-4B28-43AC-A039-C359D4924906} - System32\Tasks\HPCustParticipation HP DeskJet 2130 series => C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPCustPartic.exe [2015-04-09] (Hewlett-Packard Development Company, LP)
Task: {0C37554E-9371-4D91-BBDB-252ACD5F247E} - System32\Tasks\Driver Booster SkipUAC (WINDOW 7) => C:\Program Files\IObit\Driver Booster\4.1.0\DriverBooster.exe
Task: {10D6AB4A-B472-49BF-BBBC-C7D41FFC820D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.)
Task: {176199EB-4EDD-4C85-B133-D50BAABD6621} - System32\Tasks\UCBrowserSecureUpdater => C:\Program Files\UCBrowser\Security\uclauncher.exe [2017-03-09] (UC Web Inc.) <==== ATTENTION
Task: {17B3C514-BB24-41D4-BCA7-418A7695CCC2} - System32\Tasks\{2DA41284-D317-4B23-B824-780D33D15BC1} => pcalua.exe -a "C:\Users\WINDOW 7\Downloads\Interprt.exe" -d "C:\Users\WINDOW 7\Downloads"
Task: {224617D3-F322-4506-B879-F402FBB8C059} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\system32\FlashPlayerUpdateService.exe
Task: {25C5434B-6B68-4E8C-97C8-D1728C348829} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.)
Task: {2AAFF108-7C32-454C-9D47-29388C1849B0} - System32\Tasks\UCBrowserUpdater => C:\Program Files\UCBrowser\Application\update_task.exe [2017-05-11] (UCWeb Inc) <==== ATTENTION
Task: {35E924EB-FA5E-4560-AFEE-AF927C19822C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-17] (Adobe Systems Incorporated)
Task: {3CD69546-5203-45F1-B0F7-A0E54932C425} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {61F6A965-867E-40F4-A64B-68E074A73058} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3689701632-257498136-1677522028-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2016-11-11] (RealNetworks, Inc.)
Task: {6D0D4509-B310-44A7-A7AF-8161FDA3B410} - System32\Tasks\Quick Heal AntiMalware Scan => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ASMAIN.EXE [2016-07-23] (Quick Heal Technologies Ltd.)
Task: {6E54BCFF-64A1-4CD0-B62E-83BD4F099BBF} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2017-05-09] (Apple Inc.)
Task: {78E07B46-86FF-4CE0-A456-9C78E73E9250} - System32\Tasks\Microsoft\Windows\Multimedia\Manager => C:\Users\WINDOW 7\AppData\Roaming\Adobe\Manager.exe
Task: {82D035FF-073B-4346-B9CC-306A79CAF801} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.)
Task: {858B97EA-31D7-4428-AF89-0C285E7B3CDC} - System32\Tasks\{C8ABBBD3-42F6-4C00-B996-965D232B7EBD} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files\World of Wisdom\WOW\WOWAstro.exe"
Task: {A4F4337B-D7C4-4E1C-A7CD-8AF2BABB42CA} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3689701632-257498136-1677522028-1000 => C:\Program Files\Real\RealDownloader\recordingmanager.exe [2016-11-11] (RealNetworks, Inc.)
Task: {BAA7276C-C48C-4ECB-9238-5776EBF718C9} - System32\Tasks\RealDownloader Update Check => C:\Program Files\Real\RealDownloader\downloader2.exe [2017-05-05] ()
Task: {C0130B7E-B986-483F-B7B2-BC9018C7B04A} - System32\Tasks\{5E7004DA-55C2-4A71-AC11-15270F959049} => pcalua.exe -a G:\internalsw.exe -d G:\
Task: {C3D8D548-EDE6-4B5B-8E2A-6E8BDDEB200B} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3689701632-257498136-1677522028-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2016-11-11] (RealNetworks, Inc.)
Task: {C458F606-4046-4C5B-8DCC-F375A77D19B1} - System32\Tasks\UCBrowserUpdaterCore => C:\Program Files\UCBrowser\Application\update_task.exe [2017-05-11] (UCWeb Inc) <==== ATTENTION
Task: {CB30BA3B-92E1-46C0-A69C-939015ECFD66} - System32\Tasks\{31BBB5FD-E2B7-4A93-940F-552C6D7E00E2} => pcalua.exe -a "C:\Users\WINDOW 7\Downloads\Astrology softwares Updated\Parashara Light 7 Vedic Astrology+Crack\Parashara Light 7 Vedic Astrology+Crack\Parashara's Light 7 + Crack\Install PL7.exe" -d "C:\Users\WINDOW 7\Downloads\Astrology softwares Updated\Parashara Light 7 Vedic Astrology+Crack\Parashara Light (the data entry has 53 more characters).
Task: {E13D23A1-4BF1-45C6-B6D7-98AAEBF761B1} - System32\Tasks\{495D6E9B-284D-4024-A990-B6EF4F88545F} => pcalua.exe -a "C:\Program Files\Kun2009\Kun2009.exe" -d C:\PROGRA~1\Kun2009
Task: {E38DD6B8-A36D-4B3B-9091-08F33E9E64D1} - System32\Tasks\Opera scheduled Autoupdate 1443082045 => C:\Program Files\Opera\launcher.exe [2017-06-12] (Opera Software)
Task: {E76BF173-601D-4E19-A8BC-30803A6C3502} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3689701632-257498136-1677522028-1000 => C:\Program Files\Real\RealDownloader\RealUpgrade.exe [2016-11-11] (RealNetworks, Inc.)
Task: {E8189522-A6B8-4B98-9D97-205709CC6281} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3689701632-257498136-1677522028-1000 => C:\Program Files\Real\RealDownloader\RealUpgrade.exe [2016-11-11] (RealNetworks, Inc.)
Task: {ED4B1142-5959-471A-B2B3-0ADECAC7910A} - System32\Tasks\{80784319-CEB6-41D8-9322-D37BD05B3AA9} => pcalua.exe -a "C:\Users\WINDOW 7\Downloads\Programs\converter.exe" -d "C:\Users\WINDOW 7\AppData\Roaming\IDM"
Task: {F2CB568D-FACA-4037-AFF8-29F6C35D471F} - System32\Tasks\Resume Quickup Download => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ACAPPAA.EXE [2016-07-23] (Quick Heal Technologies Ltd.)
Task: {FEBB8FCB-C521-4E9C-BFED-40173168D66A} - System32\Tasks\360wp-srv => C:\Users\WINDOW 7\AppData\Roaming\360bizhi\360wpsrv.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Quick Heal AntiMalware Scan.job => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ASMAIN.EXE
Task: C:\Windows\Tasks\Resume Quickup Download.job => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ACAPPAA.EXE
Task: C:\Windows\Tasks\UCBrowserUpdater.job => C:\Program Files\UCBrowser\Application\update_task.exe <==== ATTENTION
Task: C:\Windows\Tasks\UCBrowserUpdaterCore.job => C:\Program Files\UCBrowser\Application\update_task.exe <==== ATTENTION
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
WMI_ActiveScriptEventConsumer_ASEC: <===== ATTENTION
 
Shortcut: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UmmyVideoDownloader\Help\ђусский.lnk -> C:\Users\WINDOW 7\AppData\Local\UmmyVideoDownloader\1.7.2.7\help\Ummy_rus.pdf () <===== Cyrillic
Shortcut: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kundli - 2009\Uninstall Kundli - 2009.lnk -> C:\Program Files\Kun2009\uninstal.bat ()
 
