i have hp pavilion laptop with windows 8.1.
whenever i connect to internet avast keeps giving notification that it blocked a virus.
infection details are
url - hxxp://differentia.ru/diff.php
infection - url:mal
process - C:\WINDOWS\SysWOW64\msiexec.exe
url - hxxp://disorderstatus.ru/order.php
infection - url:mal
process - C:\WINDOWS\SysWOW64\msiexec.exe
no apparent changes while using the computer.
from FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-08-2015
Ran by bibeksujita (administrator) on BIBEK (13-08-2015 11:37:29)
Running from C:\Users\bibeksujita\Desktop
Loaded Profiles: bibeksujita (Available Profiles: bibeksujita)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Filipe Lourenço) C:\Program Files (x86)\BatteryCare\BatteryCare.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
() C:\ProgramData\DatacardService\DCService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Somoto) C:\Users\bibeksujita\AppData\Local\FilesFrog Update Checker\update_checker.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
() C:\Program Files (x86)\Photodex\ProShow Gold\scsiaccess.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
() C:\Users\bibeksujita\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
() C:\Users\bibeksujita\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(CANON INC.) C:\Windows\System32\CNAB5RPD.EXE
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(Dropbox, Inc.) C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-08-10] (IDT, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [6109776 2015-08-13] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1743136 2013-05-29] (Wondershare)
HKLM-x32\...\Run: [BrowserPlugInHelper] => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\BrowserPlugInHelper.exe [1962896 2013-12-19] ()
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Advanced SystemCare 5] => C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe [1647448 2011-11-12] (IObit)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Google Update] => C:\Users\bibeksujita\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-05-31] (Google Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3825232 2014-05-28] (Tonec Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [FLV Player] => C:\Users\bibeksujita\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe [202752 2012-10-26] ()
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Dropbox Update] => C:\Users\bibeksujita\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-19] (Dropbox, Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [AppsHat] => C:\Users\bibeksujita\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [202752 2012-10-26] ()
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [GoogleChromeAutoLaunch_D6EBCAA31125C79C9AF7C27C47CA8B0A] => C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe [813896 2015-08-08] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP2900 Status Window.lnk [2014-08-24]
ShortcutTarget: Canon LBP2900 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE (CANON INC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP3300 Status Window.lnk [2015-02-16]
ShortcutTarget: Canon LBP3300 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB5LAD.EXE (CANON INC.)
Startup: C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-11]
ShortcutTarget: Dropbox.lnk -> C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll [2015-08-13] (AVAST Software)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2012-11-16] (Tonec Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPNOT13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT13/1
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPNOT13/1
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT13/1
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
URLSearchHook: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 - UsProvider Class - {539F76FD-084E-4858-86D5-62F02F54AE86} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2013-11-29] (Internet Download Manager, Tonec Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-13] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2013-05-02] (Orbitdownloader.com)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2013-11-29] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Wondershare Video Converter Ultimate -> {65DEE40A-3E93-4cae-9F98-B8E06DCEE2BF} -> C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRIEPlugin.dll [2013-12-19] (Wondershare Software Co., Ltd.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-13] (AVAST Software)
BHO-x32: MinibarBHO -> {AA74D58F-ACD0-450D-A85E-6C04B171C044} -> C:\Program Files (x86)\Minibar\Minibar.dll [2013-09-19] (KangoExtensions)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll [2007-02-16] (IDM)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-10] (Hewlett-Packard)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll [2013-05-02] ()
Toolbar: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-02] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{12AB8B55-C5E3-479D-9E26-67733A9B0DAC}: [NameServer] 116.68.209.16 116.68.213.14
Tcpip\..\Interfaces\{18CDEEB9-AF2F-47B7-8DC5-6EA3333E35EF}: [NameServer] 116.68.209.16 116.68.213.14
Tcpip\..\Interfaces\{4043E7E1-5004-4A69-B2C5-903B9A73FFB9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{AC5F13DC-A531-4747-87CE-21B5FF86DBC3}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{BD814FAA-4217-46C0-B993-C33CC1D055AC}: [NameServer] 116.68.209.16 116.68.213.14
FireFox:
========
FF ProfilePath: C:\Users\bibeksujita\AppData\Roaming\Mozilla\Firefox\Profiles\moclw1el.default-1417698431251
FF NetworkProxy: "type",
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll [2013-06-01] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll [2013-06-01] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-25] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-09] (Microsoft Corporation)
FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [2013-10-18] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-05-31] ()
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1476312255-3866232785-3835862293-1002: @tools.google.com/Google Update;version=3 -> C:\Users\bibeksujita\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1476312255-3866232785-3835862293-1002: @tools.google.com/Google Update;version=9 -> C:\Users\bibeksujita\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2013-05-31]
FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2013-05-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2013-07-25]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-25]
FF HKLM-x32\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt [2014-09-16]
FF HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\bibeksujita\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\bibeksujita\AppData\Roaming\IDM\idmmzcc5 [2014-05-28]
FF HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\bibeksujita\AppData\Roaming\IDM\idmmzcc5
Chrome:
=======
CHR Profile: C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Freemake Video Downloader) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2013-05-31]
CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2014-09-16]
CHR Extension: (Freemake Youtube Download Button) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2013-05-31]
CHR Extension: (Pin It Button) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-03-11]
CHR Extension: (IDM Integration Module) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-05-28]
CHR Extension: (My Browser Page) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghfknlgajlcihkhkhnlcoffhbohnlbg [2014-07-18]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (MyWebFace) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\njienacjggibaeolcbbjfnigbojkcggj [2015-01-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-05-31]
CHR HKLM-x32\...\Chrome\Extension: [chgdeabpmphfhkoemjjglmilajldekbp] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRChromePlugin.crx [2014-09-16]
CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2013-05-31]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2015-04-12]
CHR HKLM-x32\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-01-17]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService5; C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [490840 2011-11-10] (IObit)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-08] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [146600 2015-08-13] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [217088 2013-03-22] (Connectify) [File not signed]
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed]
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-04-15] (Freemake) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2015-04-15] (Ellora Assets Corp.) [File not signed]
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-11] (Hewlett-Packard Company) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625648 2015-06-08] (Lenovo)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2013-10-18] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-07-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-07-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-07-22] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe" [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-13] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-08-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-13] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-13] (AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3860480 2013-08-23] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-18] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 cmshusbser; C:\Windows\system32\DRIVERS\cmshusbser.sys [127232 2011-11-30] (QUALCOMM Incorporated)
S1 cnnctfy3; C:\Windows\system32\DRIVERS\cnnctfy3.sys [34840 2013-10-18] (Connectify)
S3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [252928 2010-04-30] (Huawei Technologies Co., Ltd.)
S3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [29696 2012-10-11] (ManyCam LLC)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-12] (CACE Technologies, Inc.)
S3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [30336 2007-01-18] (Research in Motion Ltd)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
R3 WinRing0_1_2_0; C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
R3 WsAudio_Device; C:\Windows\system32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare)
S3 RimUsb; \SystemRoot\System32\Drivers\RimUsb_AMD64.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys [X]
========================== Drivers MD5 =======================
C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
C:\Windows\system32\DRIVERS\Accelerometer.sys 899B7E724BF19F17978B6A37B864A277
C:\Windows\System32\drivers\ACPI.sys 9539F7917B4B6D92C90F0FAA6B86C605
C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
C:\Windows\system32\drivers\afd.sys 374E27295F0A9DCAA8FC96370F9BEEA5
C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
C:\Windows\System32\DRIVERS\ahcache.sys 8E8E34B7BA059050EED827410D0697A2
C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
C:\Windows\system32\DRIVERS\atikmdag.sys F931C2ED6C8294909C10657DCB9A9A4E
C:\Windows\system32\DRIVERS\atikmpag.sys 0D481A7FE3A66724DC11AD8A4E417A9A
C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
C:\Windows\System32\drivers\amd_sata.sys A2EFE3869B976296E097DEF368280F95
C:\Windows\System32\drivers\amd_xata.sys 625396421C29FB305C6C6235D01130B8
C:\Windows\system32\drivers\appid.sys 04951A9A937CBE28A2D3FEEA360B6D1F
C:\Windows\system32\DRIVERS\appexDrv.sys 44695679881DEB85CAD7C249B151066E
C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
C:\Windows\system32\drivers\aswHwid.sys 525F5989C095F5757414E1F4B39175B2
C:\Windows\system32\drivers\aswMonFlt.sys 76D585093398DB973470BB83FCF0CE52
C:\Windows\system32\drivers\aswRdr2.sys 719FF5568B5E71832541636E2A7DFE27
C:\Windows\System32\Drivers\aswRvrt.sys 21C13E3C9B801C8AE172FABBD235221E
C:\Windows\system32\drivers\aswSnx.sys 5B6A864A2CE292992040CEBAFC8F746A
C:\Windows\system32\drivers\aswSP.sys C43A0929DE32035499D6BB39A7F44439
C:\Windows\system32\drivers\aswStm.sys 763C27EA21875F54615A0174EEC78FC4
C:\Windows\System32\Drivers\aswVmm.sys C85B35201A253B99199C0A9F5B98FC18
C:\Windows\system32\DRIVERS\asyncmac.sys 3DB7721F06BC2FEDB25029EA23AB27DA