ShortcutWithArgument: C:\Users\WINDOW 7\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --load-extension="C:\Users\WINDOW~1\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --load-extension="C:\Users\WINDOW~1\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --load-extension="C:\Users\WINDOW~1\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yeadesktop.com/
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yeadesktop.com/
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-09-17 10:46 - 2013-10-23 14:23 - 00089136 _____ () C:\Windows\System32\cpwmon2k.dll
2017-05-04 14:12 - 2012-09-29 13:24 - 00167936 _____ () C:\Windows\System32\HPM1210LM.DLL
2017-05-04 14:14 - 2012-09-29 13:24 - 00069632 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\HPM1210PP.dll
2017-05-04 14:12 - 2012-09-29 13:24 - 02396160 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\hpm1210su.dll
2017-05-04 14:12 - 2012-09-29 13:54 - 00794624 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\HPM1210GC.dll
2017-05-09 00:45 - 2017-05-09 00:45 - 01041720 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 00080184 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-03-22 17:04 - 2010-08-16 15:51 - 00061440 _____ () C:\Program Files\D-Link\DWA-123\ALPBCSVC.exe
2013-03-22 17:04 - 2013-03-22 17:04 - 00073728 _____ () C:\Program Files\D-Link\DWA-123\ANPDApi.dll
2009-10-15 11:13 - 2009-10-15 11:13 - 00061440 _____ () C:\Program Files\HP\HPLaserJetService\HPTools.dll
2009-10-15 11:13 - 2009-10-15 11:13 - 00964096 _____ () C:\Program Files\HP\HPLaserJetService\LEDMXMLObjects.dll
2017-05-03 16:11 - 2012-11-08 11:00 - 00081920 _____ () C:\Windows\system32\mvusbews.DLL
2016-11-11 12:52 - 2016-11-11 12:52 - 00035104 _____ () C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
2016-11-11 12:52 - 2016-11-11 12:52 - 00040248 _____ () C:\Program Files\Real\UpdateService\DL2UpdatePlugin.dll
2016-11-11 12:52 - 2016-11-11 12:52 - 00042296 _____ () C:\Program Files\Real\UpdateService\RealDownloaderUpdatePlugin.dll
2016-11-11 12:52 - 2016-11-11 12:52 - 00039752 _____ () C:\Program Files\Real\UpdateService\VideoDLUpdatePlugin.dll
2016-12-14 07:45 - 2017-05-11 12:09 - 00599440 _____ () C:\Program Files\UCBrowser\Application\UCService.exe
2017-05-05 13:16 - 2017-05-05 13:16 - 00730864 _____ () C:\Program Files\Real\RealDownloader\downloader2.exe
2009-10-15 18:44 - 2009-10-15 18:44 - 00067128 _____ () C:\Program Files\HP\HP UT LEDM\bin\HPTools.dll
2009-10-15 18:44 - 2009-10-15 18:44 - 00075320 _____ () C:\Program Files\HP\HP UT LEDM\bin\HPToolkit.dll
2009-10-15 18:43 - 2009-10-15 18:43 - 00140856 _____ () C:\Program Files\HP\HP UT LEDM\bin\DMBaseObjects.dll
2009-10-15 18:43 - 2009-10-15 18:43 - 00240128 _____ () C:\Program Files\HP\HP UT LEDM\bin\LEDMMapperObjects.dll
2009-10-15 18:44 - 2009-10-15 18:44 - 00969784 _____ () C:\Program Files\HP\HP UT LEDM\bin\LEDMXMLObjects.dll
2017-05-09 03:06 - 2017-05-09 03:06 - 01041720 _____ () C:\Program Files\iTunes\libxml2.dll
2017-05-09 03:06 - 2017-05-09 03:06 - 00080184 _____ () C:\Program Files\iTunes\zlib1.dll
2017-05-09 00:44 - 2017-05-09 00:44 - 00189752 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
2016-07-04 19:45 - 2016-11-07 13:09 - 03129712 _____ () C:\Program Files\Business-in-a-Box 2016\BIBLauncher.exe
2016-12-15 09:02 - 2016-12-15 09:02 - 00101256 _____ () C:\Program Files\Real\RealPlayer\CrashRpt\CrashRpt1402.dll
2013-01-19 05:28 - 2012-06-26 02:41 - 01198912 _____ () C:\Program Files\Intel\Intel® Management Engine Components\UNS\ACE.dll
2017-05-17 13:16 - 2017-05-11 12:21 - 02150288 _____ () C:\Program Files\UCBrowser\Application\6.1.2716.5\UCAgent.exe
2017-05-11 07:26 - 2017-05-09 16:12 - 02864984 _____ () C:\Program Files\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
2017-05-11 07:26 - 2017-05-09 16:12 - 00087384 _____ () C:\Program Files\Google\Chrome\Application\58.0.3029.110\libegl.dll
2006-10-27 05:56 - 2006-10-27 05:56 - 00757008 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
2017-05-04 14:12 - 2012-09-29 13:24 - 00262144 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\hpm1210sd.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows\system32\drivers:ucdrv-x86.sys [84370]
AlternateDataStreams: C:\Windows\system32\drivers:x86 [1223458]
AlternateDataStreams: C:\ProgramData\Temp:BF3D62E7 [180]
AlternateDataStreams: C:\ProgramData\Temp:DBC416F8 [123]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\2 Ek Adabhut Jeevan Kahani - Part-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\9th june.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\9th june.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\june 6th &7th.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\june 6th &7th.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\june 6th.jpg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\june 6th.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\lion.jpg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\lion.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\spiral.jpg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\spiral.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\zigzag 14th june.jpg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\WINDOW 7\Desktop\zigzag 14th june.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(1)_five-point-someone-chetan-bhagat_ebook (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(1)_five-point-someone-chetan-bhagat_ebook.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(3)_3 Mistakes of my life - chetan bhagat.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(4)_Chetan_Bhagat_-_2_States_The_Story_of_My_Marriage.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(5)_Revolution 2020 - Chetan Bhagat.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(6)_Half Girlfriend - Chetan Bhagat.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(7)_One Indian Girl by Chetan Bhagat.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\(EBook -  NLP) Neuro Linguistic Programming WorkBook - Excellent!.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\-A SWITCHWORD LIST - from Kirthi.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\-Your word is your Wand.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\00000 Complete Prayer Book (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\00000 Complete Prayer Book.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\01-Wyckoff - Method of Tape Reading.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\012_6.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\014_Microsoft Word - Money and Success EFT Book.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\01EarlyCulturalWritings.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\02-Wyckoff - Method of Tape Reading (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\02-Wyckoff - Method of Tape Reading.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\06 Paul Brunton - The Ego; From Birth to Rebirth-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\067_Ek_Omkar_Satnam.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\08Karmayogin.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1 Ek Adabhut Jeevan Kahani - Part-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1-Child Development.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\10-Tips to handle students.ppt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\100-Kids-Lunch-Box-Recipes.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\101Helpful Hints for IELTS.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\109061003-Marma-Therapy.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1120.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\12906288-0-Your-Destiny-in-Numb.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\12EssaysDivineAndHuman.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\139530356-The-Power-of-Now-EckhartTolle.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\13EssaysInPhilosophyAndYoga.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\14-1300 Maths Formula.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1488023748095.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\15TheSecretOfTheVeda.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1653-leaders-born-made-pdf-download-laws_of_leadership_145.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\184915771-Celtic-Reiki-Level-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\184915789-Celtic-Reiki-Level-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\184915822-Celtic-Reiki-Master-Level-3.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\190912460-SSC-1-Healing-Cards-Sheet.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1Simran-2010 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\1Simran-2010.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\2 Ek Adabhut Jeevan Kahani - Part-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\2014-06-22-the-healing-codes-of-the-divine-mother.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\210338758-Celtic-Reiki-1-Manual.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\218375182-TheBookOfSigils.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\218377900-Ielts-Task-2-How-to-Write-at-a-9-Level.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\21971610-Massage-Therapy.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\21971610-Massage-Therapy.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\239430089-Five-Ways-to-Change-Your-Money-Situation-Now.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\245246004-Access-Bars-Headchart-pdf.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\251622445-Access-Bars-Guide.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\254870755-Big-Book-of-Angel-Tarot-The-Virtue-Doreen-Valentine-Radleigh.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\255303304-Angels-of-Abundance-Virtue-Doreen-Virtue-Grant (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\255303304-Angels-of-Abundance-Virtue-Doreen-Virtue-Grant.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\255999107-Angel-Dreams-Virtue-Doreen-Virtue-Melissa.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\278106725-Switchwords.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\2_5208872801137590600.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\2_5280892187146453252.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\2_722597121924005935.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\3-How students learn.ppt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\30 Most Convincing case.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\312280290-Angel-Detox-Doreen-Virtue-pdf.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\3487-transform-yourself-transform-others-ppt-download-transformational_leadership_668.ppt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\35609-wanna-leader-manager-find-ebooks-help-u-leadership-secrets-worlds-ceos.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\404selfimprovementtips.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\42828671-Vedanta-Yoga-Texts-Ramayana.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\4_5895753623568122179.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\59933491-365-Meditations-for-Men.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\5_6159138232387764237 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\5_6159138232387764237.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\6nbt- Gautam Buddha by Leela George.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7 Galactic Invocations.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7-Secrets-to-Blast-Belly-Fat-Fast.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7370084-Anatomy-And-Massage-Course-Notes.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7370084-Anatomy-And-Massage-Course-Notes.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7PATHS-09 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7PATHS-09 (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\7PATHS-09.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\8 Kinds of Writing 2nd Edition.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\80-Rules-to-solve-Sentence-Correction.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\83715724-SpiritofValentineAttunement.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\83715724-SpiritofValentineAttunement.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\9-A little child shall lead them-Johann Christoph Arnold.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A brief life-sketch of Hazur Baba Sawan Singh Ji Maharaj (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A brief life-sketch of Hazur Baba Sawan Singh Ji Maharaj (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A brief life-sketch of Hazur Baba Sawan Singh Ji Maharaj (3).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A brief life-sketch of Hazur Baba Sawan Singh Ji Maharaj.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A Dialogue With Oneself.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A Light To Yourself - Collected Works 10.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A Psychological Revolution - Collected Works 13.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A Wholly Different Way Of Living.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\A-Bus Express Sdn Bhd (Formerly known as Yoyo Worldwide Sdn Bhd).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Aatma-Bodha-Knowledge-of-self.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\accupressure points.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\act for children.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Action And Relationship.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Acuprressurefundamentals (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Acuprressurefundamentals (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Acuprressurefundamentals.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\After Shampoo Rinse.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Aini & Shahnaz compiled.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Aini & Shahnaz reports by sujit astrologer.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Amazing_Prediction__Know_Youself_.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\AMBRIELS TRUTH AND CLARITY EMPOWERMENT.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\An EVIL EYE or an EVIL SPELL.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\An Introduction to Communicating with Angels.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Anatomy and Massage Manual (1).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Anatomy and Massage Manual.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Anatomy and Massage Manual.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Anatomy-And-Massage-Course-Notes.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Miracles-lessons (1).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Miracles-lessons.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angel Miracles-lessons.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angels of Abundance - Virtue, Doreen, Virtue, Grant (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angels of Abundance - Virtue, Doreen, Virtue, Grant (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angels of Abundance - Virtue, Doreen, Virtue, Grant.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ank-Vidya-Jyotish.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ank.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\app_iss_ip_indmiss.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Archangels-Glory (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Archangels-Glory.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ARCHANGEL_URIELS_PEACE_AND_TRANQUILITY_EMPOWERMENT.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Aroma-Day1-Part1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Art of Living in English.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ARVIND RESUME (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ashiaana Form-beauty2 (1).doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ashiaana Form-beauty2 (Repaired).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ashiaana Form-beauty2.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ASHIANNA.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ashwin Sanghi - Chanakyas Chant.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ask And It Is Given.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Auspicious travel dates.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Autobiography-of-a-Yogi-by-Paramahansa-Yogananda.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\awakening_the_third_eyethird-eye.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ayn-rand-introduction-to-objectivist-epistemology-pdf.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ayn_Rand-The_Virtue_of_Selfishness.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ayurveda 1- 1.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ayurveda 1-2.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ayurveda.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ayurvedic_astrology.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Baba Jaimal Singh - Kirpal Singh (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Baba Jaimal Singh - Kirpal Singh.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bach flowers.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\BAFC234_M_info.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Barbara Brennan - Hands of Light - Guide to Healing   through the Human Energy Field [OCR]-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Barbara Brennan Light Emerging - Journey of Personal Healing (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Barbara Brennan Light Emerging - Journey of Personal Healing.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\become-healthy-or-extinct-by-darryl-dsouza.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bel_064_Shah.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bel_065_Sunny.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bel_066_ Uma.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Beyond Reincarnation - Experience Your Past Lives And Lives Between Live - Joe Slate.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bhagavad Gita - Radhakrishnan.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bhagavad Gita Dhyanam.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\bhagwad gita (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bhagwad Gita.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\bhav spashth.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\bhudha thoughts.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Birth Details.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Blind Horoscope.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Blink- The Power of Thinking Without Thinking.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Bonus 1 Affirmations For Entrepreneurs.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Brahmavidya.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\BROCCOLI QUICHE.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\buddha_a_story_of_enlightenment.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\burning the coin.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Cancer upaya.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\cannot connect.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\card of luck.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Certificate Template (1).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Certificate Template (2).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Certificate Template.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Certificate Template.docx.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Chakra 1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\chanakya-niti (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\chanakya-niti.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\CHANDRA.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Charaka Samhita (Acharya Charaka).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\CharlieChaplin_As_I_began_to_love_myself.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Charlotte.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Cheesy Cauliflower Patties.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Cheiro Ank-Jyotish.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Chicken Pepper Fry.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Choiceless-Awareness-by-Krishnamurti.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Clause.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\CLEAN YOUR KIDNEY IN LESS THAN P20.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Color Therapy.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Combine-Reiki-with-Other-Healing-Tools-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\common-yoga-protocol (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\common-yoga-protocol.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Complete English Grammar Rules_ - Peter Herring.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Complete-Works-of-Swami-Vivekananda.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\cord cutting.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Cosmic Awareness.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\CosmicOrderingSecret.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Creating Energy Circle Sandwiches.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\CrownofLife2012 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\CrownofLife2012.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Dale-Carnegie-How-to-win-friends-and-influence-people.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Dance Your Way to God.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Dear Shah.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Dear Sunny.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DengueFeverRemedy.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Destiny of Souls - New Case Studies of Life Between Lives.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\details astro.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Details expenses listing for AGM 2017.xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\diabetes and bhindi.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Discover_Atlantis -Diana Cooper.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Divine Healing Codes.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DL-B08 Iron Shirt Chi Kung III - Bone Marrow Nei Kung.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Doctor from Lhasa T Lobsang Rampa.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Doctors With Reiki_ Divine Healing Codes...pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\doctrate address.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DOC_HR_02_TRAINING_PLAN(1).xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Dr Arvinder Kaur.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DRAFTS 2013.07.25.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Durga Sapta Shloki.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Durga saptshati siddha mantra [ english].doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Durga Shapt shati  siddha mantra.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DurgaSaptashatEngExpl.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Dying to Be Me - Anita Moorjani-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DynamicPDF (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\DynamicPDF.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Eat_That_Frog.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Eclipse and mothers to be.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\edu-2011-spring-exam-apmv-formula.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\EE (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\EE.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Effective-Interviewing-A-Handbook-of-Skills-Techniques-and-Applications (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Effective-Interviewing-A-Handbook-of-Skills-Techniques-and-Applications.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Elixir.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\English Grammar.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\English Grammar_169.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\English Translation of Siri Guru Granth Sahib-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\english-grammar.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\error msg.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\EssentialOils.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Examination & Interview upaya.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\expirement 2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\EYESpecial.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\fabroid (1).txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\fabroid.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Feb 2017 Coverstory.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\find your stress questionaire.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\FNP PART-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\forex.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Form-yoga.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\GET IELTS BAND 9 - In Speaking Strategies and Band 9 ng Models-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\get_ielts_band_9_in_writing_task_1_data_charts_and_graphs.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Godman-2013 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Godman-2013 (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Godman-2013.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\GodPower (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\GodPower.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\gordonscott-101310.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Gregg-Braden-The-Divine-Matrix.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\GST for Finance ver 1 dt 24022017.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Gst ready.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\GST-Book-in-Hindi.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\GURU MESSAGE E-BOOK  by Gurdeep Singh -1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Guru-Charitra.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hand and Body Lotion.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hanuman Chalisa-1 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hanuman Chalisa-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hast-Rekha.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Heal Your Body.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Healing-Past-and-Future-with-Reiki.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Healing-with-the-Angels--Doreen-Virtue (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Healing-with-the-Angels--Doreen-Virtue.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\HealManual - Pendulum.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hero_by_Rhonda_Byrne_2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\HGLO (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\HGLO (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\HGLO (3).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\HGLO.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\hindi-buddhaandhisdhamma-baiae_japan-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\HINDI.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hindu_Rituals_Handbook-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Holistic Approach for disease free life.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hoof and Paw Crystal Grids for Animals bookletpdf1-1 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Hoof and Paw Crystal Grids for Animals bookletpdf1-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\How the use of Mobiles are Safe.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\How to meditate articles.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\How To Meditate Paramahansa Yogananda.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\IDEAS DEVELOPMENT.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Idioms & Phrases till CGL T1 2016.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\IELTS Made Easy- Step by Step guide to Task 2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\IELTS Speaking 2 - Lexical Resource.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\IELTS Task 2 essays by Aakash (Ryan_s Template).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\IELTS Writing- Coherence & Cohesion.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\India Today(HINDI)_June 7,2017.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Infallible-Vedic-Remedies-Mantras-for-Common-Problems.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Instructions on how to attend an Internet conference.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\invoice template.xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\JapJi-2013 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\JapJi-2013.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\jaspreet.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Jose Silva - The Silva Mind Control Method-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\journey.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kabir.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\karma.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\KATYAYANI.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kiran Akbar Dragon Reiki (1).doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kiran Akbar Dragon Reiki.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kiran Akbar.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Knee.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kriya Yoga - Synthesis of a Personal Experience Ennio Nimis.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kriya Yoga 01 Ennio Nimis.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kriya Yoga 02 Ennio Nimis.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Kriya Yoga 03 Ennio Nimis.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\kundalini-yoga- -meditation.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\kundalini.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\L&D Budget for Mfg.xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Lankavatara Sutra (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Lankavatara Sutra.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\leaderguide3532.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\LearningtheTarotin19lessons.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Lessons from the Titanic.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\lessontrainingplannercalculator.xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\LightKirpal.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Linda Goodman - Love Signs.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\lipton_biology-of-belief-10th-anniv.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\List of Tamil Books.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\LIVING-WITH-THE-HIMALAYAN-MASTERS.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Lokpal Bill, Hindi.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ManKnowThyself-2013.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\mary-k-greer-complete-book-of-tarot-reversals.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\master ielts.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Master-Key-System.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\MASTERCLASS.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Master_IELTS_Speaking.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\medical (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\medical.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\meditate-with-me-your-ebook-is-here.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Meditation Everywhere PSSM.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Meditation For Dummies (4th Edition 2016) by Stephan Bodian.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Meditation The First and Last Freedom.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\meditations.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Mental_Control_of_the_Body_-_Or,_Health_through_Se.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Mercury II Energy Business Plan .pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\messages from your angel.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Metspalu.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Mind And Memory Mastery (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Mind And Memory Mastery (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Mind And Memory Mastery.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Miracles Happen.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Morning.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Neelam Verma.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\New Doc.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Osho's Biography.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\osho-freedom-pdf (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\osho-freedom-pdf.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Outliers.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Oxford_Guide_to_English_Grammar-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 3.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 4.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 5.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\patricia-mercier-the-chakra-bible-1-ebook-pdf-collated-ocr.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Payment_Details (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Payment_Details.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Pendulum Dowsing - Day 4.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Pendulum Dowsing -Day 3.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Pendulum Dowsing lessons (final).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Positive Parenting-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\PowerOfPositiveThinking-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Pranayam - Kala Aur Vijnan.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Pranayama - The Art and Science.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Prayer-2010.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Projectforkangar.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\psychichealing.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\pyramid healing workshop batch 2 april 17 list (1).xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\pyramid healing workshop batch 2 april 17 list.xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\pyramid healing workshop list (1).xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\pyramid healing workshop list (2).xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\pyramid healing workshop list.xlsx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Pyramid Healing.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\REACH-TOGETHER - Self Help - Healing with Divine Numbers.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Reading General Academic.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\READING.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Realms of the Earth Angels - Doreen Virtue.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\RECEPTIVITY-2011.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Reiki_Parents_ebook.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\richard-bandler-get-the-life-you-want-the-secrets-to-quick-and-lasting-life-change-with-neuro-linguistic-programming.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ruhani.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\russian kids origami.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Sampuran-Ank-Jyotish.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Saral-Ank-Jyotish-Astrology.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\saral.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Schizophrenic.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Secrets of Nadi Astrology (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Secrets of Nadi Astrology.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\secrets-of-shamanism.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Shakuntala Devi__Book Of Numbers_2006.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Shiv Avataran-Hindi (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Shiv Avataran-Hindi.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Shiv Sandesh-hindi.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Shiva-Stotra-namavali.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\sigillenmagie in der praxis.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Simran-2010.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\skill matrix model.xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Skills_for_Higher_English_113.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Small_Big_book_English_ebook.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\SomePoojaSlokas.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\SoS.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Spirituality.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ss197107.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Statement_2017MTH03_271553354.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\STEP2KNOWINGYOUREWORTHYOFHAVINGIT.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\STEP4FEELINGGOODANDGRATEFUL.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\STEP5RECEIVINGTHROUGHRIGHTACTION.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\SuratShabdYoga.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\SURYA SYNERGIES LOGIN.doc:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Swami_Om_-_If_Truth_Be_Told_A_Monk_s_Memoir_2014_O_2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchwords (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\switchwords (2).docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchwords - How to Use One Word to Get What You Want.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\SWITCHWORDS DAILY.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\switchwords-1-1-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\switchwords-1-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchwords-1-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchwords-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\switchwords-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchwords-3.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchwords.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switchword_pairs-.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switch_energy (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Switch_energy.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Tarka Sangraha- Complete Version(1)-1-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Tatiana Sergantova - 365 Modelos de origami.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The Arcturian Corridor - Part I.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The Mantra Book - Way of The Prayer.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The Power - Rhonda Byrne.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\THE RETURN OF LIGHT.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The Sankhya Darshana.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The Truth About Angels.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\the-power-of-your-subconscious-mind.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The-SecretinHindi.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Theta Healing.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The_English_Teacher_s_Survival_Guide.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The_Fish_in_the_Sea_is_Not_Thirsty (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The_Magic.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\The_Power_by_Rhonda_Byrne_-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\think-and-grow-rich-chapter 01-workbook.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\think-and-grow-rich-chapter 02-  workbook.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ThinkandGrowRich (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ThinkandGrowRich (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ThinkandGrowRich (3).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ThinkandGrowRich.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Tips for becoming Emotionally Intelligent.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\TOKScombined.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Trainer Skills Checklist.xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Training Effective ness evaluation sheet.xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\TRAINING EFFECTIVENESS FORM.xls:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Training Need Analysis.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Ubuntu Linux.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Uma.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\UnStuck (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\UnStuck.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Untitled (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Untitled (2).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Untitled.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Upasana_Ke_Do_Charan_Jap_Aur_Dhyan.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\vedic-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\veergatha.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\VegetarianDiet-2013.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\vianna-stibal-theta-healing (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\vianna-stibal-theta-healing.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\virtue_angels-of-abundancethird-eye.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\WaySaints.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\What is Nadi-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\What is Nadi-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\what-is-my-spirit-animal-ebook-091715-2 (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\what-is-my-spirit-animal-ebook-091715-2.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\whomovedmycheese.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\WHY_DO_WE_TRAIN.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Wicca in the Kitchen.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\William Shakespeare - The Taming of the Shrew_144.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\wings-of-fire-by-abdul-kalam.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Winsome Wonder or Wise Women Flyer (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Winsome Wonder or Wise Women Flyer.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\wishing well.txt:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\WOL-MOD.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\word power easy.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\words can change your brain.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Wow photos (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Wow photos.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Yoga.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Yogi Kathamrita (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\Yogi Kathamrita.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\You are the Healer (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\You are the Healer.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\your-invisible-power-genevieve-behrand.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\zen meditation.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\zen meditation.docx.docx:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\zibu-the-power-of-angelic-symbology.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\_Return to Bliss_ live event with Aine Belton.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\ऐ मेरे स्कूल मुझे जरा फिर से तो बुलाना.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\पेट रोग और प्राकृतिक चिकित्सा-1.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\प्राचीन स्वास्थ्य दोहावली.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\मधुमेह (Diabetes) (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\मधुमेह (Diabetes).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\शरीर के कुछ सत्य (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\शरीर के कुछ सत्य.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\सम्पूर्ण संविधान (हिंदी).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\हिन्दू धर्म की रक्षा के लिये शिखा धारण की आवश्यकता (1).pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Downloads\हिन्दू धर्म की रक्षा के लिये शिखा धारण की आवश्यकता.pdf:SandBoxSafeFile [0]
AlternateDataStreams: C:\Users\WINDOW 7\Documents\Mercury II Energy Business Plan .pdf:SandBoxSafeFile [0]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 10:04 - 2017-06-17 09:22 - 00000000 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 2
MSCONFIG\Services: BstHdAndroidSvc => 3
MSCONFIG\Services: FirebirdServerMAGIXInstance => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: gusvc => 3
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: WsDrvInst => 3
MSCONFIG\startupfolder: C:^Users^WINDOW 7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP DeskJet 2130 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP DeskJet 2130 series.lnk.Startup
MSCONFIG\startupfolder: C:^Users^WINDOW 7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: AMD AVT => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe -s
MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
MSCONFIG\startupreg: uTorrent => "C:\Program Files\uTorrent\uTorrent.exe"
MSCONFIG\startupreg: WinampAgent => C:\Program Files\Winamp\winampa.exe
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{A87763A6-6A2A-4DE7-BD35-F9380F6A0096}] => (Allow) C:\Program Files\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{BEDF0B50-64FF-4ABC-8628-27191191D412}] => (Allow) C:\Program Files\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{21333DDF-60E6-4A2D-B758-A075EBD2397E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{15A119E4-336D-4D81-AC4B-00CF61DB688E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{94BF4EDF-D2DE-4D49-AE37-7E7425DF2BB1}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{89F102C9-544D-4CFA-B5CD-48D4D5E0705F}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{D7571F0A-FC6A-40FA-A0B7-4939894F45C2}] => (Allow) C:\Program Files\AVG\AVG2013\avgnsx.exe
FirewallRules: [{A71B61A4-4177-4893-A09E-F57153F9C814}] => (Allow) C:\Program Files\AVG\AVG2013\avgnsx.exe
FirewallRules: [{19CAC8E9-C890-438E-9822-C1A0F96CD517}] => (Allow) C:\Program Files\AVG\AVG2013\avgdiagex.exe
FirewallRules: [{AFA8C448-504D-45A4-9344-D34776ACFA45}] => (Allow) C:\Program Files\AVG\AVG2013\avgdiagex.exe
FirewallRules: [{32E55BC0-C17D-4FAE-AA42-D813BF8CD47A}] => (Allow) C:\Program Files\AVG\AVG2013\avgemcx.exe
FirewallRules: [{D5D5918E-678C-46B9-ACFF-B0F38175B203}] => (Allow) C:\Program Files\AVG\AVG2013\avgemcx.exe
FirewallRules: [{7A58F221-6FE2-48F9-ACFC-38D1C9A05282}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe
FirewallRules: [{6AF096B5-8FA4-4FB7-BA94-498B34207A3A}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{20FEEB78-19C3-4263-AE63-7C00E0E2B471}C:\program files\unity\editor\unity.exe] => (Allow) C:\program files\unity\editor\unity.exe
FirewallRules: [UDP Query User{34E201E1-5CB2-4996-B184-0503A29A144F}C:\program files\unity\editor\unity.exe] => (Allow) C:\program files\unity\editor\unity.exe
FirewallRules: [TCP Query User{3637CCE0-9F78-472B-ABCB-C8C5204DC2C3}C:\program files\strogino cs portal\dota 2\dota.exe] => (Allow) C:\program files\strogino cs portal\dota 2\dota.exe
FirewallRules: [UDP Query User{A5711177-FE0E-4D42-928D-F34E593E2B7C}C:\program files\strogino cs portal\dota 2\dota.exe] => (Allow) C:\program files\strogino cs portal\dota 2\dota.exe
FirewallRules: [{1CA326A9-8D66-4BBD-A4C9-AC926F805660}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{4FE384D0-42C4-42C6-952E-92BD2E01B45B}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{04705006-E0F3-4F42-A010-E5BED1C1F170}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{614C8DA1-C367-4EF7-8676-B6F7B7DDEED2}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{2E05F482-34EB-4D35-A48C-C5AADC8779C6}] => (Allow) C:\Program Files\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{9D8A70E6-2145-4363-A853-BCDA918E8F1B}] => (Allow) C:\Program Files\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{3D883B92-9B22-48AB-95EE-7EB81828B8A3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4AEE93E6-6A25-4F79-998C-EC935044D2BA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{FBD925C5-AC7F-4FD2-9129-66C8EBFCCE0C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{F669BF5D-FC60-4364-A945-D13322A97BB9}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\USBSetup.exe
FirewallRules: [{B53C9CB1-7F4C-4C57-AA5F-941A31AF7193}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{EFE30CE6-2434-4F30-8AE8-D4C3C71DC554}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{75F83D6A-7BE5-40D9-81A4-E6C868F3EC32}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BA5A5E11-A278-4599-9901-ABD20ED94C70}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{2F4C5589-1F24-4875-A374-7A2C5A9E1E86}] => (Allow) C:\Program Files\UCBrowser\Application\UCBrowser.exe
FirewallRules: [{EC8692B5-5FC6-4C06-94B3-86E04CB3BB3E}] => (Allow) C:\Program Files\LuDaShi\ComputerZTray.exe
FirewallRules: [{CC12438C-B878-4148-91D4-50A141E3A456}] => (Allow) C:\Program Files\LuDaShi\ComputerZTray.exe
FirewallRules: [{50E1A851-AA10-4FA8-B375-56954E672671}] => (Allow) C:\Program Files\Maoha\MaohaAP\MaohaWifiSvr.exe
FirewallRules: [{F3FD1882-B73E-4746-8036-5CD5CB918185}] => (Allow) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{B97CF10A-1DB8-4995-A438-A70FF24908C2}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{1FAF1FC7-3FFC-415A-B2E8-2AF016B413E7}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A9F31811-2FE4-45B5-9589-DAC047C5B0BD}] => (Allow) C:\Program Files\Opera\45.0.2552.888\opera.exe
FirewallRules: [{F5EAF296-8D03-411F-A6AF-55255BA1860F}] => (Allow) C:\Program Files\Opera\45.0.2552.898\opera.exe
 