C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
C:\Windows\system32\DRIVERS\athwbx.sys 509AE5E446B2171D03401F3DD3C2E682
C:\Windows\system32\drivers\AtihdW86.sys 506907D2E7F3A5B67DBD39C00A788B7C
C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
C:\Windows\System32\drivers\BasicRender.sys 38A82F4EE8C416A6744B6D30381ED768
C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
C:\Windows\System32\drivers\bthhfenum.sys 746B9F94214915AECDE4B7FEA5FF9664
C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
C:\Windows\System32\drivers\bthmodem.sys 66B791F6B11DC4303DD18A224A501542
C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
C:\Windows\System32\drivers\CLFS.sys 179A41249055D5F039F1B6703F3B6D2B
C:\Windows\system32\DRIVERS\CLVirtualDrive.sys 075CCE75090786F124573A788C8656E6
C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
C:\Windows\system32\DRIVERS\cmshusbser.sys 55D0611746F05C708F445E574182236F
C:\Windows\System32\Drivers\cng.sys 1CD3A907D64D08F49208DA00B69BF35E
C:\Windows\system32\DRIVERS\cnnctfy3.sys 99DA8A69284811F7B227D013B41C12FB
C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
C:\Windows\System32\drivers\dam.sys 315BA4BC19316D72B2E037534E048B93
C:\Windows\System32\Drivers\dfsc.sys A03F362C5557E238CBFA914689C77248
C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
C:\Windows\system32\drivers\drmkaud.sys DDC11A202207C0400CBE07315B8FDE5E
C:\Windows\System32\drivers\dxgkrnl.sys C7D252742946DD395670649742FBD73D
C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
C:\Windows\system32\DRIVERS\ewusbnet.sys DA7CEF9FFBBD6498DF106BCAB84EB10A
C:\Windows\system32\DRIVERS\ew_hwusbdev.sys E2CBB821C7CAE0EF8B56DE28ED85C740
C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
C:\Windows\System32\drivers\fileinfo.sys BCFD8B149B3ADF92D0DB1E909CAF0265
C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
C:\Windows\System32\drivers\fltmgr.sys 6592D192E2823C043EDBC010E7774053
C:\Windows\System32\drivers\FsDepends.sys 35005534E600E993A90B036E4E599F2B
C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
C:\Windows\System32\DRIVERS\fvevol.sys F152D55E497E12256290C43B31C7D0CE
C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
C:\Windows\System32\Drivers\msgpioclx.sys EF3AE7773394DF49CE74AF78A1C8D23D
C:\Windows\System32\drivers\HDAudBus.sys 498288DD5CA42C2D36D125893E968C53
C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
C:\Windows\System32\drivers\hidbth.sys 1EA1B4FABB8CC348E73CA90DBA22E104
C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
C:\Windows\System32\drivers\hidusb.sys 8DB8EAB9D0C6A5DF0BDCADEA239220B4
C:\Windows\System32\DRIVERS\hpdskflt.sys D104FF402FC3DDB686E6DEF00334DB26
C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
C:\Windows\System32\drivers\HTTP.sys 9DDCA7F18983C5410DEFF79F819DF93C
C:\Windows\System32\drivers\ew_jubusenum.sys 6DBD08BC1331C78548298E82C4B667C5
C:\Windows\system32\DRIVERS\ewusbmdm.sys 6E5CD3984742A922D0C183C7E82C3C94
C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
C:\Windows\System32\drivers\i8042prt.sys 84CFC5EFA97D0C965EDE1D56F116A541
C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
C:\Windows\System32\drivers\iaStorA.sys 050F2539E14F9D5E90A4B61738EC29BD
C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
C:\Windows\system32\DRIVERS\idmwfp.sys 929DF302F15BFE24AC66EF45D858C413
C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
C:\Windows\System32\drivers\intelpep.sys 139CFCDCD36B1B1782FD8C0014AC9B0E
C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
C:\Windows\System32\drivers\IPMIDrv.sys FD9C9E9E3F0ED51502C7E8C066BE26B9
C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
C:\Windows\System32\drivers\msiscsi.sys D90AB68D0FAC9F357F663670FDBB511E
C:\Windows\System32\drivers\kbdclass.sys 8BE92376799B6B44D543E8D07CDCF885
C:\Windows\System32\drivers\kbdhid.sys FB6E47E569D4872ABEB506BE03A45FBA
C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
C:\Windows\System32\Drivers\ksecdd.sys ADDECBCC777665BD113BED437E602AB0
C:\Windows\System32\Drivers\ksecpkg.sys F88CC88F4A6D8476F1664E805CA18CC2
C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
C:\Windows\system32\drivers\luafv.sys DDEE191AB32DFC22C6465002ECDF5EE4
C:\Windows\system32\DRIVERS\mcvidrv_x64.sys DE585D1D266805E5EEDAE911FDD16F38
C:\Windows\system32\drivers\mcaudrv_x64.sys 2E7FFDEF8BAFD04CBB517507B821E878
C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
C:\Windows\System32\drivers\mouclass.sys CEAC6D40FE887CE8406C2393CF97DE06
C:\Windows\System32\drivers\mouhid.sys 02D98BF804084E9A0D69D1C69B02CCA9
C:\Windows\System32\drivers\mountmgr.sys 515549560D481138E6E21AF7C6998E56
C:\Windows\System32\drivers\mpsdrv.sys F170510BE94CF45E3C6274578F6204B2
C:\Windows\system32\drivers\mrxdav.sys 1D55DADC22D21883A2F80297F5A5AE48
C:\Windows\System32\DRIVERS\mrxsmb.sys 0696F66E4D423793951A60562F794D14
C:\Windows\System32\DRIVERS\mrxsmb10.sys 3E28B99198B514DFEB152EACF913025E
C:\Windows\System32\DRIVERS\mrxsmb20.sys DBA635C6398782C549E3BE45CF1D0411
C:\Windows\system32\DRIVERS\bridge.sys 4E888019078AC363076A5433E89AA4F8
C:\Windows\System32\Drivers\Msfs.sys D13329FBF8345B28AB30F44CC247DC08
C:\Windows\System32\drivers\msgpiowin32.sys C6B474E46F9E543B875981ED3FFE6ADD
C:\Windows\System32\drivers\mshidkmdf.sys 65C92EB9D08DB5C69F28C7FFD4E84E31
C:\Windows\System32\drivers\mshidumdf.sys 52299F086AC2DAFD100DD5DC4A8614BA
C:\Windows\System32\drivers\msisadrv.sys 36D92AF3343C3A3E57FEF11C449AEA4C
C:\Windows\system32\drivers\MSKSSRV.sys A9BBBD2BAE6142253B9195E949AC2E8D
C:\Windows\system32\DRIVERS\mslldp.sys 375E44168F2DFB91A68B8A3F619C5A7C
C:\Windows\system32\drivers\MSPCLOCK.sys 7B2128EB875DCBC006E6A913211006D6
C:\Windows\system32\drivers\MSPQM.sys 1E88171579B218115C7A772F8DE04BD8
C:\Windows\System32\Drivers\MsRPC.sys BBE2A455053E63BECBF42C2F9B21FAE0
C:\Windows\System32\drivers\mssmbios.sys 8D6B7D515C5CBCDB75B928A0B73C3C5E
C:\Windows\system32\drivers\MSTEE.sys 115019AE01E0EB9C048530D2928AB4A2
C:\Windows\System32\drivers\MTConfig.sys 96D604A35070360F0DD4A7A8AF410B5E
C:\Windows\System32\Drivers\mup.sys 619CA29326B82372621DB2C0964D8365
C:\Windows\System32\drivers\mvumis.sys B8C35C94DCB2DFEAF03BB42131F2F77F
C:\Windows\system32\DRIVERS\nwifi.sys 78514B073CC5775800A65BFB82A0D66B
C:\Windows\System32\drivers\ndis.sys F21B77B4D74092A543807D3CEB711A88
C:\Windows\system32\DRIVERS\ndiscap.sys C6BB12BC35D1637CA17AE16D3A4725EB
C:\Windows\system32\DRIVERS\NdisImPlatform.sys 9F1DA20E943BE7AA4ED5F3E1EBA78B37
C:\Windows\system32\DRIVERS\ndistapi.sys 9423421E735BD5394351E0C47C76BB92
C:\Windows\system32\DRIVERS\ndisuio.sys B832B35055BA2B7B4181861FF94D8E59
C:\Windows\System32\drivers\NdisVirtualBus.sys 1F58E48EF75F34C35D8E93A0DC535CFE
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\System32\Drivers\NDProxy.sys A5BD69A8812FA79D1A487691DD3FB244
C:\Windows\System32\drivers\Ndu.sys 5A072F0B90C29C5233D78BE33EF5ED78
C:\Windows\System32\DRIVERS\netbios.sys A83D67D347A684F10B7D3019C8A6380C
C:\Windows\System32\DRIVERS\netbt.sys 0217532E19A748F0E5D569307363D5FD
C:\Windows\system32\DRIVERS\netvsc63.sys 70414DB660BFBB7BD58FCE8EA4364E1B
C:\Windows\System32\drivers\npf.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys 8F44A2F57C9F1A19AC9C6288C10FB351
C:\Windows\System32\drivers\npsvctrig.sys CBDB4F0871C88DF930FC0E8588CA67FC
C:\Windows\System32\drivers\nsiproxy.sys E490B459978CB87779E84C761D22B827
C:\Windows\System32\Drivers\Ntfs.sys 1C80517BE6836A812F6A9B99B8321351
C:\Windows\System32\Drivers\Null.sys EF1B290FC9F0E47CC0B537292BEE5904
C:\Windows\System32\drivers\nvraid.sys BC6B5942AFF25EBAF62DE43C3807EDF8
C:\Windows\System32\drivers\nvstor.sys 1F43ABFFAC3D6CA356851D517392966E
C:\Windows\System32\drivers\nv_agp.sys 6934A936A7369DFE37B7DBA93F5E5E49
C:\Windows\System32\drivers\parport.sys 764B1121867B2D9B31C491668AC72B2B
C:\Windows\System32\drivers\partmgr.sys EF0C1749C9A8CEE9A457473D433CC00F
C:\Windows\System32\drivers\pci.sys 275AFE3FA35E8D78BE97695DF49817C6
C:\Windows\System32\drivers\pciide.sys 346E38FCC6859A727DD28AFAD1F0AFF4
C:\Windows\System32\drivers\pcmcia.sys 4D3BDCC1C7B40C9D7B6AD990E6DEC397
C:\Windows\System32\drivers\pcw.sys BF28771D1436C88BE1D297D3098B0F7D
C:\Windows\System32\drivers\pdc.sys B9D968D8E2B0F9C6301CEB39CFC9B9E4
C:\Windows\System32\drivers\peauth.sys 0ECEE590F2E2EF969FB74A6FC583A1E6
C:\Windows\system32\DRIVERS\raspptp.sys E075CC071022BD4E9BE7C024717C0E0A
C:\Windows\System32\drivers\processr.sys ECD373F9571C745894367CC2635EA44F
C:\Windows\system32\DRIVERS\pacer.sys 8528BB05E4D4E25945F78B00B2555FB7
C:\Windows\System32\Drivers\PxHlpa64.sys BC08F7F3C53CBEE68670ED1314E290FD
C:\Windows\system32\drivers\qwavedrv.sys 3FB466684609A4329858CF2EBD62E0FD
C:\Windows\System32\DRIVERS\rasacd.sys 2C56F0EE27E4EF70CA4B4983D3638905
C:\Windows\system32\DRIVERS\AgileVpn.sys 55FE43112F61836D0581D615C72AA113
C:\Windows\system32\DRIVERS\rasl2tp.sys BBB6272B7F46C4640A8CDB8A70C3450F
C:\Windows\system32\DRIVERS\raspppoe.sys 5247F308C4103CDC4FE12AE1D235800A
C:\Windows\system32\DRIVERS\rassstp.sys 2B0F1677CDD08967005F34488559BC6F
C:\Windows\System32\DRIVERS\rdbss.sys A1A5E79C0D1352AFDC08328A623DA051
C:\Windows\System32\drivers\rdpbus.sys 6B21EBF892CD8CACB71669B35AB5DE32
C:\Windows\System32\drivers\rdpdr.sys 680C1DAE268B6FB67FA21B389A8B79EF
C:\Windows\System32\drivers\rdpvideominiport.sys 858776908AF838E3790F3261B799CDA6
C:\Windows\System32\drivers\rdyboost.sys A26AEC49F318FEE141DDDB2C5F99B3E6
C:\Windows\System32\Drivers\ReFS.sys E515A287C8FAE901EB8FB42F168E14F2
C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys 0DE22421179D5A8440B68517DDF2B051
C:\Windows\System32\Drivers\RootMdm.sys A0AF9EBF560FDD0E044E04C0AF9FF9E6
C:\Windows\system32\DRIVERS\RtsP2Stor.sys D38250F459BF60D6F4B69B79DCD948CC
C:\Windows\system32\DRIVERS\rspndr.sys 2D05A5508F4685412F2B89E8C2189ABC
C:\Windows\system32\DRIVERS\Rt630x64.sys 34DA0D14F5C3F1883A331AFB975AB434
C:\Windows\System32\drivers\vms3cap.sys 1A063730F221B2746FF00457AE17E4F0
C:\Windows\System32\drivers\sbp2port.sys C624A1B32211C3166EDB3F4AB02A30B7
C:\Windows\System32\DRIVERS\scfilter.sys ABD0237B15DBD2B4695F4B7D734A58F7
C:\Windows\System32\drivers\sdbus.sys FDEC5799BA499D18AFA3A540538866E7
C:\Windows\System32\drivers\sdstor.sys 0B1E929D11A8E358106955603FAC65E8
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\SerCx.sys DB2FF24CE0BDD15FE75870AFE312BA89
C:\Windows\System32\drivers\SerCx2.sys 0044B31F93946D5D41982314381FE431
C:\Windows\System32\drivers\serenum.sys 3CD600C089C1251BEEB4CD4CD5164F9E
C:\Windows\System32\drivers\serial.sys D864381BC9C725FAB01D94C060660166
C:\Windows\System32\drivers\sermouse.sys 0BD2B65DCE756FDE95A2E5CCCBF7705D
C:\Windows\System32\drivers\sfloppy.sys 472B7A5AC181C050888DB454663DD764
C:\Windows\System32\drivers\SiSRaid2.sys 2F518D13DD6F3053837FE606F1A2EA1F
C:\Windows\System32\drivers\sisraid4.sys 1AC9A200A9C49C4508F04AAFFCA34A3F
C:\Windows\System32\drivers\Smb_driver_AMDASF.sys AF5CC3F9B88F140D78FC967ABF0F4EC7
C:\Windows\System32\drivers\Smb_driver_Intel.sys 19555D03CB179BED8B8AAA239A36BDA4
C:\Windows\System32\drivers\spaceport.sys 33977549C2CED09936E05BEE7659EAFF
C:\Windows\System32\drivers\SpbCx.sys F337BE11071818FC3F5DC2940B6BDE34
C:\Windows\System32\DRIVERS\srv.sys 2B78788A1485F9B99A578A299DF42C02
C:\Windows\System32\DRIVERS\srv2.sys FD163F487CBA9C98AFFEB546C80F49A2
C:\Windows\System32\DRIVERS\srvnet.sys 716059F37BCCB1ABEDE99EBE82E8E362
C:\Windows\System32\drivers\stexstor.sys 366DEA74BBA65B362BCCFC6FC2ADFD8B
C:\Windows\system32\DRIVERS\stwrt64.sys 32BE0B7CCA47A5BE30E7E43DC54B54F3
C:\Windows\System32\drivers\storahci.sys 0ED2E318ABB68C1A35A8B8038BDB4C90
C:\Windows\System32\DRIVERS\vmstorfl.sys 7A08CEE1535F5A448215634C5EA74E50
C:\Windows\System32\drivers\stornvme.sys 6B06E2D11E604BE2B1A406C4CB3B90DE
C:\Windows\System32\drivers\storvsc.sys 548759755BC73DAD663250239D7E0B9F
C:\Windows\System32\drivers\swenum.sys 84E0F5D41C138C5CC975137A2A98F6D3
C:\Windows\system32\DRIVERS\SynTP.sys 0F34FE968C91D02CE30D76C257F2BDA0
C:\Windows\system32\DRIVERS\taphss6.sys DA0780D55E8CF724CF3EF7CCF0F0DB67
C:\Windows\System32\drivers\tcpip.sys 25AC0B50A71938890970E1508F107196
C:\Windows\system32\DRIVERS\tcpip.sys 25AC0B50A71938890970E1508F107196
C:\Windows\System32\drivers\tcpipreg.sys 41CF802064F72E55F50CA0A221FD36D4
C:\Windows\system32\DRIVERS\tdx.sys FFF28F9F6823EB1756C60F1649560BBF
C:\Windows\System32\drivers\terminpt.sys 232D185D2337F141311D0CF1983E1431
C:\Windows\system32\drivers\tpm.sys 82F909359600D3603FE852DB7F135626