==================== Restore Points =========================
 
13-06-2017 20:49:57 Scheduled Checkpoint
16-06-2017 09:27:41 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: mscank
Description: mscank
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: mscank
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Apple iPhone
Description: Apple iPhone
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Apple Inc.
Service: WUDFRd
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/17/2017 12:32:04 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\HP\HP DeskJet 2130 series\DriverStore\Yeti\V3\amd64\hpinkinsE111.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (06/16/2017 09:23:01 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/16/2017 09:22:03 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x80070005.
 
Error: (06/13/2017 08:44:27 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\HP\HP DeskJet 2130 series\DriverStore\Yeti\V3\amd64\hpinkinsE111.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (06/13/2017 07:45:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/13/2017 07:44:40 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x80070005.
 
Error: (06/10/2017 12:31:42 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\HP\HP DeskJet 2130 series\DriverStore\Yeti\V3\amd64\hpinkinsE111.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (06/09/2017 10:06:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/09/2017 10:05:08 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x80070005.
 
Error: (06/08/2017 09:37:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: downloader2.exe, version: 18.1.6.167, time stamp: 0x590cddaa
Faulting module name: ucrtbase.DLL, version: 10.0.10240.16390, time stamp: 0x55a5bf73
Exception code: 0xc0000417
Fault offset: 0x0007c3b4
Faulting process id: 0x1790
Faulting application start time: 0x01d2d8ff376960fd
Faulting application path: C:\Program Files\Real\RealDownloader\downloader2.exe
Faulting module path: C:\Windows\system32\ucrtbase.DLL
Report Id: 9bebeefa-4c4f-11e7-9e65-50465da0b370
 
 
System errors:
=============
Error: (06/17/2017 10:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 09:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 08:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 07:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 06:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 05:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 04:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 03:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 02:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
Error: (06/17/2017 01:56:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The sppuinotify service terminated with the following error: 
Access is denied.
 
 
CodeIntegrity:
===================================
  Date: 2016-12-14 16:52:15.244
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.243
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.241
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.236
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.234
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.221
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.218
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.215
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-12-14 16:52:15.208
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 73%
Total physical RAM: 3551.73 MB
Available physical RAM: 932.09 MB
Total Virtual: 7101.75 MB
Available Virtual: 4132.98 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:195.21 GB) (Free:4.72 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:270.45 GB) (Free:53.04 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 69D7296C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=195.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=270.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 


  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,577 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

Going over your logs I noticed that you have µTorrent installed. It is pretty much certain that if you continue to use P2P programs, you will get infected again.
1.Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
2. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
3. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
4.The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove the program, you can do so via Start > Control Panel > Add/Remove Programs.

If you are still leaning toward using this program, please take a look at this information about Ransomware which can be delivered via P2P file transfers. The newest variation of Ransomware can make it impossible to recover the files this malicious software encrypts. In other words, you will probably lose most if not all of your valuable information, including pictures. In addition it has recently been reported that P2P downloads may be tracked resulting in your IP address being monitored by copyright authorities. .
If you wish to keep it, please do not use it until we are completely done and your machine is determined to be clean and updated.

Warning
Drive c:\ () (Fixed) (Total:195.21 GB) (Free:4.72 GBNTFS
Your c:\ drive is running out of free space, you have 4.7GB, you should have at least 29GB. Windows needs 15% Free space of the total amount of the hard drive being 195GB.
This can an will cause various problems and the drive could crash.
Start by clearing out the downloads folder.

Next

Programs to uninstall that are adware related
Java 7 Update
Java 8 Update 25
Java 8 Update 91
StarBurn Version 12r10
UmmyVideoDownloader

Old versions of Java are an infection risk

Next

Download AdwCleaner from here. Save the file to the desktop.
NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.
Close all open windows and browsers.
  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:
iO5EZayK.png
  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be moved to Quarantine.
  • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this
adwcleaner_delete_restart.jpg
  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt
Next
  • Please download Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.

    Next
    • Please download Malwarebytes Anti-Malware to your desktop.
    • Double-click mbam-setup-version.exe and follow the prompts to install the program.
    • Launch Malwarebytes Anti-Malware
    • Then click Finish.
    • If an update is found, you will be prompted to download and install the latest version.
    • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
    • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
    • Reboot your computer if prompted.
    Posting the Malwarebytes log.
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • post that saved log to your next reply.
    In your next reply post;
  • The AdwCleaner [C1].txt Log
  • The JRT.txt Log
  • Malwarebytes log




  • 0

#3
Sunshine-cures

Sunshine-cures

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

Going over your logs I noticed that you have µTorrent installed. It is pretty much certain that if you continue to use P2P programs, you will get infected again.
1.Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
2. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
3. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
4.The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove the program, you can do so via Start > Control Panel > Add/Remove Programs.

If you are still leaning toward using this program, please take a look at this information about Ransomware which can be delivered via P2P file transfers. The newest variation of Ransomware can make it impossible to recover the files this malicious software encrypts. In other words, you will probably lose most if not all of your valuable information, including pictures. In addition it has recently been reported that P2P downloads may be tracked resulting in your IP address being monitored by copyright authorities. .
If you wish to keep it, please do not use it until we are completely done and your machine is determined to be clean and updated.

Warning
Drive c:\ () (Fixed) (Total:195.21 GB) (Free:4.72 GBNTFS
Your c:\ drive is running out of free space, you have 4.7GB, you should have at least 29GB. Windows needs 15% Free space of the total amount of the hard drive being 195GB.
This can an will cause various problems and the drive could crash.
Start by clearing out the downloads folder.

Next

Programs to uninstall that are adware related
Java 7 Update
Java 8 Update 25
Java 8 Update 91
StarBurn Version 12r10
UmmyVideoDownloader

Old versions of Java are an infection risk

Next

Download AdwCleaner from here. Save the file to the desktop.
NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.
Close all open windows and browsers.

  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:
<script type="text/javascript"> //</script>iO5EZayK.png
  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be moved to Quarantine.
  • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this
adwcleaner_delete_restart.jpg
  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt
Next
  • Please download Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.

    Next
    • Please download Malwarebytes Anti-Malware to your desktop.
    • Double-click mbam-setup-version.exe and follow the prompts to install the program.
    • Launch Malwarebytes Anti-Malware
    • Then click Finish.
    • If an update is found, you will be prompted to download and install the latest version.
    • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
    • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
    • Reboot your computer if prompted.
    Posting the Malwarebytes log.
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • post that saved log to your next reply.
    In your next reply post;
  • The AdwCleaner [C1].txt Log
  • The JRT.txt Log
  • Malwarebytes log


     

 

Thank you Zep! i think its pretty cleaned up now... i did exactly how you instructed, your instructions were pretty clear and easy to follow... have removed utorrent, tho i used to love it a lot to download my files... will see what i can do, maybe i just keep one old computer aside to do that... lol... now i need to install an antivirus... how do i go about that, just purchase and install it? what about the old one can i just normally uninstall it? i was using the free version... thanx a ton for your help! 


  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,577 posts
Oh Dear,

We should have posted the log files from each thing that was run,


Next

Download the enclosed => file.Attached File  fixlist.txt   133.6KB   26 downloads Save it in the location FRST64 is. Your desktop. Run FRST and click on the Fix button. Wait until finished.

The tool will make a log in the location FRST is,Your desktop. (Fixlog.txt). Please post it to your reply.

Post the Fixlog, it will be on the desktop.
  • 0

#5
Sunshine-cures

Sunshine-cures

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

i have them saved ... will post, i just joined this forum, will need time to understand it... where do i post them?


  • 0

#6
Sunshine-cures

Sunshine-cures

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-06-2017 01
Ran by WINDOW 7 (administrator) on WINDOW7-PC (17-06-2017 11:23:07)
Running from C:\Users\WINDOW 7\Desktop
Loaded Profiles: WINDOW 7 (Available Profiles: WINDOW 7 & Guest)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ARWSRVC.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCSECSVC.EXE
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE
() C:\Program Files\D-Link\DWA-123\ALPBCSVC.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\QUHLPSVC.EXE
() C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\REPRSVC.EXE
() C:\Program Files\UCBrowser\Application\UCService.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\Real\RealDownloader\downloader2.exe
(Hewlett-Packard Company) C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(BitTorrent, Inc.) C:\Program Files\uTorrent\uTorrent.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\onlinent.exe
() C:\Program Files\Business-in-a-Box 2016\BIBLauncher.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudPhotos.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple, Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\secd.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
() C:\Program Files\UCBrowser\Application\6.1.2716.5\UCAgent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Quick Heal Core UI] => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\strtupap.exe [181392 2016-07-23] (Quick Heal Technologies Ltd.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [352648 2016-12-15] (RealNetworks, Inc.)
HKLM\...\Run: [RealDownloader] => C:\Program Files\Real\RealDownloader\downloader2.exe [730864 2017-05-05] ()
HKLM\...\Run: [HPUsageTrackingLEDM] => C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [30264 2009-10-15] (Hewlett-Packard Company)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [267064 2017-05-09] (Apple Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-05-09] (Apple Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [uTorrent] => C:\Program Files\uTorrent\uTorrent.exe [399736 2013-03-18] (BitTorrent, Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [BIBLauncher] => C:\Program Files\Business-in-a-Box 2016\BIBLauncher.exe [3129712 2016-11-07] ()
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [iCloudPhotos] => C:\Program Files\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-03-16] (Apple Inc.)
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Run: [Windscribe] => C:\Program Files\Windscribe\Windscribe.exe
HKLM\...\Providers\jymv66na: C:\Program Files\Adobe\\local32spl.dll
Lsa: [Notification Packages] scecli C:\Windows\system32\ScSecAuth.Dll
ShellExecuteHooks: No Name - {D7563EE2-AA87-11E6-B5B6-64006A5CFC23} - C:\Users\WINDOW 7\AppData\Roaming\Mtetionqucult\Nemosh.dll -> No File
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  -> No File
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2012-11-16] (Tonec Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2016-12-15]
ShortcutTarget: RealTimes.lnk -> C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall LastPass RunOnce.lnk [2016-11-06]
ShortcutTarget: Uninstall LastPass RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{0D786AF9-991C-4775-BB8A-2EFC61D28272}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{30E4D2A3-3B53-45F1-B6CF-13716D5B8168}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131261821422668700&GUID=2179420A-EC42-4971-8F6E-CCF9CD3617B0
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131261821422668700&GUID=2179420A-EC42-4971-8F6E-CCF9CD3617B0
HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://malaysia.msn.com/?rd=1&ucc=MY&dcc=MY&opt=0&ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3689701632-257498136-1677522028-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3689701632-257498136-1677522028-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2013-11-30] (Internet Download Manager, Tonec Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files\Real\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2016-11-11] (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-06-22] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-22] (Oracle Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137 [2017-06-16]
FF NetworkProxy: Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137 -> autoconfig_url", "data:text/javascript,%2F*windscribe*%2Ffunction%20FindProxyForURL(url%2C%20host)%20%7B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20if%20(isPlainHostName(host)%20%7C%7C%20%20shExpMatch(host%2C%20%22*.local%22)%20%7C%7C%20shExpMatch(host%2C%20%22*.int%22)%20%7C%7C%20shExpMatch(url%2C%20%22*%3A%2F%2Fapi.windscribe.com%2F*%22))%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20%22DIRECT%22%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20var%20lanIps%20%3D%20%2F(%5E127.)%7C(%5E192.168.)%7C(%5E10.)%7C(%5E172.1%5B6-9%5D.)%7C(%5E172.2%5B0-9%5D.)%7C(%5E172.3%5B0-1%5D.)%2F%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20if(lanIps.test(host))%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20%22DIRECT%22%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20if%20(url.substring(0%2C%205)%20%3D%3D%20'http%3A'%20%7C%7C%20url.substring(0%2C%206)%20%3D%3D%20'https%3A'%20%7C%7C%20url.substring(0%2C%204)%20%3D%3D%20'ftp%3A'%20%7C%7C%20url.substring(0%2C%203)%20%3D%3D%20'ws%3A')%20%7B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20%22HTTPS%20ext-start.windscribe.com%22%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%7D%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20return%20'DIRECT'%3B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%7D"
FF NetworkProxy: Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137 -> type", 2
FF Extension: (Windscribe) - C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137\Extensions\@windscribeff.xpi [2017-06-09]
FF Extension: (Pin It button) - C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137\Extensions\[email protected] [2016-12-19]
FF Extension: (uBlock Origin) - C:\Users\WINDOW 7\AppData\Roaming\Mozilla\Firefox\Profiles\jqfj44wa.default-1482141035137\Extensions\[email protected] [2017-05-16]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [not signed]
FF HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\WINDOW 7\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\WINDOW 7\AppData\Roaming\IDM\idmmzcc5 [2014-01-20] [not signed]
FF HKU\S-1-5-21-3689701632-257498136-1677522028-1000\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\WINDOW 7\AppData\Roaming\IDM\idmmzcc5
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-17] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-06-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-06-22] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @real.com/nppl3260;version=18.1.6.161 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2016-12-15] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=18.1.6.161 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2016-12-15] (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3689701632-257498136-1677522028-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\WINDOW 7\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-30] (Unity Technologies ApS)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-05-09]
 
Chrome: 
=======
CHR DefaultProfile: ChromeDefaultData
CHR NewTab: ChromeDefaultData ->  Not-active:"chrome-extension://kdkndgfoddphljphiagiedpopmhkkinn/stubby.html", Not-active:"chrome-extension://ppgplhcfmaadpnkmnkhgadmaekeldbnh/stubby.html", Not-active:"chrome-extension://lbapdklahcjljfincdglncfpdgfhckcf/stubby.html"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://srchnet.com/search/{searchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> {searchTerms}
CHR Profile: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-06-17] <==== ATTENTION
CHR Extension: (Google Docs) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-16]
CHR Extension: (Google Drive) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-16]
CHR Extension: (YouTube) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-16]
CHR Extension: (Tampermonkey) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-06-09]
CHR Extension: (Google Docs Offline) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-16]
CHR Extension: (PDFConverterHQ) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\kdkndgfoddphljphiagiedpopmhkkinn [2017-05-29]
CHR Extension: (MyScrapNook) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lbapdklahcjljfincdglncfpdgfhckcf [2017-05-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Search for Chrome) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pdmejgdbephapagdfiondmmepkbpchhg [2017-05-03]
CHR Extension: (Gmail) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-16]
CHR Extension: (Chrome Media Router) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-16]
CHR Extension: (TelevisionFanatic) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ppgplhcfmaadpnkmnkhgadmaekeldbnh [2017-05-27]
CHR Profile: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default [2017-06-03]
CHR Extension: (Google Slides) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-15]
CHR Extension: (Google Docs) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-15]
CHR Extension: (Google Drive) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-05]
CHR Extension: (YouTube) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-15]
CHR Extension: (Tampermonkey) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-02-15]
CHR Extension: (Adobe Acrobat) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-05]
CHR Extension: (Google Sheets) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-15]
CHR Extension: (Google Docs Offline) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-05]
CHR Extension: (IDM Integration Module) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2017-02-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-05]
CHR Extension: (Gmail) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-15]
CHR Extension: (Chrome Media Router) - C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-26]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2013-11-30]
CHR HKU\S-1-5-21-3689701632-257498136-1677522028-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\WINDOW~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-04-10]
CHR HKU\S-1-5-21-3689701632-257498136-1677522028-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx
 