C:\Windows\System32\drivers\tsusbflt.sys BF8F54CA37E9C9D6582C31C5761F8C93
C:\Windows\System32\drivers\TsUsbGD.sys E0088068DCE2EE82897027DDB8E05254
C:\Windows\system32\DRIVERS\tunnel.sys C8E0E78B5D284C2FF59BDFFDAF997242
C:\Windows\System32\drivers\uagp35.sys F6EEAD052943B5A3104C1405BB856C54
C:\Windows\System32\drivers\uaspstor.sys FE6067B1FD4E63650C667B33D080565B
C:\Windows\System32\drivers\ucx01000.sys B034A41891A36457B994307DFA772293
C:\Windows\System32\DRIVERS\udfs.sys 1EC649F112896FAE33250F0B97AC5D0B
C:\Windows\System32\drivers\UEFI.sys 9578691F297E1B1F519970FE6D47CB21
C:\Windows\System32\drivers\uliagpkx.sys 5EAB5117DDB24FC4D39E6FFFCF1837B9
C:\Windows\System32\drivers\umbus.sys DA34C39A18E60E7C3FA0630566408034
C:\Windows\System32\drivers\umpass.sys AE8294875E5446E359B1E8035D40C05E
C:\Windows\System32\drivers\usbccgp.sys 433ECDE01A52691FA7ACA51C10C09B70
C:\Windows\System32\drivers\usbcir.sys B3D6457D841A0CAEF4C52D88621715F2
C:\Windows\System32\drivers\usbehci.sys 48BA326A3DBA5B5BEB5F2777F4618696
C:\Windows\system32\DRIVERS\usbfilter.sys 4875DC63E548812C75D4FDEF84970C89
C:\Windows\System32\drivers\usbhub.sys 93435654DCA210298BA0F986EB51C679
C:\Windows\System32\drivers\UsbHub3.sys 83C9C45D59C72FEFDAE9A5686BE31FEA
C:\Windows\System32\drivers\usbohci.sys 3019097FB6C985EF24C058090FF3BDBD
C:\Windows\System32\drivers\usbprint.sys 4D655E3B684BE9B0F7FFD8A2935C348C
C:\Windows\system32\DRIVERS\usbscan.sys F04D164C4168701A4E7835607722E5F1
C:\Windows\System32\drivers\USBSTOR.SYS EA23453240137F6773174E0D93F61A69
C:\Windows\System32\drivers\usbuhci.sys 064260B3A5868AC894A4943543BC7AB7
C:\Windows\System32\Drivers\usbvideo.sys 18F744E8CCEB2670040EBAF7AD77B8C6
C:\Windows\System32\drivers\USBXHCI.SYS 48430B0313FC1CFE3D2400553F1A93CD
C:\Windows\system32\DRIVERS\usb8023x.sys 3CAAB947B1F247A570DE15983BEDEBCF
C:\Windows\System32\drivers\vdrvroot.sys FEB26E3B8345A7E8D62F945C4AE86562
C:\Windows\System32\drivers\VerifierExt.sys A026EDEAA5EECAE0B08E2748B616D4BD
C:\Windows\System32\drivers\vhdmp.sys 52E483A3701A5A61A75A06993720347D
C:\Windows\System32\drivers\viaide.sys 06D38968028E9AB19DE9B618C7B6D199
C:\Windows\System32\drivers\vmbus.sys C6305BDFC4F7CE51F72BB072C03D4ACE
C:\Windows\System32\drivers\VMBusHID.sys DA40BEA0A863CE768C940CA9723BF81F
C:\Windows\System32\drivers\volmgr.sys 55D7D963DE85162F1C49721E502F9744
C:\Windows\System32\drivers\volmgrx.sys CCB9E901F7254BF96D28EB1B0E5329B7
C:\Windows\System32\drivers\volsnap.sys 4BB9BC49DEE1A319EC58274A7BBED663
C:\Windows\System32\drivers\vpci.sys 01355C98B5C3ED1EC446743CDA848FCE
C:\Windows\System32\drivers\vsmraid.sys 4539F45F9F4C9757A86A56C949421E07
C:\Windows\System32\drivers\vstxraid.sys 0849B7260F26FE05EA56DED0672E2F4B
C:\Windows\System32\drivers\vwifibus.sys BE970C369E43B509C1EDA2B8FA7CECB0
C:\Windows\system32\DRIVERS\vwififlt.sys 6B26AD573CCDD5209DF4397438B76354
C:\Windows\system32\DRIVERS\vwifimp.sys 0B48E0DFB44EE475F4FD8A8EE599AF30
C:\Windows\System32\drivers\wacompen.sys 0910AB9ED404C1434E2D0376C2AD5D8B
C:\Windows\system32\DRIVERS\wanarp.sys AFCD4054D61BD708B82991348ED1C763
C:\Windows\system32\DRIVERS\wanarp.sys AFCD4054D61BD708B82991348ED1C763
C:\Windows\system32\drivers\WdBoot.sys F5D4FA3E1F4879C361FFF3855259D2C2
C:\Windows\System32\drivers\wdcsam64.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys CB6C63FF8342B467E2EF76E98D5B934D
C:\Windows\system32\drivers\WdFilter.sys 019CC610AD95FF47EAD7C08B7A683B96
C:\Windows\System32\Drivers\WdNisDrv.sys 6CC1BB8F6851A262E2E824F0E92D5EEF
C:\Windows\System32\DRIVERS\wfplwfs.sys BFBE1C5F57FE7A885673A1962D5532B7
C:\Windows\System32\drivers\wimmount.sys 867BCC69ED9C31C501465EB0E8BA9DFA
C:\Program Files (x86)\BatteryCare\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA
C:\Windows\system32\DRIVERS\WinUSB.sys AC263C2F66405589528995AA41040599
C:\Windows\System32\drivers\WirelessButtonDriver64.sys 4F2A80D65AE6F845776E2F06AE6782ED
C:\Windows\System32\drivers\wmiacpi.sys 2834D9D3B4F554A39C72F00EA3F0E128
C:\Windows\System32\Drivers\Wof.sys 7FC5667DF73D4B04AA457CC3A4180E09
C:\Windows\System32\DRIVERS\wpcfltr.sys 182561A14F2E93E81E66FE3700D17A5A
C:\Windows\System32\drivers\WpdUpFltr.sys 9F2904B55F6CECCD1A8D986B5CE2609A
C:\Windows\system32\drivers\ws2ifsl.sys AE072B0339D0A18E455DC21666CAD572
C:\Windows\system32\drivers\VirtualAudio.sys ADD2FE1A9F4EE41A6D724819550D4E1F
C:\Windows\System32\drivers\WudfPf.sys D537815E450A149752C15868392AD1F3
C:\Windows\System32\drivers\WUDFRd.sys 7CCBBCEE408A5DBE3FE47297DB5A6CFC
C:\Windows\system32\DRIVERS\WUDFRd.sys 7CCBBCEE408A5DBE3FE47297DB5A6CFC
C:\Windows\system32\DRIVERS\WUDFRd.sys 7CCBBCEE408A5DBE3FE47297DB5A6CFC
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three Months Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-13 11:34 - 2015-08-13 11:37 - 00055790 _____ C:\Users\bibeksujita\Desktop\FRST.txt
2015-08-13 11:33 - 2015-08-13 11:37 - 00000000 ____D C:\FRST
2015-08-13 11:33 - 2015-08-13 11:33 - 02173952 _____ (Farbar) C:\Users\bibeksujita\Desktop\FRST64.exe
2015-08-13 11:23 - 2015-08-13 11:23 - 00688992 _____ (Swearware) C:\Users\bibeksujita\Desktop\dds.scr
2015-08-13 11:05 - 2015-08-13 11:05 - 00006664 _____ C:\WINDOWS\PFRO.log
2015-08-13 10:08 - 2015-08-13 10:08 - 00003184 _____ C:\WINDOWS\System32\Tasks\ASC5_AutoClean
2015-08-13 09:41 - 2015-08-13 09:40 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-13 09:40 - 2015-08-13 09:40 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-08-12 18:47 - 2015-08-12 18:47 - 00000020 ___SH C:\Users\fbwuserE2CD.bibek.000\ntuser.ini
2015-08-12 18:47 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-12 18:47 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-12 18:44 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-12 18:44 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\TuneUp Software
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Macromedia
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\IObit
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Local\Google
2015-08-12 18:44 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 18:44 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-12 18:43 - 2015-08-12 18:47 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000
2015-08-12 18:43 - 2015-08-12 18:43 - 00000020 ___SH C:\Users\fbwuserC16F.bibek.000\ntuser.ini
2015-08-12 18:43 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\Documents\hp.system.package.metadata
2015-08-12 18:43 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-12 18:43 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-12 18:40 - 2015-08-12 18:43 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000
2015-08-12 18:40 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-12 18:40 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\Documents\hp.system.package.metadata
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\TuneUp Software
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Macromedia
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\IObit
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Local\Google
2015-08-12 18:40 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 18:40 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-12 14:34 - 2015-08-12 14:35 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-11 15:21 - 2015-08-11 15:21 - 00000020 ___SH C:\Users\fbwuserE2CD.bibek\ntuser.ini
2015-08-11 15:21 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-11 15:21 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-11 15:19 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-11 15:19 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\TuneUp Software
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Macromedia
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\IObit
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Local\Google
2015-08-11 15:19 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-11 15:19 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-11 15:18 - 2015-08-11 15:21 - 00000000 ____D C:\Users\fbwuserE2CD.bibek
2015-08-11 15:18 - 2015-08-11 15:18 - 00000020 ___SH C:\Users\fbwuserC16F.bibek\ntuser.ini
2015-08-11 15:18 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\Documents\hp.system.package.metadata
2015-08-11 15:18 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-11 15:18 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-11 15:16 - 2015-08-11 15:18 - 00000000 ____D C:\Users\fbwuserC16F.bibek
2015-08-11 15:16 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-11 15:16 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\Documents\hp.system.package.metadata
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\TuneUp Software
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\Macromedia
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\IObit
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Local\Google
2015-08-11 15:16 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-11 15:16 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-10 14:33 - 2015-08-10 14:33 - 00000020 ___SH C:\Users\fbwuserE2CD\ntuser.ini
2015-08-10 14:33 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-10 14:33 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-10 14:31 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-10 14:31 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\TuneUp Software
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\Macromedia
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\IObit
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Local\Google
2015-08-10 14:31 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-10 14:31 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-10 14:30 - 2015-08-10 14:33 - 00000000 ____D C:\Users\fbwuserE2CD
2015-08-10 14:30 - 2015-08-10 14:30 - 00000020 ___SH C:\Users\fbwuserC16F\ntuser.ini
2015-08-10 14:30 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\Documents\hp.system.package.metadata
2015-08-10 14:30 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-10 14:30 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-10 14:28 - 2015-08-10 14:30 - 00000000 ____D C:\Users\fbwuserC16F
2015-08-10 14:28 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-10 14:28 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\Documents\hp.system.package.metadata
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\TuneUp Software
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\Macromedia
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\IObit
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Local\Google
2015-08-10 14:28 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-10 14:28 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-03 15:44 - 2015-08-03 15:44 - 00002216 _____ C:\Users\bibeksujita\Desktop\FLV Player.lnk
2015-07-30 18:03 - 2015-07-30 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-07-26 18:11 - 2015-08-09 18:11 - 00003194 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForbibeksujita
2015-07-26 18:11 - 2015-08-09 18:11 - 00000368 _____ C:\WINDOWS\Tasks\HPCeeScheduleForbibeksujita.job
2015-07-24 11:32 - 2015-07-29 11:55 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\FlickrUploadrWindows
2015-07-24 11:32 - 2015-07-24 11:32 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\SquirrelTemp
2015-07-24 11:32 - 2015-07-24 11:32 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\IsolatedStorage
2015-07-24 11:32 - 2015-07-24 11:32 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Flickr
2015-07-24 08:05 - 2015-07-24 08:05 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Photos Backup
2015-07-13 11:41 - 2015-07-13 11:41 - 00002187 _____ C:\Users\bibeksujita\Desktop\AppsHat.lnk
2015-07-13 11:41 - 2015-07-13 11:41 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat
2015-07-13 11:40 - 2015-07-13 11:40 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Minibar
2015-07-13 11:40 - 2015-07-13 11:40 - 00000000 ____D C:\Program Files (x86)\Minibar
2015-07-08 15:26 - 2015-07-08 20:55 - 00000000 ____D C:\WINDOWS\Minidump
2015-06-19 09:37 - 2015-08-13 10:48 - 00000954 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA.job
2015-06-19 09:37 - 2015-08-12 14:48 - 00000902 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core.job
2015-06-19 09:37 - 2015-07-20 14:43 - 00003912 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA
2015-06-19 09:37 - 2015-07-20 14:43 - 00003532 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core