Opera: 
=======
OPR Extension: (SaveFrom.net helper) - C:\Users\WINDOW 7\AppData\Roaming\Opera Software\Opera Stable\Extensions\npdpplbicnmpoigidfdjadamgfkilaak [2016-07-15]
OPR Extension: (Fast search) - C:\Users\WINDOW 7\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha [2016-12-14]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 arwsrvc; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\arwsrvc.exe [224400 2016-10-01] (Quick Heal Technologies Ltd.)
S4 Behavior Detection System; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\bdssvc.exe [34960 2016-09-26] (Quick Heal Technologies Ltd.)
S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [437880 2015-08-19] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413304 2015-08-19] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [839288 2015-08-19] (BlueStack Systems, Inc.)
R2 Core Mail Protection; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE [51344 2016-07-23] (Quick Heal Technologies Ltd.)
R2 Core Scanning Server; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE [237712 2016-10-12] (Quick Heal Technologies Ltd.)
S3 Core Scanning ServerEx; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE [237712 2016-10-12] (Quick Heal Technologies Ltd.)
R2 D-Link DWA-123_PBC_WPS; C:\Program Files\D-Link\DWA-123\ALPBCSVC.exe [61440 2010-08-16] () [File not signed]
S4 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-10-15] (HP) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [462048 2012-04-21] (Intel® Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [166720 2012-06-26] (Intel Corporation)
S4 Online Protection System; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\opssvc.exe [53904 2016-07-23] (Quick Heal Technologies Ltd.)
R2 Quick Update Service; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\quhlpsvc.exe [136848 2016-07-23] (Quick Heal Technologies Ltd.)
R2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [35104 2016-11-11] ()
R2 RealTimes Desktop Service; C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [987408 2016-12-15] (RealNetworks, Inc.)
R2 RepairService; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\reprsvc.exe [38016 2016-11-03] (Quick Heal Technologies Ltd.)
R2 ScanWscS; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE [289504 2016-07-12] (Quick Heal Technologies Ltd.)
R2 ScSecSvc; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ScSecSvc.exe [452752 2016-07-23] (Quick Heal Technologies Ltd.)
R2 UCBrowserSvc; C:\Program Files\UCBrowser\Application\UCService.exe [599440 2017-05-11] () <==== ATTENTION
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S2 GmSvc; C:\Program Files\LDSGameCenter\GmSvc.dll [X]
S2 Pherheght; C:\Program Files\Vigaghtlterk\atifespcontrols.dll [X]
S4 WsDrvInst; C:\Program Files\Wondershare\MobileTrans\DriverInstall.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ACWINLPT; C:\Windows\system32\ACWINLPT.SYS [4080 1999-05-20] () [File not signed]
R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwf.sys [12800 2013-03-22] ()
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
R3 arwflt; C:\Windows\System32\DRIVERS\arwflt.sys [71680 2016-09-29] (Quick Heal Technologies Ltd.)
R1 ASPI32; C:\Windows\system32\Drivers\ASPI32.sys [25244 2004-08-06] (Adaptec)
R3 atkldrvr; C:\Windows\System32\DRIVERS\atkldrvr.sys [45296 2016-05-02] (Quick Heal Technologies Ltd.)
S4 bdsflt; C:\Windows\System32\DRIVERS\bdsflt.sys [279000 2016-11-18] (Quick Heal Technologies Ltd.)
S4 bdsnm; C:\Windows\System32\DRIVERS\bdsnm.sys [30992 2016-09-26] (Quick Heal Technologies Ltd.)
R3 bsfs; C:\Windows\System32\DRIVERS\bsfs.sys [76984 2016-04-12] (Quick Heal Technologies Ltd.)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [132216 2015-08-19] (BlueStack Systems)
R2 catflt; C:\Windows\System32\DRIVERS\catflt.sys [127824 2016-09-22] (Quick Heal Technologies Ltd.)
R2 EMLSS; C:\Windows\System32\drivers\emltdi.sys [42608 2016-04-12] (Quick Heal Technologies Ltd.)
R1 ggc; C:\Windows\System32\DRIVERS\ggc.sys [74784 2016-09-22] (Quick Heal Technologies Ltd.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2016-12-14] (REALiX™)
R2 IntelHaxm; C:\Windows\System32\DRIVERS\IntelHaxm.sys [90632 2015-11-16] (Intel  Corporation)
R3 kbfltr; C:\Windows\System32\DRIVERS\kbfltr.sys [27144 2016-08-16] (Quick Heal Technologies Ltd.)
S3 llio; C:\Windows\system32\DRIVERS\llio.sys [69512 2016-04-12] (Quick Heal Technologies Ltd.)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-03] (Intel Corporation)
S0 mscank; C:\Windows\System32\DRIVERS\mscank.sys [45168 2016-04-12] (Quick Heal Technologies Ltd.)
R3 netr28u; C:\Windows\System32\DRIVERS\Dnetr28u.sys [1277504 2012-01-06] (Ralink Technology Corp.)
R0 PxHelp20; C:\Windows\System32\DRIVERS\PxHelp20.sys [20016 2003-10-28] (Sonic Solutions) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [721904 2013-07-11] () [File not signed]
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2016-04-21] (The OpenVPN Project)
R1 ucdrv; C:\Windows\System32\drivers:ucdrv-x86.sys [84370 ] (UC Web Inc.) <==== ATTENTION
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [15872 2009-07-14] (Microsoft Corporation)
R0 webssx; C:\Windows\System32\drivers\webssx.sys [71656 2016-08-18] (Quick Heal Technologies Ltd.)
R1 wsnf; C:\Windows\System32\DRIVERS\wsnf.sys [52584 2016-04-12] (Quick Heal Technologies Ltd.)
U1 aswbdisk; no ImagePath
S3 ComputerZ; \??\C:\Program Files\LuDaShi\ComputerZ.sys [X] <==== ATTENTION
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
NETSVC: HpSvc -> no filepath.
NETSVC: GmSvc -> C:\Program Files\LDSGameCenter\GmSvc.dll ==> No File
NETSVC: WpSvc -> no filepath.
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-17 11:25 - 2017-06-17 11:25 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Sunny Knee
2017-06-17 11:23 - 2017-06-17 11:25 - 00028159 _____ C:\Users\WINDOW 7\Desktop\FRST.txt
2017-06-17 11:22 - 2017-06-17 11:23 - 00000000 ____D C:\FRST
2017-06-17 11:13 - 2017-06-17 11:13 - 01777152 _____ (Farbar) C:\Users\WINDOW 7\Desktop\FRST.exe
2017-06-16 16:27 - 2017-06-16 16:27 - 00000000 ____D C:\Users\WINDOW 7\Desktop\downloaded
2017-06-16 16:06 - 2017-06-16 16:27 - 1293593107 _____ C:\Users\WINDOW 7\Downloads\ebooksharing-20170616T075918Z-002.zip
2017-06-16 15:41 - 2017-06-16 15:52 - 00000000 ____D C:\Users\WINDOW 7\Desktop\new list of ebooks telegram
2017-06-16 15:07 - 2017-06-16 15:07 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Telegram Ebooks
2017-06-16 12:51 - 2017-06-16 15:30 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Ebooks CDB
2017-06-16 12:51 - 2017-06-16 12:51 - 22249753 _____ C:\Users\WINDOW 7\Desktop\2 Ek Adabhut Jeevan Kahani - Part-2.pdf
2017-06-16 10:28 - 2017-06-16 10:28 - 00021970 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-15 at 11.33.55.ogg
2017-06-16 10:28 - 2017-06-16 10:28 - 00019414 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-16 at 10.27.30.ogg
2017-06-16 10:28 - 2017-06-16 10:28 - 00018133 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-16 at 10.27.22.ogg
2017-06-16 10:28 - 2017-06-16 10:28 - 00012444 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-16 at 10.27.17.ogg
2017-06-16 09:54 - 2017-06-16 09:54 - 00574071 _____ C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture (2).pdf
2017-06-16 09:54 - 2017-06-16 09:54 - 00574071 _____ C:\Users\WINDOW 7\Downloads\cedar_pine_chips_picture (1).pdf
2017-06-16 09:22 - 2017-06-16 09:22 - 00000000 ___HD C:\Users\WINDOW 7\ScStore
2017-06-15 15:27 - 2017-06-15 15:27 - 00068952 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Image 2017-06-12 at 16.20.18.jpeg
2017-06-14 23:03 - 2017-06-14 23:03 - 22249753 _____ C:\Users\WINDOW 7\Downloads\2 Ek Adabhut Jeevan Kahani - Part-2.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 20937480 _____ C:\Users\WINDOW 7\Downloads\1 Ek Adabhut Jeevan Kahani - Part-1.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 06226936 _____ C:\Users\WINDOW 7\Downloads\Small_Big_book_English_ebook.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 01493831 _____ C:\Users\WINDOW 7\Downloads\मधुमेह (Diabetes) (1).pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00872507 _____ C:\Users\WINDOW 7\Downloads\30 Most Convincing case.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00536823 _____ C:\Users\WINDOW 7\Downloads\Hindu_Rituals_Handbook-1.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00201119 _____ C:\Users\WINDOW 7\Downloads\your-invisible-power-genevieve-behrand.pdf
2017-06-14 23:03 - 2017-06-14 23:03 - 00039438 _____ C:\Users\WINDOW 7\Downloads\Beyond Reincarnation - Experience Your Past Lives And Lives Between Live - Joe Slate.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 06848813 _____ C:\Users\WINDOW 7\Downloads\Aroma-Day1-Part1.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 03019961 _____ C:\Users\WINDOW 7\Downloads\common-yoga-protocol (1).pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 00795176 _____ C:\Users\WINDOW 7\Downloads\kundalini.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 00775662 _____ C:\Users\WINDOW 7\Downloads\kundalini-yoga- -meditation.pdf
2017-06-14 23:02 - 2017-06-14 23:02 - 00505759 _____ C:\Users\WINDOW 7\Downloads\EssentialOils.pdf
2017-06-14 22:53 - 2017-06-14 22:53 - 00092837 _____ C:\Users\WINDOW 7\Desktop\E-Ticket Print.pdf
2017-06-14 21:51 - 2017-06-14 21:51 - 00390985 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.16.mp4
2017-06-14 21:51 - 2017-06-14 21:51 - 00388610 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.23.mp4
2017-06-14 21:51 - 2017-06-14 21:51 - 00270433 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.08.mp4
2017-06-14 21:51 - 2017-06-14 21:51 - 00144085 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-09 at 09.14.18.mp4
2017-06-14 21:49 - 2017-06-14 21:49 - 00055990 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-14 at 21.23.27.ogg
2017-06-10 10:55 - 2017-06-10 10:55 - 09516337 _____ C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 07782641 _____ C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 07763216 _____ C:\Users\WINDOW 7\Downloads\Combine-Reiki-with-Other-Healing-Tools-1.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 05457572 _____ C:\Users\WINDOW 7\Downloads\LIVING-WITH-THE-HIMALAYAN-MASTERS.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04430087 _____ C:\Users\WINDOW 7\Downloads\Archangels-Glory (1).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04165895 _____ C:\Users\WINDOW 7\Downloads\Tarka Sangraha- Complete Version(1)-1-1.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04105063 _____ C:\Users\WINDOW 7\Downloads\Healing-Past-and-Future-with-Reiki.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 04027046 _____ C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 03696848 _____ C:\Users\WINDOW 7\Downloads\Tantrik Siddhiya - Dr. N.D.Shrimali-Compressed
2017-06-10 10:55 - 2017-06-10 10:55 - 03307723 _____ C:\Users\WINDOW 7\Downloads\HINDI.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 02511588 _____ C:\Users\WINDOW 7\Downloads\GST-Book-in-Hindi.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01659786 _____ C:\Users\WINDOW 7\Downloads\4_5895753623568122179.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01493831 _____ C:\Users\WINDOW 7\Downloads\मधुमेह (Diabetes).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01214589 _____ C:\Users\WINDOW 7\Downloads\PowerOfPositiveThinking-1.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01176887 _____ C:\Users\WINDOW 7\Downloads\Discover_Atlantis -Diana Cooper.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 01101719 _____ C:\Users\WINDOW 7\Downloads\सम्पूर्ण संविधान (हिंदी).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 00909555 _____ C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue (2).pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 00520037 _____ C:\Users\WINDOW 7\Downloads\The Sankhya Darshana.pdf
2017-06-10 10:55 - 2017-06-10 10:55 - 00182664 _____ C:\Users\WINDOW 7\Downloads\The Mantra Book - Way of The Prayer.pdf
2017-06-10 10:54 - 2017-06-10 10:54 - 06974235 _____ C:\Users\WINDOW 7\Downloads\Tatiana Sergantova - 365 Modelos de origami.pdf
2017-06-10 10:54 - 2017-06-10 10:54 - 01910834 _____ C:\Users\WINDOW 7\Downloads\russian kids origami.pdf
2017-06-09 13:48 - 2017-06-09 13:43 - 00207957 _____ C:\Users\WINDOW 7\Desktop\9th june.jpeg
2017-06-09 12:05 - 2017-06-09 12:05 - 49148880 _____ C:\Users\WINDOW 7\Downloads\veergatha.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 05773718 _____ C:\Users\WINDOW 7\Downloads\6nbt- Gautam Buddha by Leela George.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02890550 _____ C:\Users\WINDOW 7\Downloads\Autobiography-of-a-Yogi-by-Paramahansa-Yogananda.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02861323 _____ C:\Users\WINDOW 7\Downloads\Art of Living in English.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02423979 _____ C:\Users\WINDOW 7\Downloads\buddha_a_story_of_enlightenment.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02407590 _____ C:\Users\WINDOW 7\Downloads\Gst ready.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02216567 _____ C:\Users\WINDOW 7\Downloads\Bhagwad Gita.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 02034812 _____ C:\Users\WINDOW 7\Downloads\Ashwin Sanghi - Chanakyas Chant.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 01553456 _____ C:\Users\WINDOW 7\Downloads\Bruce-H.-Lipton-The-Biology-of-Belief-Unleashing-the-Power-of-Consciousness-Matter-and-Miracles-epub-TKRG
2017-06-09 12:04 - 2017-06-09 12:04 - 01276464 _____ C:\Users\WINDOW 7\Downloads\Gregg-Braden-The-Divine-Matrix.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 00585264 _____ C:\Users\WINDOW 7\Downloads\Ayn_Rand-The_Virtue_of_Selfishness.pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 00368157 _____ C:\Users\WINDOW 7\Downloads\bhagwad gita (1).pdf
2017-06-09 12:04 - 2017-06-09 12:04 - 00087824 _____ C:\Users\WINDOW 7\Downloads\ayn-rand-introduction-to-objectivist-epistemology-pdf.pdf
2017-06-09 11:03 - 2017-06-09 11:03 - 14939764 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 10.02.37.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14939012 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 09.51.59.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14885376 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 09.53.13.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14506681 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-07 at 09.40.31.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 14442816 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-06 at 10.03.12.mp4
2017-06-09 11:03 - 2017-06-09 11:03 - 00179607 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-03 at 10.46.43.ogg
2017-06-09 11:03 - 2017-06-09 11:03 - 00062685 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-06-03 at 10.46.49.ogg
2017-06-09 11:02 - 2017-06-09 11:02 - 18833237 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-07 at 10.03.47.mp4
2017-06-09 11:02 - 2017-06-09 11:02 - 14498364 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Video 2017-06-07 at 09.41.04.mp4
2017-06-09 11:02 - 2017-06-09 11:02 - 01845719 _____ C:\Users\WINDOW 7\Downloads\WhatsApp Audio 2017-05-31 at 14.53.09.mp4
2017-06-09 11:02 - 2017-06-09 11:02 - 00000000 ____D C:\Users\WINDOW 7\Downloads\Learn Sanskrit
2017-06-08 22:20 - 2017-06-08 22:20 - 01993473 _____ C:\Users\WINDOW 7\Downloads\Practicing the Power of Now - Eckhart Tolle.compressed
2017-06-08 22:19 - 2017-06-08 22:19 - 22416275 _____ C:\Users\WINDOW 7\Downloads\patricia-mercier-the-chakra-bible-1-ebook-pdf-collated-ocr.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 09516337 _____ C:\Users\WINDOW 7\Downloads\Angel Medicine - Doreen Virtue (1).pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 07782641 _____ C:\Users\WINDOW 7\Downloads\Angels_101_Work_n_Heal_with_the_Angels_Doreen Virtue (1).pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 04027046 _____ C:\Users\WINDOW 7\Downloads\Big Book of Angel Tarot - Doreen Virtue (1).pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03768242 _____ C:\Users\WINDOW 7\Downloads\CosmicOrderingSecret.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03450842 _____ C:\Users\WINDOW 7\Downloads\The-SecretinHindi.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03412782 _____ C:\Users\WINDOW 7\Downloads\2_5280892187146453252.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 03176914 _____ C:\Users\WINDOW 7\Downloads\2_722597121924005935.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 01525760 _____ C:\Users\WINDOW 7\Downloads\awakening_the_third_eyethird-eye.pdf
2017-06-08 22:19 - 2017-06-08 22:19 - 00816177 _____ C:\Users\WINDOW 7\Downloads\Switchwords - How to Use One Word to Get What You Want.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 33059906 _____ C:\Users\WINDOW 7\Downloads\The Power - Rhonda Byrne.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 20278321 _____ C:\Users\WINDOW 7\Downloads\India Today(HINDI)_June 7,2017.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 12497326 _____ C:\Users\WINDOW 7\Downloads\Barbara Brennan Light Emerging - Journey of Personal Healing (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 05912404 _____ C:\Users\WINDOW 7\Downloads\7 Galactic Invocations.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 02134449 _____ C:\Users\WINDOW 7\Downloads\what-is-my-spirit-animal-ebook-091715-2 (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 01569001 _____ C:\Users\WINDOW 7\Downloads\2_5208872801137590600.pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 01324912 _____ C:\Users\WINDOW 7\Downloads\You are the Healer (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00909555 _____ C:\Users\WINDOW 7\Downloads\Angel Dreams - Doreen Virtue (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00861873 _____ C:\Users\WINDOW 7\Downloads\Angels of Abundance - Virtue, Doreen, Virtue, Grant (2).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00831392 _____ C:\Users\WINDOW 7\Downloads\UnStuck (1).pdf
2017-06-08 22:18 - 2017-06-08 22:18 - 00723707 _____ C:\Users\WINDOW 7\Downloads\Healing-with-the-Angels--Doreen-Virtue (1).pdf
2017-06-08 22:17 - 2017-06-08 22:18 - 00784616 _____ C:\Users\WINDOW 7\Downloads\Hoof and Paw Crystal Grids for Animals bookletpdf1-1 (1).pdf
2017-06-08 22:17 - 2017-06-08 22:18 - 00037942 _____ C:\Users\WINDOW 7\Downloads\vedic-1.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 13622243 _____ C:\Users\WINDOW 7\Downloads\The Arcturian Corridor - Part I.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 12862714 _____ C:\Users\WINDOW 7\Downloads\Barbara Brennan - Hands of Light - Guide to Healing   through the Human Energy Field [OCR]-1.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 00034535 _____ C:\Users\WINDOW 7\Downloads\Switchwords-1-2.pdf
2017-06-08 22:17 - 2017-06-08 22:17 - 00034535 _____ C:\Users\WINDOW 7\Downloads\Switchwords-1.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 05398411 _____ C:\Users\WINDOW 7\Downloads\The_Magic.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 04730239 _____ C:\Users\WINDOW 7\Downloads\Hero_by_Rhonda_Byrne_2.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 03588479 _____ C:\Users\WINDOW 7\Downloads\05. Gyanamrit-May16
2017-06-08 22:16 - 2017-06-08 22:16 - 02510896 _____ C:\Users\WINDOW 7\Downloads\virtue_angels-of-abundancethird-eye.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00791237 _____ C:\Users\WINDOW 7\Downloads\Master-Key-System.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00575683 _____ C:\Users\WINDOW 7\Downloads\switchwords-2.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00575683 _____ C:\Users\WINDOW 7\Downloads\switchwords-1-1-1.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00575683 _____ C:\Users\WINDOW 7\Downloads\switchwords-1-1.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00351748 _____ C:\Users\WINDOW 7\Downloads\bhudha thoughts.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00109433 _____ C:\Users\WINDOW 7\Downloads\Switchword_pairs-.pdf
2017-06-08 22:16 - 2017-06-08 22:16 - 00034535 _____ C:\Users\WINDOW 7\Downloads\Switchwords-3.pdf
2017-06-08 22:15 - 2017-06-08 22:16 - 01016838 _____ C:\Users\WINDOW 7\Downloads\Dying to Be Me - Anita Moorjani-2.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 08632861 _____ C:\Users\WINDOW 7\Downloads\The_Power_by_Rhonda_Byrne_-1.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 05639243 _____ C:\Users\WINDOW 7\Downloads\Infallible-Vedic-Remedies-Mantras-for-Common-Problems.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 03019961 _____ C:\Users\WINDOW 7\Downloads\common-yoga-protocol.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 02452561 _____ C:\Users\WINDOW 7\Downloads\ऐ मेरे स्कूल मुझे जरा फिर से तो बुलाना.pdf
2017-06-08 22:15 - 2017-06-08 22:15 - 00263819 _____ C:\Users\WINDOW 7\Downloads\karma.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 10661128 _____ C:\Users\WINDOW 7\Downloads\Osho's Biography.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03943668 _____ C:\Users\WINDOW 7\Downloads\Outliers.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03614228 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 4.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03573455 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 1.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03499862 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 5.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03238297 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 3.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 03116569 _____ C:\Users\WINDOW 7\Downloads\Patanjali Yoga Sutra 2.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 00652841 _____ C:\Users\WINDOW 7\Downloads\Blink- The Power of Thinking Without Thinking.pdf
2017-06-08 22:14 - 2017-06-08 22:14 - 00595145 _____ C:\Users\WINDOW 7\Downloads\Ask And It Is Given.pdf
2017-06-08 22:13 - 2017-06-08 22:13 - 00551040 _____ C:\Users\WINDOW 7\Downloads\Reiki_Parents_ebook.pdf
2017-06-08 21:42 - 2017-06-08 21:42 - 00121668 _____ C:\Users\WINDOW 7\Downloads\AMBRIELS TRUTH AND CLARITY EMPOWERMENT.pdf
2017-06-08 21:40 - 2017-06-08 21:40 - 00110480 _____ C:\Users\WINDOW 7\Downloads\ARCHANGEL_URIELS_PEACE_AND_TRANQUILITY_EMPOWERMENT.pdf
2017-06-08 21:35 - 2017-06-08 21:35 - 00226717 _____ C:\Users\WINDOW 7\Downloads\cord cutting.pdf
2017-06-08 21:32 - 2017-06-08 21:32 - 00341430 _____ C:\Users\WINDOW 7\Downloads\archangel_uriels_peace_and_tranquility_empowerment_pdf.zip
2017-06-08 21:28 - 2017-06-08 21:38 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Angel Miracles
2017-06-08 11:18 - 2017-06-17 11:23 - 00001159 _____ C:\Users\WINDOW 7\Desktop\Mozilla Firefox.lnk
2017-06-06 22:13 - 2017-06-06 22:14 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Poonam
2017-06-06 15:50 - 2017-06-06 15:50 - 00000000 ____D C:\Users\WINDOW 7\Desktop\Neetu Jain
2017-06-06 14:52 - 2017-06-06 14:52 - 00144599 _____ C:\Users\WINDOW 7\Desktop\june 6th &7th.jpeg
2017-06-06 13:18 - 2017-06-06 13:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2017-06-05 19:05 - 2017-06-05 19:05 - 01365040 _____ C:\Users\WINDOW 7\Downloads\How the use of Mobiles are Safe.pdf
2017-06-05 19:05 - 2017-06-05 19:05 - 00464940 _____ C:\Users\WINDOW 7\Downloads\ayurveda.pdf
2017-06-05 18:40 - 2017-06-05 18:40 - 00000000 ____D C:\Users\WINDOW 7\Desktop\MIT
2017-06-05 17:47 - 2017-06-05 18:43 - 1970658553 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170605T094150Z-001.zip
2017-06-05 17:47 - 2017-06-05 18:38 - 1744351568 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170605T094150Z-002.zip
2017-06-05 17:44 - 2017-06-05 17:47 - 00000000 ____D C:\Users\WINDOW 7\Downloads\Ebooks
2017-06-05 15:25 - 2017-06-05 15:25 - 00000000 ____D C:\Users\WINDOW 7\Desktop\New folder (2)
2017-06-04 16:09 - 2017-06-04 16:09 - 10468818 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T080849Z-001.zip
2017-06-04 16:03 - 2017-06-04 16:09 - 419605277 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T080149Z-001.zip
2017-06-04 15:24 - 2017-06-04 15:26 - 94656760 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T072420Z-001.zip
2017-06-04 14:48 - 2017-06-04 15:21 - 762120720 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064502Z-001.zip
2017-06-04 14:48 - 2017-06-04 15:20 - 752254831 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064204Z-001.zip
2017-06-04 14:47 - 2017-06-04 15:09 - 762120720 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064343Z-001.zip
2017-06-04 14:42 - 2017-06-04 14:43 - 49996378 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170604T064228Z-001.zip
2017-05-31 11:53 - 2017-05-31 13:01 - 1988520908 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034647Z-001.zip
2017-05-31 11:53 - 2017-05-31 12:58 - 1745823693 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034647Z-002.zip
2017-05-31 11:53 - 2017-05-31 12:02 - 283608723 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034647Z-003.zip
2017-05-31 11:49 - 2017-05-31 12:17 - 617489909 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170531T034722Z-001.zip
2017-05-30 15:50 - 2017-05-30 15:50 - 02011341 _____ C:\Users\WINDOW 7\Downloads\Mom2.zip
2017-05-28 07:24 - 2017-05-28 07:58 - 2023200948 _____ C:\Users\WINDOW 7\Downloads\drive-download-20170527T231709Z-001.zip
2017-05-27 06:36 - 2017-05-27 06:36 - 00016219 _____ C:\ProgramData\P1210OS.HTM
2017-05-27 06:36 - 2012-08-31 09:49 - 00024772 _____ C:\ProgramData\P1210DEF.css
2017-05-27 06:31 - 2017-05-27 06:31 - 00000000 ____D C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2017-05-23 13:06 - 2017-05-23 13:06 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-05-23 13:06 - 2017-05-23 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-05-23 13:04 - 2017-05-23 13:06 - 00000000 ____D C:\Program Files\iTunes
2017-05-22 10:55 - 2017-05-22 10:55 - 00844364 _____ C:\Users\WINDOW 7\Downloads\IGR-Starter.exe
2017-05-22 10:55 - 2017-05-22 10:55 - 00000000 ____D C:\Users\WINDOW 7\InfoCenter
2017-05-21 13:22 - 2017-05-21 13:19 - 00361790 _____ C:\Users\WINDOW 7\Documents\Mercury II Energy Business Plan .pdf
2017-05-21 13:19 - 2017-05-21 13:19 - 00361790 _____ C:\Users\WINDOW 7\Downloads\Mercury II Energy Business Plan .pdf
2017-05-20 12:53 - 2017-05-20 12:53 - 00000000 ____D C:\Users\WINDOW 7\Documents\Audacity
2017-05-20 12:52 - 2017-05-20 14:59 - 00000000 ____D C:\Users\WINDOW 7\AppData\Roaming\audacity
2017-05-20 12:52 - 2017-05-20 12:52 - 00000977 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2017-05-20 12:52 - 2017-05-20 12:52 - 00000965 _____ C:\Users\Public\Desktop\Audacity.lnk
2017-05-20 12:52 - 2017-05-20 12:52 - 00000000 ____D C:\Users\WINDOW 7\AppData\Local\Audacity
2017-05-20 12:52 - 2017-05-20 12:52 - 00000000 ____D C:\Program Files\Audacity
2017-05-20 12:51 - 2017-05-20 13:12 - 27113272 _____ (Audacity Team ) C:\Users\WINDOW 7\Downloads\audacity-win-2.1.3 (1).exe
2017-05-19 19:12 - 2017-05-19 19:12 - 17163336 _____ (Nullsoft, Inc.) C:\Users\WINDOW 7\Downloads\winamp5666_full_all.exe
2017-05-19 19:08 - 2017-05-19 19:09 - 27113272 _____ (Audacity Team ) C:\Users\WINDOW 7\Downloads\audacity-win-2.1.3.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-17 11:23 - 2016-12-19 17:44 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-06-17 11:23 - 2016-12-19 17:44 - 00001159 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-06-17 11:23 - 2016-12-16 11:34 - 00000286 _____ C:\Windows\Tasks\UCBrowserUpdaterCore.job
2017-06-17 11:23 - 2016-12-14 17:42 - 00001168 _____ C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-06-17 11:23 - 2016-07-12 11:11 - 00002365 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-17 11:16 - 2013-03-18 18:46 - 00000000 ____D C:\Users\WINDOW 7\AppData\Roaming\uTorrent
2017-06-17 11:01 - 2016-12-14 07:45 - 00000450 _____ C:\Windows\Tasks\UCBrowserUpdater.job
2017-06-17 10:56 - 2009-07-14 12:34 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-17 10:56 - 2009-07-14 12:34 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-17 10:44 - 2016-12-14 18:44 - 00000468 _____ C:\Windows\Tasks\Quick Heal AntiMalware Scan.job
2017-06-17 10:43 - 2016-12-14 18:43 - 00000444 _____ C:\Windows\Tasks\Resume Quickup Download.job
2017-06-16 12:33 - 2015-09-24 16:06 - 00000000 ____D C:\Program Files\Opera
2017-06-16 09:42 - 2016-11-19 19:28 - 00000000 ____D C:\Users\WINDOW 7\AppData\LocalLow\Mozilla
2017-06-16 09:28 - 2010-11-21 05:01 - 00785302 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-16 09:28 - 2009-07-14 10:37 - 00000000 ____D C:\Windows\inf
2017-06-16 09:22 - 2016-06-22 13:55 - 00000147 _____ C:\HaxLogs.txt
2017-06-16 09:22 - 2013-01-19 05:18 - 00000000 ____D C:\Users\WINDOW 7
2017-06-16 09:21 - 2017-05-17 12:03 - 00000000 ____D C:\Program Files\Common Files\AV
2017-06-16 09:21 - 2016-12-14 07:38 - 00000000 ____D C:\ProgramData\AVAST Software
2017-06-16 09:21 - 2009-07-14 12:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-09 13:43 - 2014-03-04 11:27 - 00000000 ___RD C:\Users\WINDOW 7\Documents\Scanned Documents
2017-06-08 22:05 - 2017-03-03 16:32 - 00000000 ____D C:\Users\WINDOW 7\Desktop\zen meditation and quotes
2017-06-01 12:25 - 2016-06-15 01:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-05-23 13:05 - 2016-11-02 12:15 - 00000000 ____D C:\Program Files\iPod
2017-05-21 18:56 - 2014-09-17 10:47 - 00000000 ____D C:\Users\WINDOW 7\AppData\Local\CutePDF Writer
 