2015-06-19 09:37 - 2015-06-19 09:37 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Dropbox
2015-06-19 09:37 - 2015-06-19 09:37 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-04 10:37 - 2015-06-04 10:37 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\{80C89AE0-887B-443F-9A67-B29A3F8B881B}
2015-05-26 08:36 - 2015-05-26 08:36 - 00000000 ____D C:\Program Files\avast software
2015-05-22 22:42 - 2015-07-30 18:07 - 00000000 ____D C:\Users\bibeksujita\Downloads\Shareit
2015-05-22 22:35 - 2015-05-25 09:56 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Lenovo
2015-05-22 22:34 - 2015-07-30 18:04 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2015-05-22 22:34 - 2015-07-30 18:03 - 00001220 _____ C:\Users\Public\Desktop\SHAREit.lnk
2015-05-22 22:34 - 2015-07-30 18:03 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2015-05-22 22:34 - 2015-05-22 22:34 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-05-22 22:27 - 2015-05-22 22:27 - 00000000 ____D C:\SWTOOLS
2015-05-22 13:25 - 2015-05-22 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit
2015-05-22 13:25 - 2015-05-22 13:25 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
==================== Three Months Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-13 11:34 - 2013-08-24 09:51 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Skype
2015-08-13 11:31 - 2013-05-31 02:43 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1476312255-3866232785-3835862293-1002
2015-08-13 11:21 - 2013-07-25 22:55 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Media Player Classic
2015-08-13 11:20 - 2014-07-21 14:53 - 01763144 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-13 11:15 - 2013-10-02 12:04 - 00000000 ___RD C:\Users\bibeksujita\Dropbox
2015-08-13 11:15 - 2013-10-02 12:01 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Dropbox
2015-08-13 11:06 - 2013-08-22 20:30 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-13 11:04 - 2013-08-22 19:10 - 06815744 ___SH C:\WINDOWS\system32\config\BBI
2015-08-13 10:59 - 2013-05-31 18:08 - 00000944 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA.job
2015-08-13 10:56 - 2013-08-17 13:45 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-13 10:47 - 2013-08-22 21:21 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-13 10:42 - 2014-05-28 11:46 - 00000000 ____D C:\Users\bibeksujita\Downloads\Video
2015-08-13 10:35 - 2014-05-28 11:45 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\DMCache
2015-08-13 09:59 - 2013-05-31 18:08 - 00000892 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core.job
2015-08-13 09:42 - 2013-07-25 20:21 - 00003926 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-13 09:40 - 2014-05-08 13:33 - 00150672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-08-13 09:40 - 2014-05-08 13:33 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-08-13 09:40 - 2013-07-25 20:22 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-08-13 09:40 - 2013-07-25 20:21 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-08-13 09:40 - 2013-07-25 20:21 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-08-13 09:40 - 2013-07-25 20:21 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-08-13 09:40 - 2013-07-25 19:55 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-08-13 09:40 - 2013-07-25 19:55 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-08-13 09:35 - 2013-05-31 18:57 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Adobe
2015-08-12 19:34 - 2014-03-18 15:48 - 00956412 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-12 18:07 - 2013-05-31 02:37 - 00003938 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4D65D3F1-3CDF-4F80-B0B6-AD329DB0689C}
2015-08-12 15:57 - 2013-08-22 21:21 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-08-12 13:02 - 2014-05-28 11:46 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\IDM
2015-08-11 15:41 - 2013-05-31 02:34 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Packages
2015-08-10 20:49 - 2013-12-24 22:50 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\vlc
2015-08-04 16:33 - 2013-10-18 19:05 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\BatteryCare
2015-08-03 15:44 - 2014-11-23 14:25 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\WebPlayer
2015-07-30 17:41 - 2014-07-21 14:18 - 00000000 ____D C:\Users\bibeksujita
2015-07-28 19:05 - 2014-09-16 17:55 - 00000000 ____D C:\ProgramData\Wondershare Video Converter Ultimate
2015-07-24 20:59 - 2013-07-25 19:13 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2015-07-24 08:00 - 2013-05-31 01:09 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Google
2015-07-16 09:54 - 2013-05-31 18:08 - 00003902 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA
2015-07-16 09:54 - 2013-05-31 18:08 - 00003522 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core
2015-07-16 09:50 - 2013-08-17 13:45 - 00003890 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-16 09:50 - 2013-08-17 13:45 - 00003654 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-16 09:50 - 2013-08-17 13:45 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
==================== Files in the root of some directories =======
2014-08-20 22:00 - 2014-08-20 22:00 - 0000132 _____ () C:\Users\bibeksujita\AppData\Roaming\Adobe GIF Format CS6 Prefs
2014-08-20 15:11 - 2014-08-20 22:49 - 0000132 _____ () C:\Users\bibeksujita\AppData\Roaming\Adobe PNG Format CS6 Prefs
2013-08-04 00:42 - 2015-05-13 17:55 - 0013312 _____ () C:\Users\bibeksujita\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-31 18:56 - 2014-07-11 20:32 - 0007598 _____ () C:\Users\bibeksujita\AppData\Local\Resmon.ResmonCfg
2015-02-04 20:55 - 2015-02-04 20:55 - 0000461 _____ () C:\ProgramData\EDITING (F) - Shortcut.lnk
2013-08-24 09:54 - 2013-08-24 09:54 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2013-08-22 09:41 - 2013-08-22 09:41 - 89562112 ___SH () C:\ProgramData\msdgchj.exe
2013-08-22 09:41 - 2013-08-22 09:41 - 90973312 ___SH () C:\ProgramData\msvbdd.exe
Files to move or delete:
====================
C:\ProgramData\msdgchj.exe
C:\ProgramData\msvbdd.exe
Some files in TEMP:
====================
C:\Users\bibeksujita\AppData\Local\Temp\cdo1570824543.dll
C:\Users\bibeksujita\AppData\Local\Temp\cdo3418664131.dll
C:\Users\bibeksujita\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxup5nu.dll
C:\Users\bibeksujita\AppData\Local\Temp\HssInstaller.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== BCD ================================
Firmware Boot Manager
---------------------
identifier {fwbootmgr}
displayorder {c4c81405-10ae-11e4-824f-806e6f6e6963}
{3c2b7739-cadd-11e3-becb-806e6f6e6963}
{3c2b773a-cadd-11e3-becb-806e6f6e6963}
timeout 0
Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale en-US
inherit {globalsettings}
integrityservices Enable
default {current}
resumeobject {5f20d818-1cd0-11e2-be71-8434977dbdc2}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30
Firmware Application (101fffff)
-------------------------------
identifier {3c2b7739-cadd-11e3-becb-806e6f6e6963}
description USB Drive (UEFI)
Firmware Application (101fffff)
-------------------------------
identifier {3c2b773a-cadd-11e3-becb-806e6f6e6963}
description Internal CD/DVD ROM Drive (UEFI)
Firmware Application (101fffff)
-------------------------------
identifier {c4c81405-10ae-11e4-824f-806e6f6e6963}
description Internal Hard Disk or Solid State Disk
Windows Boot Loader
-------------------
identifier {5f20d815-1cd0-11e2-be71-8434977dbdc2}
device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{5f20d816-1cd0-11e2-be71-8434977dbdc2}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{5f20d816-1cd0-11e2-be71-8434977dbdc2}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \WINDOWS\system32\winload.efi
description Windows 8.1
locale en-US
inherit {bootloadersettings}
recoverysequence {5f20d81a-1cd0-11e2-be71-8434977dbdc2}
integrityservices Enable
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \WINDOWS
resumeobject {5f20d818-1cd0-11e2-be71-8434977dbdc2}
nx OptIn
bootmenupolicy Standard
Windows Boot Loader
-------------------
identifier {5f20d81a-1cd0-11e2-be71-8434977dbdc2}
device ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{5f20d81b-1cd0-11e2-be71-8434977dbdc2}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{5f20d81b-1cd0-11e2-be71-8434977dbdc2}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Resume from Hibernate
---------------------
identifier {5f20d818-1cd0-11e2-be71-8434977dbdc2}
device partition=C:
path \WINDOWS\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {5f20d81a-1cd0-11e2-be71-8434977dbdc2}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Resume from Hibernate
---------------------
identifier {82af29ed-1cc5-11e2-83c2-9556a012f1b8}
device partition=C:
path \Windows\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {5f20d815-1cd0-11e2-be71-8434977dbdc2}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\memtest.efi
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes
EMS Settings
------------
identifier {emssettings}
bootems No
Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
-----------
identifier {badmemory}
Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}
Device options
--------------
identifier {5f20d816-1cd0-11e2-be71-8434977dbdc2}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume1
ramdisksdipath \Recovery\WindowsRE\boot.sdi
Device options
--------------
identifier {5f20d817-1cd0-11e2-be71-8434977dbdc2}
description Windows Setup
ramdisksdidevice partition=C:
ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi
Device options
--------------
identifier {5f20d81b-1cd0-11e2-be71-8434977dbdc2}
description Windows Recovery
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\WindowsRE\boot.sdi
LastRegBack: 2015-07-28 16:48
==================== End of log ============================
whenever i connect to internet avast keeps giving notification that it blocked a virus.
infection details are
url - hxxp://differentia.ru/diff.php
infection - url:mal
process - C:\WINDOWS\SysWOW64\msiexec.exe
url - hxxp://disorderstatus.ru/order.php
infection - url:mal
process - C:\WINDOWS\SysWOW64\msiexec.exe
no apparent changes while using the computer.
from FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-08-2015
Ran by bibeksujita (administrator) on BIBEK (13-08-2015 11:37:29)
Running from C:\Users\bibeksujita\Desktop
Loaded Profiles: bibeksujita (Available Profiles: bibeksujita)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Filipe Lourenço) C:\Program Files (x86)\BatteryCare\BatteryCare.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
() C:\ProgramData\DatacardService\DCService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Somoto) C:\Users\bibeksujita\AppData\Local\FilesFrog Update Checker\update_checker.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
() C:\Program Files (x86)\Photodex\ProShow Gold\scsiaccess.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
() C:\Users\bibeksujita\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
() C:\Users\bibeksujita\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(CANON INC.) C:\Windows\System32\CNAB5RPD.EXE
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(Dropbox, Inc.) C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-08-10] (IDT, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [6109776 2015-08-13] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1743136 2013-05-29] (Wondershare)
HKLM-x32\...\Run: [BrowserPlugInHelper] => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\BrowserPlugInHelper.exe [1962896 2013-12-19] ()
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Advanced SystemCare 5] => C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe [1647448 2011-11-12] (IObit)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Google Update] => C:\Users\bibeksujita\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-05-31] (Google Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3825232 2014-05-28] (Tonec Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [FLV Player] => C:\Users\bibeksujita\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe [202752 2012-10-26] ()
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [Dropbox Update] => C:\Users\bibeksujita\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-19] (Dropbox, Inc.)
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [AppsHat] => C:\Users\bibeksujita\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [202752 2012-10-26] ()
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Run: [GoogleChromeAutoLaunch_D6EBCAA31125C79C9AF7C27C47CA8B0A] => C:\Users\bibeksujita\AppData\Local\Google\Chrome\Application\chrome.exe [813896 2015-08-08] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP2900 Status Window.lnk [2014-08-24]
ShortcutTarget: Canon LBP2900 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE (CANON INC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP3300 Status Window.lnk [2015-02-16]
ShortcutTarget: Canon LBP3300 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB5LAD.EXE (CANON INC.)
Startup: C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-11]
ShortcutTarget: Dropbox.lnk -> C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bibeksujita\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll [2015-08-13] (AVAST Software)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2012-11-16] (Tonec Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPNOT13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT13/1
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPNOT13/1
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT13/1
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
URLSearchHook: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 - UsProvider Class - {539F76FD-084E-4858-86D5-62F02F54AE86} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2013-11-29] (Internet Download Manager, Tonec Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-13] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2013-05-02] (Orbitdownloader.com)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2013-11-29] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Wondershare Video Converter Ultimate -> {65DEE40A-3E93-4cae-9F98-B8E06DCEE2BF} -> C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRIEPlugin.dll [2013-12-19] (Wondershare Software Co., Ltd.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-13] (AVAST Software)
BHO-x32: MinibarBHO -> {AA74D58F-ACD0-450D-A85E-6C04B171C044} -> C:\Program Files (x86)\Minibar\Minibar.dll [2013-09-19] (KangoExtensions)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll [2007-02-16] (IDM)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-10] (Hewlett-Packard)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll [2013-05-02] ()
Toolbar: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKU\S-1-5-21-1476312255-3866232785-3835862293-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-02] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{12AB8B55-C5E3-479D-9E26-67733A9B0DAC}: [NameServer] 116.68.209.16 116.68.213.14
Tcpip\..\Interfaces\{18CDEEB9-AF2F-47B7-8DC5-6EA3333E35EF}: [NameServer] 116.68.209.16 116.68.213.14
Tcpip\..\Interfaces\{4043E7E1-5004-4A69-B2C5-903B9A73FFB9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{AC5F13DC-A531-4747-87CE-21B5FF86DBC3}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{BD814FAA-4217-46C0-B993-C33CC1D055AC}: [NameServer] 116.68.209.16 116.68.213.14
FireFox:
========
FF ProfilePath: C:\Users\bibeksujita\AppData\Roaming\Mozilla\Firefox\Profiles\moclw1el.default-1417698431251
FF NetworkProxy: "type",
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll [2013-06-01] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll [2013-06-01] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-25] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-09] (Microsoft Corporation)
FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [2013-10-18] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-05-31] ()
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1476312255-3866232785-3835862293-1002: @tools.google.com/Google Update;version=3 -> C:\Users\bibeksujita\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1476312255-3866232785-3835862293-1002: @tools.google.com/Google Update;version=9 -> C:\Users\bibeksujita\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2013-05-31]
FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2013-05-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2013-07-25]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-25]
FF HKLM-x32\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt [2014-09-16]
FF HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\bibeksujita\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\bibeksujita\AppData\Roaming\IDM\idmmzcc5 [2014-05-28]
FF HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF HKU\S-1-5-21-1476312255-3866232785-3835862293-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\bibeksujita\AppData\Roaming\IDM\idmmzcc5
Chrome:
=======
CHR Profile: C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Freemake Video Downloader) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2013-05-31]
CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2014-09-16]
CHR Extension: (Freemake Youtube Download Button) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2013-05-31]
CHR Extension: (Pin It Button) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-03-11]
CHR Extension: (IDM Integration Module) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-05-28]
CHR Extension: (My Browser Page) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghfknlgajlcihkhkhnlcoffhbohnlbg [2014-07-18]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (MyWebFace) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\njienacjggibaeolcbbjfnigbojkcggj [2015-01-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\bibeksujita\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-05-31]
CHR HKLM-x32\...\Chrome\Extension: [chgdeabpmphfhkoemjjglmilajldekbp] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRChromePlugin.crx [2014-09-16]
CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2013-05-31]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2015-04-12]
CHR HKLM-x32\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-01-17]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService5; C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [490840 2011-11-10] (IObit)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-08] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [146600 2015-08-13] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [217088 2013-03-22] (Connectify) [File not signed]
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed]
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-04-15] (Freemake) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2015-04-15] (Ellora Assets Corp.) [File not signed]
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-11] (Hewlett-Packard Company) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625648 2015-06-08] (Lenovo)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2013-10-18] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-07-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-07-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-07-22] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe" [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-13] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-08-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-13] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-13] (AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3860480 2013-08-23] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-18] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 cmshusbser; C:\Windows\system32\DRIVERS\cmshusbser.sys [127232 2011-11-30] (QUALCOMM Incorporated)
S1 cnnctfy3; C:\Windows\system32\DRIVERS\cnnctfy3.sys [34840 2013-10-18] (Connectify)
S3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [252928 2010-04-30] (Huawei Technologies Co., Ltd.)
S3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [29696 2012-10-11] (ManyCam LLC)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-12] (CACE Technologies, Inc.)
S3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [30336 2007-01-18] (Research in Motion Ltd)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
R3 WinRing0_1_2_0; C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
R3 WsAudio_Device; C:\Windows\system32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare)
S3 RimUsb; \SystemRoot\System32\Drivers\RimUsb_AMD64.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys [X]
========================== Drivers MD5 =======================
C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
C:\Windows\system32\DRIVERS\Accelerometer.sys 899B7E724BF19F17978B6A37B864A277
C:\Windows\System32\drivers\ACPI.sys 9539F7917B4B6D92C90F0FAA6B86C605
C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
C:\Windows\system32\drivers\afd.sys 374E27295F0A9DCAA8FC96370F9BEEA5
C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
C:\Windows\System32\DRIVERS\ahcache.sys 8E8E34B7BA059050EED827410D0697A2
C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
C:\Windows\system32\DRIVERS\atikmdag.sys F931C2ED6C8294909C10657DCB9A9A4E
C:\Windows\system32\DRIVERS\atikmpag.sys 0D481A7FE3A66724DC11AD8A4E417A9A
C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
C:\Windows\System32\drivers\amd_sata.sys A2EFE3869B976296E097DEF368280F95
C:\Windows\System32\drivers\amd_xata.sys 625396421C29FB305C6C6235D01130B8
C:\Windows\system32\drivers\appid.sys 04951A9A937CBE28A2D3FEEA360B6D1F
C:\Windows\system32\DRIVERS\appexDrv.sys 44695679881DEB85CAD7C249B151066E
C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
C:\Windows\system32\drivers\aswHwid.sys 525F5989C095F5757414E1F4B39175B2
C:\Windows\system32\drivers\aswMonFlt.sys 76D585093398DB973470BB83FCF0CE52
C:\Windows\system32\drivers\aswRdr2.sys 719FF5568B5E71832541636E2A7DFE27
C:\Windows\System32\Drivers\aswRvrt.sys 21C13E3C9B801C8AE172FABBD235221E
C:\Windows\system32\drivers\aswSnx.sys 5B6A864A2CE292992040CEBAFC8F746A
C:\Windows\system32\drivers\aswSP.sys C43A0929DE32035499D6BB39A7F44439
C:\Windows\system32\drivers\aswStm.sys 763C27EA21875F54615A0174EEC78FC4
C:\Windows\System32\Drivers\aswVmm.sys C85B35201A253B99199C0A9F5B98FC18
C:\Windows\system32\DRIVERS\asyncmac.sys 3DB7721F06BC2FEDB25029EA23AB27DA
C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
C:\Windows\system32\DRIVERS\athwbx.sys 509AE5E446B2171D03401F3DD3C2E682
C:\Windows\system32\drivers\AtihdW86.sys 506907D2E7F3A5B67DBD39C00A788B7C
C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
C:\Windows\System32\drivers\BasicRender.sys 38A82F4EE8C416A6744B6D30381ED768
C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
C:\Windows\System32\drivers\bthhfenum.sys 746B9F94214915AECDE4B7FEA5FF9664
C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
C:\Windows\System32\drivers\bthmodem.sys 66B791F6B11DC4303DD18A224A501542
C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
C:\Windows\System32\drivers\CLFS.sys 179A41249055D5F039F1B6703F3B6D2B
C:\Windows\system32\DRIVERS\CLVirtualDrive.sys 075CCE75090786F124573A788C8656E6
C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
C:\Windows\system32\DRIVERS\cmshusbser.sys 55D0611746F05C708F445E574182236F
C:\Windows\System32\Drivers\cng.sys 1CD3A907D64D08F49208DA00B69BF35E
C:\Windows\system32\DRIVERS\cnnctfy3.sys 99DA8A69284811F7B227D013B41C12FB
C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