==================== Files in the root of some directories =======
 
2016-07-07 17:33 - 2016-11-06 19:32 - 21737496 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2014-12-06 02:06 - 2014-12-06 02:06 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{084A6DE9-C5C8-4FED-BE02-45C7A4F3378D}
2014-11-23 14:00 - 2014-11-23 14:00 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{177B100C-9E87-48BF-B92C-D8A112B2E015}
2014-11-25 02:06 - 2014-11-25 02:06 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{1A003A31-C889-4FAA-885C-2DD8D8D8D5F7}
2015-03-07 04:12 - 2015-03-07 04:12 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{289FFCA7-4223-4225-AB47-7271BE119FAB}
2015-02-02 02:05 - 2015-02-02 02:05 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{2D8C87EF-339A-462F-8D79-E51BD0DB68E6}
2014-10-06 12:59 - 2014-10-06 12:59 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{3228A5E7-EB34-4BEE-A760-1EDEF0A764E7}
2015-02-16 02:04 - 2015-02-16 02:04 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{415DB93F-D2D4-4D6F-8D92-9DFE60DE3F31}
2015-02-14 04:12 - 2015-02-14 04:12 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{6827031D-4081-4DD3-BB67-E5AD1D1CFB46}
2014-10-23 12:53 - 2014-10-23 12:53 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{7966CC61-2967-471F-945C-F452ACD138C5}
2014-10-27 12:53 - 2014-10-27 12:53 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{C87A1114-9CEF-466E-A429-DBE188985424}
2014-10-25 00:59 - 2014-10-25 00:59 - 0000000 _____ () C:\Users\WINDOW 7\AppData\Local\{D48CFC2C-0E28-4557-A095-1A64345029DC}
2016-04-21 16:20 - 2016-04-21 16:20 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-03-22 14:27 - 2013-03-22 14:27 - 0199976 _____ () C:\ProgramData\NCCD.log
2017-05-27 06:36 - 2012-08-31 09:49 - 0024772 _____ () C:\ProgramData\P1210DEF.css
2017-05-27 06:36 - 2017-05-27 06:36 - 0016219 _____ () C:\ProgramData\P1210OS.HTM
2017-05-27 06:36 - 2012-08-31 09:49 - 0002944 _____ () C:\ProgramData\P1210SIG.GIF
 