C:\Windows\System32\drivers\dam.sys 315BA4BC19316D72B2E037534E048B93
C:\Windows\System32\Drivers\dfsc.sys A03F362C5557E238CBFA914689C77248
C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
C:\Windows\system32\drivers\drmkaud.sys DDC11A202207C0400CBE07315B8FDE5E
C:\Windows\System32\drivers\dxgkrnl.sys C7D252742946DD395670649742FBD73D
C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
C:\Windows\system32\DRIVERS\ewusbnet.sys DA7CEF9FFBBD6498DF106BCAB84EB10A
C:\Windows\system32\DRIVERS\ew_hwusbdev.sys E2CBB821C7CAE0EF8B56DE28ED85C740
C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
C:\Windows\System32\drivers\fileinfo.sys BCFD8B149B3ADF92D0DB1E909CAF0265
C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
C:\Windows\System32\drivers\fltmgr.sys 6592D192E2823C043EDBC010E7774053
C:\Windows\System32\drivers\FsDepends.sys 35005534E600E993A90B036E4E599F2B
C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
C:\Windows\System32\DRIVERS\fvevol.sys F152D55E497E12256290C43B31C7D0CE
C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
C:\Windows\System32\Drivers\msgpioclx.sys EF3AE7773394DF49CE74AF78A1C8D23D
C:\Windows\System32\drivers\HDAudBus.sys 498288DD5CA42C2D36D125893E968C53
C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
C:\Windows\System32\drivers\hidbth.sys 1EA1B4FABB8CC348E73CA90DBA22E104
C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
C:\Windows\System32\drivers\hidusb.sys 8DB8EAB9D0C6A5DF0BDCADEA239220B4
C:\Windows\System32\DRIVERS\hpdskflt.sys D104FF402FC3DDB686E6DEF00334DB26
C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
C:\Windows\System32\drivers\HTTP.sys 9DDCA7F18983C5410DEFF79F819DF93C
C:\Windows\System32\drivers\ew_jubusenum.sys 6DBD08BC1331C78548298E82C4B667C5
C:\Windows\system32\DRIVERS\ewusbmdm.sys 6E5CD3984742A922D0C183C7E82C3C94
C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
C:\Windows\System32\drivers\i8042prt.sys 84CFC5EFA97D0C965EDE1D56F116A541
C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
C:\Windows\System32\drivers\iaStorA.sys 050F2539E14F9D5E90A4B61738EC29BD
C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
C:\Windows\system32\DRIVERS\idmwfp.sys 929DF302F15BFE24AC66EF45D858C413
C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
C:\Windows\System32\drivers\intelpep.sys 139CFCDCD36B1B1782FD8C0014AC9B0E
C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
C:\Windows\System32\drivers\IPMIDrv.sys FD9C9E9E3F0ED51502C7E8C066BE26B9
C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
C:\Windows\System32\drivers\msiscsi.sys D90AB68D0FAC9F357F663670FDBB511E
C:\Windows\System32\drivers\kbdclass.sys 8BE92376799B6B44D543E8D07CDCF885
C:\Windows\System32\drivers\kbdhid.sys FB6E47E569D4872ABEB506BE03A45FBA
C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
C:\Windows\System32\Drivers\ksecdd.sys ADDECBCC777665BD113BED437E602AB0
C:\Windows\System32\Drivers\ksecpkg.sys F88CC88F4A6D8476F1664E805CA18CC2
C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
C:\Windows\system32\drivers\luafv.sys DDEE191AB32DFC22C6465002ECDF5EE4
C:\Windows\system32\DRIVERS\mcvidrv_x64.sys DE585D1D266805E5EEDAE911FDD16F38
C:\Windows\system32\drivers\mcaudrv_x64.sys 2E7FFDEF8BAFD04CBB517507B821E878
C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
C:\Windows\System32\drivers\mouclass.sys CEAC6D40FE887CE8406C2393CF97DE06
C:\Windows\System32\drivers\mouhid.sys 02D98BF804084E9A0D69D1C69B02CCA9
C:\Windows\System32\drivers\mountmgr.sys 515549560D481138E6E21AF7C6998E56
C:\Windows\System32\drivers\mpsdrv.sys F170510BE94CF45E3C6274578F6204B2
C:\Windows\system32\drivers\mrxdav.sys 1D55DADC22D21883A2F80297F5A5AE48
C:\Windows\System32\DRIVERS\mrxsmb.sys 0696F66E4D423793951A60562F794D14
C:\Windows\System32\DRIVERS\mrxsmb10.sys 3E28B99198B514DFEB152EACF913025E
C:\Windows\System32\DRIVERS\mrxsmb20.sys DBA635C6398782C549E3BE45CF1D0411
C:\Windows\system32\DRIVERS\bridge.sys 4E888019078AC363076A5433E89AA4F8
C:\Windows\System32\Drivers\Msfs.sys D13329FBF8345B28AB30F44CC247DC08
C:\Windows\System32\drivers\msgpiowin32.sys C6B474E46F9E543B875981ED3FFE6ADD
C:\Windows\System32\drivers\mshidkmdf.sys 65C92EB9D08DB5C69F28C7FFD4E84E31
C:\Windows\System32\drivers\mshidumdf.sys 52299F086AC2DAFD100DD5DC4A8614BA
C:\Windows\System32\drivers\msisadrv.sys 36D92AF3343C3A3E57FEF11C449AEA4C
C:\Windows\system32\drivers\MSKSSRV.sys A9BBBD2BAE6142253B9195E949AC2E8D
C:\Windows\system32\DRIVERS\mslldp.sys 375E44168F2DFB91A68B8A3F619C5A7C
C:\Windows\system32\drivers\MSPCLOCK.sys 7B2128EB875DCBC006E6A913211006D6
C:\Windows\system32\drivers\MSPQM.sys 1E88171579B218115C7A772F8DE04BD8
C:\Windows\System32\Drivers\MsRPC.sys BBE2A455053E63BECBF42C2F9B21FAE0
C:\Windows\System32\drivers\mssmbios.sys 8D6B7D515C5CBCDB75B928A0B73C3C5E
C:\Windows\system32\drivers\MSTEE.sys 115019AE01E0EB9C048530D2928AB4A2
C:\Windows\System32\drivers\MTConfig.sys 96D604A35070360F0DD4A7A8AF410B5E
C:\Windows\System32\Drivers\mup.sys 619CA29326B82372621DB2C0964D8365
C:\Windows\System32\drivers\mvumis.sys B8C35C94DCB2DFEAF03BB42131F2F77F
C:\Windows\system32\DRIVERS\nwifi.sys 78514B073CC5775800A65BFB82A0D66B
C:\Windows\System32\drivers\ndis.sys F21B77B4D74092A543807D3CEB711A88
C:\Windows\system32\DRIVERS\ndiscap.sys C6BB12BC35D1637CA17AE16D3A4725EB
C:\Windows\system32\DRIVERS\NdisImPlatform.sys 9F1DA20E943BE7AA4ED5F3E1EBA78B37
C:\Windows\system32\DRIVERS\ndistapi.sys 9423421E735BD5394351E0C47C76BB92
C:\Windows\system32\DRIVERS\ndisuio.sys B832B35055BA2B7B4181861FF94D8E59
C:\Windows\System32\drivers\NdisVirtualBus.sys 1F58E48EF75F34C35D8E93A0DC535CFE
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\System32\Drivers\NDProxy.sys A5BD69A8812FA79D1A487691DD3FB244
C:\Windows\System32\drivers\Ndu.sys 5A072F0B90C29C5233D78BE33EF5ED78
C:\Windows\System32\DRIVERS\netbios.sys A83D67D347A684F10B7D3019C8A6380C
C:\Windows\System32\DRIVERS\netbt.sys 0217532E19A748F0E5D569307363D5FD
C:\Windows\system32\DRIVERS\netvsc63.sys 70414DB660BFBB7BD58FCE8EA4364E1B
C:\Windows\System32\drivers\npf.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys 8F44A2F57C9F1A19AC9C6288C10FB351
C:\Windows\System32\drivers\npsvctrig.sys CBDB4F0871C88DF930FC0E8588CA67FC
C:\Windows\System32\drivers\nsiproxy.sys E490B459978CB87779E84C761D22B827
C:\Windows\System32\Drivers\Ntfs.sys 1C80517BE6836A812F6A9B99B8321351
C:\Windows\System32\Drivers\Null.sys EF1B290FC9F0E47CC0B537292BEE5904
C:\Windows\System32\drivers\nvraid.sys BC6B5942AFF25EBAF62DE43C3807EDF8
C:\Windows\System32\drivers\nvstor.sys 1F43ABFFAC3D6CA356851D517392966E
C:\Windows\System32\drivers\nv_agp.sys 6934A936A7369DFE37B7DBA93F5E5E49
C:\Windows\System32\drivers\parport.sys 764B1121867B2D9B31C491668AC72B2B
C:\Windows\System32\drivers\partmgr.sys EF0C1749C9A8CEE9A457473D433CC00F
C:\Windows\System32\drivers\pci.sys 275AFE3FA35E8D78BE97695DF49817C6
C:\Windows\System32\drivers\pciide.sys 346E38FCC6859A727DD28AFAD1F0AFF4
C:\Windows\System32\drivers\pcmcia.sys 4D3BDCC1C7B40C9D7B6AD990E6DEC397
C:\Windows\System32\drivers\pcw.sys BF28771D1436C88BE1D297D3098B0F7D
C:\Windows\System32\drivers\pdc.sys B9D968D8E2B0F9C6301CEB39CFC9B9E4
C:\Windows\System32\drivers\peauth.sys 0ECEE590F2E2EF969FB74A6FC583A1E6
C:\Windows\system32\DRIVERS\raspptp.sys E075CC071022BD4E9BE7C024717C0E0A
C:\Windows\System32\drivers\processr.sys ECD373F9571C745894367CC2635EA44F
C:\Windows\system32\DRIVERS\pacer.sys 8528BB05E4D4E25945F78B00B2555FB7
C:\Windows\System32\Drivers\PxHlpa64.sys BC08F7F3C53CBEE68670ED1314E290FD
C:\Windows\system32\drivers\qwavedrv.sys 3FB466684609A4329858CF2EBD62E0FD
C:\Windows\System32\DRIVERS\rasacd.sys 2C56F0EE27E4EF70CA4B4983D3638905
C:\Windows\system32\DRIVERS\AgileVpn.sys 55FE43112F61836D0581D615C72AA113
C:\Windows\system32\DRIVERS\rasl2tp.sys BBB6272B7F46C4640A8CDB8A70C3450F
C:\Windows\system32\DRIVERS\raspppoe.sys 5247F308C4103CDC4FE12AE1D235800A
C:\Windows\system32\DRIVERS\rassstp.sys 2B0F1677CDD08967005F34488559BC6F
C:\Windows\System32\DRIVERS\rdbss.sys A1A5E79C0D1352AFDC08328A623DA051
C:\Windows\System32\drivers\rdpbus.sys 6B21EBF892CD8CACB71669B35AB5DE32
C:\Windows\System32\drivers\rdpdr.sys 680C1DAE268B6FB67FA21B389A8B79EF
C:\Windows\System32\drivers\rdpvideominiport.sys 858776908AF838E3790F3261B799CDA6
C:\Windows\System32\drivers\rdyboost.sys A26AEC49F318FEE141DDDB2C5F99B3E6
C:\Windows\System32\Drivers\ReFS.sys E515A287C8FAE901EB8FB42F168E14F2
C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys 0DE22421179D5A8440B68517DDF2B051
C:\Windows\System32\Drivers\RootMdm.sys A0AF9EBF560FDD0E044E04C0AF9FF9E6
C:\Windows\system32\DRIVERS\RtsP2Stor.sys D38250F459BF60D6F4B69B79DCD948CC
C:\Windows\system32\DRIVERS\rspndr.sys 2D05A5508F4685412F2B89E8C2189ABC
C:\Windows\system32\DRIVERS\Rt630x64.sys 34DA0D14F5C3F1883A331AFB975AB434
C:\Windows\System32\drivers\vms3cap.sys 1A063730F221B2746FF00457AE17E4F0
C:\Windows\System32\drivers\sbp2port.sys C624A1B32211C3166EDB3F4AB02A30B7
C:\Windows\System32\DRIVERS\scfilter.sys ABD0237B15DBD2B4695F4B7D734A58F7
C:\Windows\System32\drivers\sdbus.sys FDEC5799BA499D18AFA3A540538866E7
C:\Windows\System32\drivers\sdstor.sys 0B1E929D11A8E358106955603FAC65E8
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\SerCx.sys DB2FF24CE0BDD15FE75870AFE312BA89
C:\Windows\System32\drivers\SerCx2.sys 0044B31F93946D5D41982314381FE431
C:\Windows\System32\drivers\serenum.sys 3CD600C089C1251BEEB4CD4CD5164F9E
C:\Windows\System32\drivers\serial.sys D864381BC9C725FAB01D94C060660166
C:\Windows\System32\drivers\sermouse.sys 0BD2B65DCE756FDE95A2E5CCCBF7705D
C:\Windows\System32\drivers\sfloppy.sys 472B7A5AC181C050888DB454663DD764
C:\Windows\System32\drivers\SiSRaid2.sys 2F518D13DD6F3053837FE606F1A2EA1F
C:\Windows\System32\drivers\sisraid4.sys 1AC9A200A9C49C4508F04AAFFCA34A3F
C:\Windows\System32\drivers\Smb_driver_AMDASF.sys AF5CC3F9B88F140D78FC967ABF0F4EC7
C:\Windows\System32\drivers\Smb_driver_Intel.sys 19555D03CB179BED8B8AAA239A36BDA4
C:\Windows\System32\drivers\spaceport.sys 33977549C2CED09936E05BEE7659EAFF
C:\Windows\System32\drivers\SpbCx.sys F337BE11071818FC3F5DC2940B6BDE34
C:\Windows\System32\DRIVERS\srv.sys 2B78788A1485F9B99A578A299DF42C02
C:\Windows\System32\DRIVERS\srv2.sys FD163F487CBA9C98AFFEB546C80F49A2
C:\Windows\System32\DRIVERS\srvnet.sys 716059F37BCCB1ABEDE99EBE82E8E362
C:\Windows\System32\drivers\stexstor.sys 366DEA74BBA65B362BCCFC6FC2ADFD8B
C:\Windows\system32\DRIVERS\stwrt64.sys 32BE0B7CCA47A5BE30E7E43DC54B54F3
C:\Windows\System32\drivers\storahci.sys 0ED2E318ABB68C1A35A8B8038BDB4C90
C:\Windows\System32\DRIVERS\vmstorfl.sys 7A08CEE1535F5A448215634C5EA74E50
C:\Windows\System32\drivers\stornvme.sys 6B06E2D11E604BE2B1A406C4CB3B90DE
C:\Windows\System32\drivers\storvsc.sys 548759755BC73DAD663250239D7E0B9F
C:\Windows\System32\drivers\swenum.sys 84E0F5D41C138C5CC975137A2A98F6D3
C:\Windows\system32\DRIVERS\SynTP.sys 0F34FE968C91D02CE30D76C257F2BDA0
C:\Windows\system32\DRIVERS\taphss6.sys DA0780D55E8CF724CF3EF7CCF0F0DB67
C:\Windows\System32\drivers\tcpip.sys 25AC0B50A71938890970E1508F107196
C:\Windows\system32\DRIVERS\tcpip.sys 25AC0B50A71938890970E1508F107196
C:\Windows\System32\drivers\tcpipreg.sys 41CF802064F72E55F50CA0A221FD36D4
C:\Windows\system32\DRIVERS\tdx.sys FFF28F9F6823EB1756C60F1649560BBF
C:\Windows\System32\drivers\terminpt.sys 232D185D2337F141311D0CF1983E1431
C:\Windows\system32\drivers\tpm.sys 82F909359600D3603FE852DB7F135626
C:\Windows\System32\drivers\tsusbflt.sys BF8F54CA37E9C9D6582C31C5761F8C93
C:\Windows\System32\drivers\TsUsbGD.sys E0088068DCE2EE82897027DDB8E05254
C:\Windows\system32\DRIVERS\tunnel.sys C8E0E78B5D284C2FF59BDFFDAF997242
C:\Windows\System32\drivers\uagp35.sys F6EEAD052943B5A3104C1405BB856C54
C:\Windows\System32\drivers\uaspstor.sys FE6067B1FD4E63650C667B33D080565B
C:\Windows\System32\drivers\ucx01000.sys B034A41891A36457B994307DFA772293
C:\Windows\System32\DRIVERS\udfs.sys 1EC649F112896FAE33250F0B97AC5D0B
C:\Windows\System32\drivers\UEFI.sys 9578691F297E1B1F519970FE6D47CB21
C:\Windows\System32\drivers\uliagpkx.sys 5EAB5117DDB24FC4D39E6FFFCF1837B9
C:\Windows\System32\drivers\umbus.sys DA34C39A18E60E7C3FA0630566408034
C:\Windows\System32\drivers\umpass.sys AE8294875E5446E359B1E8035D40C05E
C:\Windows\System32\drivers\usbccgp.sys 433ECDE01A52691FA7ACA51C10C09B70
C:\Windows\System32\drivers\usbcir.sys B3D6457D841A0CAEF4C52D88621715F2
C:\Windows\System32\drivers\usbehci.sys 48BA326A3DBA5B5BEB5F2777F4618696
C:\Windows\system32\DRIVERS\usbfilter.sys 4875DC63E548812C75D4FDEF84970C89
C:\Windows\System32\drivers\usbhub.sys 93435654DCA210298BA0F986EB51C679
C:\Windows\System32\drivers\UsbHub3.sys 83C9C45D59C72FEFDAE9A5686BE31FEA
C:\Windows\System32\drivers\usbohci.sys 3019097FB6C985EF24C058090FF3BDBD
C:\Windows\System32\drivers\usbprint.sys 4D655E3B684BE9B0F7FFD8A2935C348C
C:\Windows\system32\DRIVERS\usbscan.sys F04D164C4168701A4E7835607722E5F1
C:\Windows\System32\drivers\USBSTOR.SYS EA23453240137F6773174E0D93F61A69
C:\Windows\System32\drivers\usbuhci.sys 064260B3A5868AC894A4943543BC7AB7
C:\Windows\System32\Drivers\usbvideo.sys 18F744E8CCEB2670040EBAF7AD77B8C6
C:\Windows\System32\drivers\USBXHCI.SYS 48430B0313FC1CFE3D2400553F1A93CD
C:\Windows\system32\DRIVERS\usb8023x.sys 3CAAB947B1F247A570DE15983BEDEBCF
C:\Windows\System32\drivers\vdrvroot.sys FEB26E3B8345A7E8D62F945C4AE86562
C:\Windows\System32\drivers\VerifierExt.sys A026EDEAA5EECAE0B08E2748B616D4BD
C:\Windows\System32\drivers\vhdmp.sys 52E483A3701A5A61A75A06993720347D
C:\Windows\System32\drivers\viaide.sys 06D38968028E9AB19DE9B618C7B6D199
C:\Windows\System32\drivers\vmbus.sys C6305BDFC4F7CE51F72BB072C03D4ACE
C:\Windows\System32\drivers\VMBusHID.sys DA40BEA0A863CE768C940CA9723BF81F
C:\Windows\System32\drivers\volmgr.sys 55D7D963DE85162F1C49721E502F9744
C:\Windows\System32\drivers\volmgrx.sys CCB9E901F7254BF96D28EB1B0E5329B7
C:\Windows\System32\drivers\volsnap.sys 4BB9BC49DEE1A319EC58274A7BBED663
C:\Windows\System32\drivers\vpci.sys 01355C98B5C3ED1EC446743CDA848FCE
C:\Windows\System32\drivers\vsmraid.sys 4539F45F9F4C9757A86A56C949421E07
C:\Windows\System32\drivers\vstxraid.sys 0849B7260F26FE05EA56DED0672E2F4B
C:\Windows\System32\drivers\vwifibus.sys BE970C369E43B509C1EDA2B8FA7CECB0
C:\Windows\system32\DRIVERS\vwififlt.sys 6B26AD573CCDD5209DF4397438B76354
C:\Windows\system32\DRIVERS\vwifimp.sys 0B48E0DFB44EE475F4FD8A8EE599AF30
C:\Windows\System32\drivers\wacompen.sys 0910AB9ED404C1434E2D0376C2AD5D8B
C:\Windows\system32\DRIVERS\wanarp.sys AFCD4054D61BD708B82991348ED1C763
C:\Windows\system32\DRIVERS\wanarp.sys AFCD4054D61BD708B82991348ED1C763
C:\Windows\system32\drivers\WdBoot.sys F5D4FA3E1F4879C361FFF3855259D2C2
C:\Windows\System32\drivers\wdcsam64.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys CB6C63FF8342B467E2EF76E98D5B934D
C:\Windows\system32\drivers\WdFilter.sys 019CC610AD95FF47EAD7C08B7A683B96
C:\Windows\System32\Drivers\WdNisDrv.sys 6CC1BB8F6851A262E2E824F0E92D5EEF
C:\Windows\System32\DRIVERS\wfplwfs.sys BFBE1C5F57FE7A885673A1962D5532B7
C:\Windows\System32\drivers\wimmount.sys 867BCC69ED9C31C501465EB0E8BA9DFA
C:\Program Files (x86)\BatteryCare\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA
C:\Windows\system32\DRIVERS\WinUSB.sys AC263C2F66405589528995AA41040599
C:\Windows\System32\drivers\WirelessButtonDriver64.sys 4F2A80D65AE6F845776E2F06AE6782ED
C:\Windows\System32\drivers\wmiacpi.sys 2834D9D3B4F554A39C72F00EA3F0E128
C:\Windows\System32\Drivers\Wof.sys 7FC5667DF73D4B04AA457CC3A4180E09
C:\Windows\System32\DRIVERS\wpcfltr.sys 182561A14F2E93E81E66FE3700D17A5A
C:\Windows\System32\drivers\WpdUpFltr.sys 9F2904B55F6CECCD1A8D986B5CE2609A
C:\Windows\system32\drivers\ws2ifsl.sys AE072B0339D0A18E455DC21666CAD572
C:\Windows\system32\drivers\VirtualAudio.sys ADD2FE1A9F4EE41A6D724819550D4E1F
C:\Windows\System32\drivers\WudfPf.sys D537815E450A149752C15868392AD1F3
C:\Windows\System32\drivers\WUDFRd.sys 7CCBBCEE408A5DBE3FE47297DB5A6CFC
C:\Windows\system32\DRIVERS\WUDFRd.sys 7CCBBCEE408A5DBE3FE47297DB5A6CFC
C:\Windows\system32\DRIVERS\WUDFRd.sys 7CCBBCEE408A5DBE3FE47297DB5A6CFC
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three Months Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-13 11:34 - 2015-08-13 11:37 - 00055790 _____ C:\Users\bibeksujita\Desktop\FRST.txt
2015-08-13 11:33 - 2015-08-13 11:37 - 00000000 ____D C:\FRST
2015-08-13 11:33 - 2015-08-13 11:33 - 02173952 _____ (Farbar) C:\Users\bibeksujita\Desktop\FRST64.exe
2015-08-13 11:23 - 2015-08-13 11:23 - 00688992 _____ (Swearware) C:\Users\bibeksujita\Desktop\dds.scr
2015-08-13 11:05 - 2015-08-13 11:05 - 00006664 _____ C:\WINDOWS\PFRO.log
2015-08-13 10:08 - 2015-08-13 10:08 - 00003184 _____ C:\WINDOWS\System32\Tasks\ASC5_AutoClean
2015-08-13 09:41 - 2015-08-13 09:40 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-13 09:40 - 2015-08-13 09:40 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-08-12 18:47 - 2015-08-12 18:47 - 00000020 ___SH C:\Users\fbwuserE2CD.bibek.000\ntuser.ini
2015-08-12 18:47 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-12 18:47 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-12 18:44 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-12 18:44 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\TuneUp Software
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Macromedia
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\IObit
2015-08-12 18:44 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Local\Google
2015-08-12 18:44 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 18:44 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-12 18:43 - 2015-08-12 18:47 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000
2015-08-12 18:43 - 2015-08-12 18:43 - 00000020 ___SH C:\Users\fbwuserC16F.bibek.000\ntuser.ini
2015-08-12 18:43 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek.000\Documents\hp.system.package.metadata
2015-08-12 18:43 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-12 18:43 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-12 18:40 - 2015-08-12 18:43 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000
2015-08-12 18:40 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-12 18:40 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\Documents\hp.system.package.metadata
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\TuneUp Software
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Macromedia
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\IObit
2015-08-12 18:40 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Local\Google
2015-08-12 18:40 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 18:40 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserC16F.bibek.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-12 14:34 - 2015-08-12 14:35 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-11 15:21 - 2015-08-11 15:21 - 00000020 ___SH C:\Users\fbwuserE2CD.bibek\ntuser.ini
2015-08-11 15:21 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-11 15:21 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-11 15:19 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-11 15:19 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\TuneUp Software
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Macromedia
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\IObit
2015-08-11 15:19 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Local\Google
2015-08-11 15:19 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-11 15:19 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-11 15:18 - 2015-08-11 15:21 - 00000000 ____D C:\Users\fbwuserE2CD.bibek
2015-08-11 15:18 - 2015-08-11 15:18 - 00000020 ___SH C:\Users\fbwuserC16F.bibek\ntuser.ini
2015-08-11 15:18 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD.bibek\Documents\hp.system.package.metadata
2015-08-11 15:18 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-11 15:18 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-11 15:16 - 2015-08-11 15:18 - 00000000 ____D C:\Users\fbwuserC16F.bibek
2015-08-11 15:16 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-11 15:16 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\Documents\hp.system.package.metadata
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\TuneUp Software
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\Macromedia
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\IObit
2015-08-11 15:16 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Local\Google
2015-08-11 15:16 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-11 15:16 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserC16F.bibek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-10 14:33 - 2015-08-10 14:33 - 00000020 ___SH C:\Users\fbwuserE2CD\ntuser.ini
2015-08-10 14:33 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-10 14:33 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-10 14:31 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-10 14:31 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\TuneUp Software
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\Macromedia
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\IObit
2015-08-10 14:31 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Local\Google
2015-08-10 14:31 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-10 14:31 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserE2CD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-10 14:30 - 2015-08-10 14:33 - 00000000 ____D C:\Users\fbwuserE2CD
2015-08-10 14:30 - 2015-08-10 14:30 - 00000020 ___SH C:\Users\fbwuserC16F\ntuser.ini
2015-08-10 14:30 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserE2CD\Documents\hp.system.package.metadata
2015-08-10 14:30 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-10 14:30 - 2014-03-18 15:58 - 00000369 _____ C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-10 14:28 - 2015-08-10 14:30 - 00000000 ____D C:\Users\fbwuserC16F
2015-08-10 14:28 - 2014-07-22 03:30 - 00000000 ___RD C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-10 14:28 - 2014-07-22 03:27 - 00000000 ___RD C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\Documents\hp.system.package.metadata
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\TuneUp Software
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\Macromedia
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\IObit
2015-08-10 14:28 - 2014-07-21 14:30 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Local\Google
2015-08-10 14:28 - 2013-08-22 21:21 - 00000000 ___RD C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-10 14:28 - 2013-08-22 21:21 - 00000000 ____D C:\Users\fbwuserC16F\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-03 15:44 - 2015-08-03 15:44 - 00002216 _____ C:\Users\bibeksujita\Desktop\FLV Player.lnk
2015-07-30 18:03 - 2015-07-30 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-07-26 18:11 - 2015-08-09 18:11 - 00003194 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForbibeksujita
2015-07-26 18:11 - 2015-08-09 18:11 - 00000368 _____ C:\WINDOWS\Tasks\HPCeeScheduleForbibeksujita.job
2015-07-24 11:32 - 2015-07-29 11:55 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\FlickrUploadrWindows
2015-07-24 11:32 - 2015-07-24 11:32 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\SquirrelTemp
2015-07-24 11:32 - 2015-07-24 11:32 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\IsolatedStorage
2015-07-24 11:32 - 2015-07-24 11:32 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Flickr
2015-07-24 08:05 - 2015-07-24 08:05 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Photos Backup
2015-07-13 11:41 - 2015-07-13 11:41 - 00002187 _____ C:\Users\bibeksujita\Desktop\AppsHat.lnk
2015-07-13 11:41 - 2015-07-13 11:41 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat
2015-07-13 11:40 - 2015-07-13 11:40 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Minibar
2015-07-13 11:40 - 2015-07-13 11:40 - 00000000 ____D C:\Program Files (x86)\Minibar
2015-07-08 15:26 - 2015-07-08 20:55 - 00000000 ____D C:\WINDOWS\Minidump
2015-06-19 09:37 - 2015-08-13 10:48 - 00000954 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA.job
2015-06-19 09:37 - 2015-08-12 14:48 - 00000902 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core.job
2015-06-19 09:37 - 2015-07-20 14:43 - 00003912 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA
2015-06-19 09:37 - 2015-07-20 14:43 - 00003532 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core
2015-06-19 09:37 - 2015-06-19 09:37 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Dropbox
2015-06-19 09:37 - 2015-06-19 09:37 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-04 10:37 - 2015-06-04 10:37 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\{80C89AE0-887B-443F-9A67-B29A3F8B881B}
2015-05-26 08:36 - 2015-05-26 08:36 - 00000000 ____D C:\Program Files\avast software
2015-05-22 22:42 - 2015-07-30 18:07 - 00000000 ____D C:\Users\bibeksujita\Downloads\Shareit
2015-05-22 22:35 - 2015-05-25 09:56 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Lenovo
2015-05-22 22:34 - 2015-07-30 18:04 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2015-05-22 22:34 - 2015-07-30 18:03 - 00001220 _____ C:\Users\Public\Desktop\SHAREit.lnk
2015-05-22 22:34 - 2015-07-30 18:03 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2015-05-22 22:34 - 2015-05-22 22:34 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-05-22 22:27 - 2015-05-22 22:27 - 00000000 ____D C:\SWTOOLS
2015-05-22 13:25 - 2015-05-22 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit
2015-05-22 13:25 - 2015-05-22 13:25 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
==================== Three Months Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-13 11:34 - 2013-08-24 09:51 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Skype
2015-08-13 11:31 - 2013-05-31 02:43 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1476312255-3866232785-3835862293-1002
2015-08-13 11:21 - 2013-07-25 22:55 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Media Player Classic
2015-08-13 11:20 - 2014-07-21 14:53 - 01763144 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-13 11:15 - 2013-10-02 12:04 - 00000000 ___RD C:\Users\bibeksujita\Dropbox
2015-08-13 11:15 - 2013-10-02 12:01 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\Dropbox
2015-08-13 11:06 - 2013-08-22 20:30 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-13 11:04 - 2013-08-22 19:10 - 06815744 ___SH C:\WINDOWS\system32\config\BBI
2015-08-13 10:59 - 2013-05-31 18:08 - 00000944 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA.job
2015-08-13 10:56 - 2013-08-17 13:45 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-13 10:47 - 2013-08-22 21:21 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-13 10:42 - 2014-05-28 11:46 - 00000000 ____D C:\Users\bibeksujita\Downloads\Video
2015-08-13 10:35 - 2014-05-28 11:45 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\DMCache
2015-08-13 09:59 - 2013-05-31 18:08 - 00000892 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core.job
2015-08-13 09:42 - 2013-07-25 20:21 - 00003926 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-13 09:40 - 2014-05-08 13:33 - 00150672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-08-13 09:40 - 2014-05-08 13:33 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-08-13 09:40 - 2013-07-25 20:22 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-08-13 09:40 - 2013-07-25 20:21 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-08-13 09:40 - 2013-07-25 20:21 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-08-13 09:40 - 2013-07-25 20:21 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-08-13 09:40 - 2013-07-25 19:55 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-08-13 09:40 - 2013-07-25 19:55 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-08-13 09:35 - 2013-05-31 18:57 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Adobe
2015-08-12 19:34 - 2014-03-18 15:48 - 00956412 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-12 18:07 - 2013-05-31 02:37 - 00003938 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4D65D3F1-3CDF-4F80-B0B6-AD329DB0689C}
2015-08-12 15:57 - 2013-08-22 21:21 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-08-12 13:02 - 2014-05-28 11:46 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\IDM
2015-08-11 15:41 - 2013-05-31 02:34 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Packages
2015-08-10 20:49 - 2013-12-24 22:50 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\vlc
2015-08-04 16:33 - 2013-10-18 19:05 - 00000000 ____D C:\Users\bibeksujita\AppData\Roaming\BatteryCare
2015-08-03 15:44 - 2014-11-23 14:25 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\WebPlayer
2015-07-30 17:41 - 2014-07-21 14:18 - 00000000 ____D C:\Users\bibeksujita
2015-07-28 19:05 - 2014-09-16 17:55 - 00000000 ____D C:\ProgramData\Wondershare Video Converter Ultimate
2015-07-24 20:59 - 2013-07-25 19:13 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2015-07-24 08:00 - 2013-05-31 01:09 - 00000000 ____D C:\Users\bibeksujita\AppData\Local\Google
2015-07-16 09:54 - 2013-05-31 18:08 - 00003902 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002UA
2015-07-16 09:54 - 2013-05-31 18:08 - 00003522 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1476312255-3866232785-3835862293-1002Core
2015-07-16 09:50 - 2013-08-17 13:45 - 00003890 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-16 09:50 - 2013-08-17 13:45 - 00003654 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-16 09:50 - 2013-08-17 13:45 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
==================== Files in the root of some directories =======
2014-08-20 22:00 - 2014-08-20 22:00 - 0000132 _____ () C:\Users\bibeksujita\AppData\Roaming\Adobe GIF Format CS6 Prefs
2014-08-20 15:11 - 2014-08-20 22:49 - 0000132 _____ () C:\Users\bibeksujita\AppData\Roaming\Adobe PNG Format CS6 Prefs
2013-08-04 00:42 - 2015-05-13 17:55 - 0013312 _____ () C:\Users\bibeksujita\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-31 18:56 - 2014-07-11 20:32 - 0007598 _____ () C:\Users\bibeksujita\AppData\Local\Resmon.ResmonCfg
2015-02-04 20:55 - 2015-02-04 20:55 - 0000461 _____ () C:\ProgramData\EDITING (F) - Shortcut.lnk
2013-08-24 09:54 - 2013-08-24 09:54 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2013-08-22 09:41 - 2013-08-22 09:41 - 89562112 ___SH () C:\ProgramData\msdgchj.exe
2013-08-22 09:41 - 2013-08-22 09:41 - 90973312 ___SH () C:\ProgramData\msvbdd.exe
Files to move or delete:
====================
C:\ProgramData\msdgchj.exe
C:\ProgramData\msvbdd.exe
Some files in TEMP:
====================
C:\Users\bibeksujita\AppData\Local\Temp\cdo1570824543.dll
C:\Users\bibeksujita\AppData\Local\Temp\cdo3418664131.dll
C:\Users\bibeksujita\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxup5nu.dll
C:\Users\bibeksujita\AppData\Local\Temp\HssInstaller.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== BCD ================================
Firmware Boot Manager
---------------------
identifier {fwbootmgr}
displayorder {c4c81405-10ae-11e4-824f-806e6f6e6963}
{3c2b7739-cadd-11e3-becb-806e6f6e6963}
{3c2b773a-cadd-11e3-becb-806e6f6e6963}
timeout 0
Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale en-US
inherit {globalsettings}
integrityservices Enable
default {current}
resumeobject {5f20d818-1cd0-11e2-be71-8434977dbdc2}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30
Firmware Application (101fffff)
-------------------------------
identifier {3c2b7739-cadd-11e3-becb-806e6f6e6963}
description USB Drive (UEFI)
Firmware Application (101fffff)
-------------------------------
identifier {3c2b773a-cadd-11e3-becb-806e6f6e6963}
description Internal CD/DVD ROM Drive (UEFI)
Firmware Application (101fffff)
-------------------------------
identifier {c4c81405-10ae-11e4-824f-806e6f6e6963}
description Internal Hard Disk or Solid State Disk
Windows Boot Loader
-------------------
identifier {5f20d815-1cd0-11e2-be71-8434977dbdc2}
device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{5f20d816-1cd0-11e2-be71-8434977dbdc2}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{5f20d816-1cd0-11e2-be71-8434977dbdc2}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \WINDOWS\system32\winload.efi
description Windows 8.1
locale en-US
inherit {bootloadersettings}
recoverysequence {5f20d81a-1cd0-11e2-be71-8434977dbdc2}
integrityservices Enable
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \WINDOWS
resumeobject {5f20d818-1cd0-11e2-be71-8434977dbdc2}
nx OptIn
bootmenupolicy Standard
Windows Boot Loader
-------------------
identifier {5f20d81a-1cd0-11e2-be71-8434977dbdc2}
device ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{5f20d81b-1cd0-11e2-be71-8434977dbdc2}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{5f20d81b-1cd0-11e2-be71-8434977dbdc2}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Resume from Hibernate
---------------------
identifier {5f20d818-1cd0-11e2-be71-8434977dbdc2}
device partition=C:
path \WINDOWS\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {5f20d81a-1cd0-11e2-be71-8434977dbdc2}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Resume from Hibernate
---------------------
identifier {82af29ed-1cc5-11e2-83c2-9556a012f1b8}
device partition=C:
path \Windows\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {5f20d815-1cd0-11e2-be71-8434977dbdc2}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\memtest.efi
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes
EMS Settings
------------
identifier {emssettings}
bootems No
Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
-----------
identifier {badmemory}
Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}
Device options
--------------
identifier {5f20d816-1cd0-11e2-be71-8434977dbdc2}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume1
ramdisksdipath \Recovery\WindowsRE\boot.sdi
Device options
--------------
identifier {5f20d817-1cd0-11e2-be71-8434977dbdc2}
description Windows Setup
ramdisksdidevice partition=C:
ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi
Device options
--------------
identifier {5f20d81b-1cd0-11e2-be71-8434977dbdc2}
description Windows Recovery
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\WindowsRE\boot.sdi
LastRegBack: 2015-07-28 16:48
==================== End of log ============================