Some files in TEMP:
====================
2016-12-14 07:37 - 2016-12-14 07:37 - 17156848 _____ (IObit                                                       ) C:\Users\WINDOW 7\AppData\Local\Temp\7C80.tmp.exe
2015-09-24 16:53 - 2015-09-24 16:54 - 4236616 _____ (Google) C:\Users\WINDOW 7\AppData\Local\Temp\B21F.exe
2016-12-14 07:44 - 2016-12-14 07:45 - 53124496 _____ (UCWeb Inc.) C:\Users\WINDOW 7\AppData\Local\Temp\Browser_V5.7.16400.16_f_4730_(Build1611171340).exe
2016-12-14 07:47 - 2016-12-14 07:47 - 0308538 _____ (sunnyday                                                    ) C:\Users\WINDOW 7\AppData\Local\Temp\BSIJN7ZLHH.exe
2017-01-05 10:21 - 2017-01-05 10:21 - 7596123 _____ (SoftVipDownload) C:\Users\WINDOW 7\AppData\Local\Temp\EASEUS Data Recovery Wizard Professional v5.5.1 Final Full.exe
2016-12-14 07:45 - 2016-12-14 07:46 - 1107880 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\inst_buychannel_06.exe
2016-12-14 07:37 - 2016-12-14 07:37 - 10250125 _____ (                                                            ) C:\Users\WINDOW 7\AppData\Local\Temp\jg3.6.0.exe
2014-07-12 05:12 - 2014-07-12 05:12 - 0918952 _____ (Oracle Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
2014-07-28 13:15 - 2014-07-28 13:15 - 0918440 _____ (Oracle Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
2014-09-30 01:06 - 2014-12-23 05:27 - 0937896 _____ (Oracle Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
2016-12-15 14:06 - 2016-12-15 14:06 - 2458672 _____ (The OpenSSL Project, http://www.openssl.org/)C:\Users\WINDOW 7\AppData\Local\Temp\libeay32.dll
2015-04-02 00:20 - 2016-11-10 12:25 - 0186280 _____ (RealNetworks, Inc.) C:\Users\WINDOW 7\AppData\Local\Temp\lowproc.exe
2016-12-14 07:41 - 2016-12-14 07:46 - 48156456 _____ (www.ludashi.com) C:\Users\WINDOW 7\AppData\Local\Temp\ludashisetup.exe
2016-12-14 08:05 - 2016-12-14 08:05 - 0210840 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\mininewsrepair.exe
2016-12-15 14:06 - 2016-12-15 14:06 - 0970912 _____ (Microsoft Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\msvcr120.dll
2015-09-24 16:03 - 2015-09-24 16:03 - 0724256 _____ (Opera Software) C:\Users\WINDOW 7\AppData\Local\Temp\Opera_NI_stable.exe
2014-11-08 16:33 - 2015-05-21 21:04 - 0610816 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\Quarantine.exe
2016-12-14 07:40 - 2016-12-11 23:26 - 1160549 _____ (                                                            ) C:\Users\WINDOW 7\AppData\Local\Temp\setup.exe
2016-12-15 14:06 - 2016-12-15 14:06 - 0772672 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\sqlite3.dll
2015-04-02 00:20 - 2016-11-10 12:25 - 0096496 _____ (RealNetworks, Inc.) C:\Users\WINDOW 7\AppData\Local\Temp\stubhelper.dll
2015-02-19 17:08 - 2015-02-19 17:10 - 12684696 _____ (                                                            ) C:\Users\WINDOW 7\AppData\Local\Temp\UmmyVideoDownloader.exe
2014-09-06 09:52 - 2014-09-06 09:53 - 24743106 _____ () C:\Users\WINDOW 7\AppData\Local\Temp\vlc-2.1.5-win32.exe
2006-05-24 13:10 - 2006-05-24 13:10 - 0455600 ____R (Macrovision Corporation) C:\Users\WINDOW 7\AppData\Local\Temp\_isA9B6.exe
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\Drivers\baa8764732b1925675da2f885b26b9b6.sys
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-06-13 20:42
 
==================== End of FRST.txt ============================

  • 0

#7
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,577 posts
That log is called FRST.txt

I already have that one.

I want the adwCleaner log, it's also automatically saved here--C:\AdwCleaner\AdwCleaner[C0].txt

Copy and paste that log to a reply.
  • 0

#8
Sunshine-cures

Sunshine-cures

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
# AdwCleaner v6.047 - Logfile created 17/06/2017 at 12:23:31
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-06-16.2 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X86)
# Username : WINDOW 7 - WINDOW7-PC
# Running from : C:\Users\WINDOW 7\Desktop\adwcleaner_6.047.exe
# Mode: Clean
 
 
 
***** [ Services ] *****
 
[-] Service deleted: ucdrv
[-] Service deleted: GmSvc
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\Users\WINDOW 7\AppData\Roaming\navplugin
[-] Folder deleted: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师
[-] Folder deleted: C:\Program Files\Plumbytes Software
[-] Folder deleted: C:\Program Files\Maoha
[-] Folder deleted: C:\Users\WINDOW 7\AppData\Local\svchost
[-] Folder deleted: C:\Windows\system32\SSL
[-] Folder deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ppgplhcfmaadpnkmnkhgadmaekeldbnh
[-] Folder deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Extension Settings\ppgplhcfmaadpnkmnkhgadmaekeldbnh
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UC浏览器.lnk
[-] File deleted: C:\TOSTACK
[#] File deleted: C:\Windows\system32\DRIVERS:X86
[-] File deleted: C:\Users\WINDOW~1\AppData\Local\Temp\YeapUserInfo.ini
[-] File deleted: C:\Windows\system32\chtbrkg.dll
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\chrome-extension_ppgplhcfmaadpnkmnkhgadmaekeldbnh_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\chrome-extension_ppgplhcfmaadpnkmnkhgadmaekeldbnh_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_akz.imgfarm.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_akz.imgfarm.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_ext.dl.tb.ask.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_ext.dl.tb.ask.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_fromdoctopdf.dl.tb.ask.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_fromdoctopdf.dl.tb.ask.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_hp.myway.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_hp.myway.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_myscrapnook.dl.tb.ask.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_myscrapnook.dl.tb.ask.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_pdfconverterhq.dl.tb.ask.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_pdfconverterhq.dl.tb.ask.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_qtipr.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_qtipr.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_televisionfanatic.dl.tb.ask.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_televisionfanatic.dl.tb.ask.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_ttdetect.staticimgfarm.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_ttdetect.staticimgfarm.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_www.plumbytes.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_www.plumbytes.com_0.localstorage-journal
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_www.yeadesktop.com_0.localstorage
[-] File deleted: C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\hxxp_www.yeadesktop.com_0.localstorage-journal
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
[-] Shortcut disinfected: C:\Users\Public\Desktop\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\Users\WINDOW 7\Desktop\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Shortcut disinfected: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Shortcut disinfected: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\WINDOW 7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk
 
 
***** [ Scheduled Tasks ] *****
 
[-] Task deleted: UCBrowserUpdaterCore
[-] Task deleted: Microsoft\Windows\Multimedia\Manager
[-] Task deleted: UCBrowserSecureUpdater
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML
[-] Key deleted: HKU\.DEFAULT\Software\UpgSvr
[-] Key deleted: HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\360WallPaper
[-] Key deleted: HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\dlr
[-] Key deleted: HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\PopWnd
[-] Key deleted: HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\UpgSvr
[-] Key deleted: HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\QiLu Inc.
[-] Key deleted: HKU\S-1-5-21-3689701632-257498136-1677522028-1000\Software\drpsu
[#] Key deleted on reboot: HKU\S-1-5-18\Software\UpgSvr
[#] Key deleted on reboot: HKCU\Software\360WallPaper
[#] Key deleted on reboot: HKCU\Software\dlr
[#] Key deleted on reboot: HKCU\Software\PopWnd
[#] Key deleted on reboot: HKCU\Software\UpgSvr
[#] Key deleted on reboot: HKCU\Software\QiLu Inc.
[#] Key deleted on reboot: HKCU\Software\drpsu
[-] Key deleted: HKLM\SOFTWARE\jhdbca
[-] Key deleted: HKLM\SOFTWARE\{84416237-6490-494D-9AD6-4994DD978971}
[-] Key deleted: HKLM\SOFTWARE\QiLu Inc.
[-] Key deleted: HKLM\SOFTWARE\Microsoft\DMunversion
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktop.com
[-] Value deleted: HKCU\SOFTWARE\Classes\.crx\OpenWithProgids [UCHTML.AssocFile.CRX]
[-] Value deleted: HKCU\SOFTWARE\Classes\.htm\OpenWithProgids [UCHTML.AssocFile.HTM]
[-] Value deleted: HKCU\SOFTWARE\Classes\.html\OpenWithProgids [UCHTML.AssocFile.HTML]
[-] Value deleted: HKCU\SOFTWARE\Classes\.mht\OpenWithProgids [UCHTML.AssocFile.MHT]
[-] Value deleted: HKCU\SOFTWARE\Classes\.shtm\OpenWithProgids [UCHTML.AssocFile.SHTM]
[-] Value deleted: HKCU\SOFTWARE\Classes\.shtml\OpenWithProgids [UCHTML.AssocFile.SHTML]
[-] Value deleted: HKCU\SOFTWARE\Classes\.webp\OpenWithProgids [UCHTML.AssocFile.WEBP]
[-] Value deleted: HKCU\SOFTWARE\Classes\.xht\OpenWithProgids [UCHTML.AssocFile.XHT]
[-] Value deleted: HKCU\SOFTWARE\Classes\.xhtml\OpenWithProgids [UCHTML.AssocFile.XHTML]
[-] Value deleted: HKLM\SOFTWARE\Classes\.htm\OpenWithProgids [UCHTML.AssocFile.HTM]
[-] Value deleted: HKLM\SOFTWARE\Classes\.html\OpenWithProgids [UCHTML.AssocFile.HTML]
[-] Value deleted: HKLM\SOFTWARE\Classes\.mht\OpenWithProgids [UCHTML.AssocFile.MHT]
[-] Value deleted: HKLM\SOFTWARE\Classes\.shtm\OpenWithProgids [UCHTML.AssocFile.SHTM]
[-] Value deleted: HKLM\SOFTWARE\Classes\.shtml\OpenWithProgids [UCHTML.AssocFile.SHTML]
[-] Value deleted: HKLM\SOFTWARE\Classes\.webp\OpenWithProgids [UCHTML.AssocFile.WEBP]
[-] Value deleted: HKLM\SOFTWARE\Classes\.xht\OpenWithProgids [UCHTML.AssocFile.XHT]
[-] Value deleted: HKLM\SOFTWARE\Classes\.xhtml\OpenWithProgids [UCHTML.AssocFile.XHTML]
[-] Key deleted: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{181480C8-90AC-3430-B39A-CD121E034A1A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{8F54FA54-1DF8-3B20-890C-CDD95364BC95}
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Web data] [Search Provider] Deleted: google
[-] [C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\WINDOW 7\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [extension] Deleted: ppgplhcfmaadpnkmnkhgadmaekeldbnh
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [22560 Bytes] - [14/12/2016 18:03:33]
C:\AdwCleaner\AdwCleaner[C2].txt - [4069 Bytes] - [16/12/2016 10:52:36]
C:\AdwCleaner\AdwCleaner[C3].txt - [10419 Bytes] - [17/06/2017 12:23:31]
C:\AdwCleaner\AdwCleaner[R0].txt - [13347 Bytes] - [28/05/2015 09:48:38]
C:\AdwCleaner\AdwCleaner[S0].txt - [13546 Bytes] - [28/05/2015 09:50:34]
C:\AdwCleaner\AdwCleaner[S1].txt - [21571 Bytes] - [14/12/2016 18:00:47]
C:\AdwCleaner\AdwCleaner[S2].txt - [4151 Bytes] - [16/12/2016 10:51:26]
C:\AdwCleaner\AdwCleaner[S3].txt - [11097 Bytes] - [17/06/2017 12:20:01]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [10862 Bytes] ##########
    
 
 
 
 
This one? 

  • 0

#9
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,577 posts
Very good.

Next

Post the JRT.txt Log.

That one should be on the desktop in a notepad looking thing. Copy it then paste it into your next reply.

And the Malwarebytes log too


Thank you

:)
  • 0

#10
Sunshine-cures

Sunshine-cures

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

related to this topic, since now my computer is cleaned up, is the window defender enuff to protect it? or do i have to buy any anti virus software? or is there anything that i can use for free for a while and then check what is best for me? 


  • 0

#11
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,577 posts
Your computer is not cleaned up. We have a long ways to go here.

As far as Anti Virus you can uninstall:
Quick Heal AntiVirus Pro
And for now install Avast free: You may change that later if you want.
https://www.avast.co...ivirus-download. <----Get avast free here.

Now

Please follow instructions in post # 9. I want the JRT.txt Log and the Malwarebytes log.
Copy an paste those logs in you next reply.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP