"Your personal files are encrypted" virus, please help

NovusVirtae

New Member
Thread author
Sep 3, 2016
2
Hi

I'd appreciate it if you could take a look on this log, this thing is annoying and needs to be removed.

Additional scan result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by Peiman91 (2016-09-03 21:14:19)
Running from C:\Users\Peiman91\Downloads
Windows 8 (X64) (2015-04-30 14:36:35)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administratör (S-1-5-21-3490378375-1854901139-762114773-500 - Administrator - Disabled) => C:\Users\Administrator
Gäst (S-1-5-21-3490378375-1854901139-762114773-501 - Limited - Disabled)
Peiman91 (S-1-5-21-3490378375-1854901139-762114773-1001 - Administrator - Enabled) => C:\Users\Peiman91

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Internet Security (Disabled - Out of date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: Norton Internet Security (Disabled - Out of date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Internet Security (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.1.0.9 - Absolute Software)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.172 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.12.3042.71515 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.12.3042.71515 - Alcor Micro Corp.) Hidden
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 6.30.59.26 - Broadcom Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 5.21 - Piriform)
Google Chrome (HKU\S-1-5-21-3490378375-1854901139-762114773-1001\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.14.265 - SurfRight B.V.)
Integrated Camera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 5.12.831.31 - Vimicro)
Intel AppUp(R) center (HKLM-x32\...\Intel AppUp(R) center 41651) (Version: 3.8.0.41651.58 - Intel)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2843 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Update Manager (x32 Version: 1.0.0.34813 - Intel Corporation) Hidden
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.00 - )
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.2600 - Broadcom Corporation)
Lenovo Dependency Package (HKLM-x32\...\Lenovo Dependency Package_is1) (Version: 1.05.0013 - Lenovo Group Limited)
Lenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.66.00.07 - )
Lenovo QuickLaunch (HKLM-x32\...\{A802F1E3-34C8-4C84-9948-C1C4E37D0FA9}) (Version: 1.00.0036 - Lenovo Group Limited)
Lenovo Settings - Camera Audio (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 4.0.21.0 - Lenovo Corporation)
Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 1.0.5.13 - Lenovo Group Limited)
Lenovo Settings Mobile Hotspot (HKLM\...\{42603F7D-B08D-436B-B0D8-3E2DEF1AFD41}_is1) (Version: 1.0.0.29 - Lenovo)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.00.0019 - Lenovo)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4433.1507 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.14.01.105 - Huawei Technologies Co.,Ltd)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 23.009.05.03.1014 - Huawei Technologies Co.,Ltd)
Nitro Pro 8 (HKLM\...\{73CBF5CA-73F0-41A7-87CD-190746E41263}) (Version: 8.0.10.9 - Nitro)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 20.6.0.27 - Symantec Corporation)
On Screen Display (HKLM\...\OnScreenDisplay) (Version: 7.10.00 - )
Open RegEdit (HKLM-x32\...\Open RegEdit2.0) (Version: 2.0 - Easy Desk Software)
Password Vault (HKLM\...\{1CACE706-D749-44CA-BBFE-AF60946D1B18}) (Version: 6.0.200.75 - AuthenTec, Inc.)
RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 2.1.1.0 - Lenovo)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6710 - Realtek Semiconductor Corp.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Start Menu 8 (HKLM-x32\...\IObit_StartMenu8_is1) (Version: 2.2.0 - IObit)
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.80.99066 - SugarSync, Inc.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.5 - Synaptics Incorporated)
Tele2 Mobile Partner (HKLM-x32\...\Tele2 Mobile Partner) (Version: 21.005.11.04.56 - Huawei Technologies Co.,Ltd)
Windows Driver Package - Intel Corporation (iaStorA) HDC (09/01/2012 11.6.0.1030) (HKLM\...\C5447D3383070620C3892FF393F522D6225CBA13) (Version: 09/01/2012 11.6.0.1030 - Intel Corporation)
Windows Driver Package - Lenovo 1.66.00.07 (08/15/2012 1.66.00.07) (HKLM\...\E56A6B34B44A7A597FFEBE0E14D81095E0FD4D73) (Version: 08/15/2012 1.66.00.07 - Lenovo)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3490378375-1854901139-762114773-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Peiman91\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3490378375-1854901139-762114773-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Peiman91\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3490378375-1854901139-762114773-1001_Classes\CLSID\{9E506282-69D3-5ABA-9C1D-15994B37F4AC}\InprocServer32 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll (Intel)
CustomCLSID: HKU\S-1-5-21-3490378375-1854901139-762114773-1001_Classes\CLSID\{9E506282-69D3-5ABA-9C1D-15994B37F4AD}\InprocServer32 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll (Intel)
CustomCLSID: HKU\S-1-5-21-3490378375-1854901139-762114773-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Peiman91\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)

==================== Restore Points =========================

26-07-2016 22:07:09 Schemalagd kontrollpunkt
23-08-2016 21:27:18 Schemalagd kontrollpunkt

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {08DF0EB1-A678-479A-98B5-7FBDC704EEF5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {0EA401C7-BA98-4919-96AD-89F5C06CC890} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2012-09-28] ()
Task: {4175304A-4AB6-4B5D-8D0F-C10B55EED719} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3490378375-1854901139-762114773-1001Core => C:\Users\Peiman91\AppData\Local\Google\Update\GoogleUpdate.exe [2016-07-25] (Google Inc.)
Task: {41972796-8A0A-41E2-990D-057315E05C9B} - System32\Tasks\Lenovo\sysrun-480 => C:\Users\Peiman91\AppData\Local\Temp\sysrun-480.cmd <==== ATTENTION
Task: {4DD46B86-690E-4DF5-99F4-64058E179117} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {51B5417E-7C4B-46DD-A8A3-DAEB114FE43A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-05] (Piriform Ltd)
Task: {863AFDB1-311D-4438-9201-22EB341CA9BE} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\WSCStub.exe [2015-07-27] (Symantec Corporation)
Task: {8BB9B013-38F8-4BF7-A75B-808CCA8CFC4F} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {8F5CF9F9-32A0-4D25-86D0-D581C9C8BB89} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2015-07-27] (Symantec Corporation)
Task: {907954A7-4863-4077-A714-967E49F42120} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16] (Synaptics Incorporated)
Task: {945062D2-BACA-4481-AC00-2A7897ADB162} - System32\Tasks\Lenovo\Lenovo-8019 => C:\ProgramData\Lenovo-8019.vbs [2013-05-10] ()
Task: {99EABCC7-C34A-4123-B8BE-9785CA2A53ED} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3490378375-1854901139-762114773-1001UA => C:\Users\Peiman91\AppData\Local\Google\Update\GoogleUpdate.exe [2016-07-25] (Google Inc.)
Task: {A2D0CDDB-FD57-4F38-9E96-A937886983BA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {A9D93BC0-CAA6-47ED-8196-DD4BB61BA62F} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {BFCF5CF0-082A-4284-A006-54C14E39399A} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {D098BCC8-B4DE-4BA6-B4F6-9094F427C472} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {F43357BE-80E4-4334-AB04-CA2C463D56F6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3490378375-1854901139-762114773-1001Core.job => C:\Users\Peiman91\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3490378375-1854901139-762114773-1001UA.job => C:\Users\Peiman91\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2012-09-26 03:34 - 2012-09-26 03:34 - 00047480 _____ () C:\Program Files\Lenovo\Bluetooth Software\BtwLeAPI.dll
2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2015-06-28 22:31 - 2012-03-12 11:05 - 00232288 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2015-06-28 22:28 - 2012-11-01 12:49 - 00657504 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
2012-08-31 13:43 - 2012-08-31 13:43 - 01130344 _____ () C:\Program Files\Lenovo Fingerprint Reader\DataManager.dll
2012-08-31 13:43 - 2012-08-31 13:43 - 00087400 _____ () C:\Program Files\Lenovo Fingerprint Reader\ssutil.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00218624 _____ () C:\ProgramData\Tele2 Mobile Partner\OnlineUpdate\ouc.exe
2013-05-09 23:52 - 2012-08-24 12:52 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-05-10 00:12 - 2012-12-19 16:17 - 00104448 _____ () C:\Program Files (x86)\ThinkPad\Utilities\SV\PWMRT64V.DLL
2013-05-10 00:11 - 2013-01-02 21:55 - 00175008 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2012-07-25 22:44 - 2012-07-25 22:35 - 00070144 _____ () C:\windows\system32\WinMetadata\Windows.Networking.winmd
2013-02-06 04:01 - 2013-02-06 04:01 - 00458744 _____ () C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
2012-08-31 13:44 - 2012-08-31 13:44 - 04622184 _____ () C:\Program Files\Lenovo Fingerprint Reader\x86\IEWebSiteLogon.exe
2015-05-22 23:14 - 2015-05-22 23:14 - 00514048 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\Tele2 Mobile Partner.exe
2013-02-06 04:01 - 2013-02-06 04:01 - 00014328 _____ () C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
2012-11-28 18:21 - 2012-11-01 21:43 - 00175008 _____ () C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2016-09-03 21:09 - 2016-09-03 21:09 - 03826240 _____ () C:\Users\Peiman91\Downloads\adwcleaner_6.010.exe
2013-05-10 00:07 - 2012-11-09 05:14 - 00033072 _____ () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll
2013-05-10 00:13 - 2012-11-27 01:37 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll
2013-05-10 00:13 - 2012-11-27 01:37 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll
2015-08-22 22:53 - 2015-05-20 19:03 - 00622880 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2015-06-28 22:28 - 2009-01-10 12:32 - 00011362 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\mingwm10.dll
2015-06-28 22:28 - 2009-06-22 20:42 - 00043008 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\libgcc_s_dw2-1.dll
2015-06-28 22:28 - 2010-05-10 04:51 - 02415104 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtCore4.dll
2015-06-28 22:28 - 2010-02-10 16:10 - 01148416 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtNetwork4.dll
2015-06-28 22:28 - 2012-11-01 12:26 - 00843264 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QueryStrategy.dll
2015-06-28 22:28 - 2010-02-10 16:06 - 00398336 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtXml4.dll
2016-09-02 22:19 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2016-09-02 22:19 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2016-09-02 22:19 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2016-09-02 22:19 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2016-09-02 22:19 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2015-08-22 22:53 - 2015-05-20 19:03 - 00348960 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madExcept_.bpl
2015-08-22 22:53 - 2015-05-20 19:03 - 00183584 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madBasic_.bpl
2015-08-22 22:53 - 2015-05-20 19:03 - 00050976 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madDisAsm_.bpl
2015-08-22 22:53 - 2015-05-20 19:04 - 00268920 _____ () C:\Program Files (x86)\IObit\Start Menu 8\sqlite3.dll
2015-08-22 22:53 - 2015-05-20 19:03 - 00053024 _____ () C:\Program Files (x86)\IObit\Start Menu 8\parseAuto.dll
2015-08-22 22:53 - 2015-05-20 19:03 - 00622880 _____ () C:\Program Files (x86)\IObit\Start Menu 8\ProductStatistics.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00011362 _____ () C:\ProgramData\Tele2 Mobile Partner\OnlineUpdate\mingwm10.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00043008 _____ () C:\ProgramData\Tele2 Mobile Partner\OnlineUpdate\libgcc_s_dw2-1.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 02415104 _____ () C:\ProgramData\Tele2 Mobile Partner\OnlineUpdate\QtCore4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 01148416 _____ () C:\ProgramData\Tele2 Mobile Partner\OnlineUpdate\QtNetwork4.dll
2015-08-22 22:53 - 2015-05-20 19:04 - 00041248 _____ () C:\Program Files (x86)\IObit\Start Menu 8\winkey.dll
2016-08-08 23:49 - 2016-08-03 02:24 - 01771336 _____ () C:\Users\Peiman91\AppData\Local\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-08 23:49 - 2016-08-03 02:23 - 00094024 _____ () C:\Users\Peiman91\AppData\Local\Google\Chrome\Application\52.0.2743.116\libegl.dll
2012-08-31 13:44 - 2012-08-31 13:44 - 00900456 _____ () C:\Program Files\Lenovo Fingerprint Reader\x86\DataManager.dll
2013-05-09 23:47 - 2012-06-25 04:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-08-20 21:39 - 2012-05-30 08:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.6.0.27\wincfi39.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00428032 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\core.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00261632 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\sdk.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00011362 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\mingwm10.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00043008 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\libgcc_s_dw2-1.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 02415104 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\QtCore4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 09515520 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\QtGui4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00381952 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\Proxy.DLL
2015-05-22 23:14 - 2015-05-22 23:13 - 00218112 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\Common.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00135168 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\Trace.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00545280 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\PluginContainer.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00238080 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\AtCodec.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00301056 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\DeviceSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00235008 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NetSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00133120 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\OSDialup.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00159232 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\XCodec.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00157184 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\DataServicePlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00176128 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\CallSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00264704 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\AddrBookSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00217600 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\SmsSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00142336 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\USSDSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00156672 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\STKSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00338432 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\DeviceAppPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00065536 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\OSPowerMgr.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00106496 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\Win7Support.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 01077248 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\AddrBookPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00670720 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\SmsAppPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00550400 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\CallAppPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00547840 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\CallLogSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00158720 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NetConnectSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00211968 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\DialUpPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00101376 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\OSAdapt.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00180224 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NDISPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00131072 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\OSNDIS.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 01101824 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NDISAPI.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00278528 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NetInfoSrvPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00062976 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\OSCall.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00495104 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\DeviceMgrUIPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00123392 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\ATR2SMgr.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00184832 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\XFramePlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00337920 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\StatusBarMgrPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00117760 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\LayoutPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00428032 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\DialupUIPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00093184 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NotifyServicePlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00333312 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NetConnectPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00249344 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\MenuMgrPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00483328 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\NetInfoUIExPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00808960 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\SMSUIPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00739328 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\AddrBookUIPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00239104 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\LiveUpdateInterface.DLL
2015-05-22 23:14 - 2015-05-22 23:13 - 01148416 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\QtNetwork4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00229888 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\ToolBarMgrPlugin.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00082944 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\plugins\imageformats\qgif4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00081920 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\plugins\imageformats\qico4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00192000 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\plugins\imageformats\qjpeg4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00350720 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\plugins\imageformats\qmng4.dll
2015-05-22 23:14 - 2015-05-22 23:13 - 00370176 _____ () C:\Program Files (x86)\Tele2 Mobile Partner\plugins\imageformats\qtiff4.dll
2016-08-08 23:49 - 2016-08-03 01:54 - 17602240 _____ () C:\Users\Peiman91\AppData\Local\Google\Chrome\Application\52.0.2743.116\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3490378375-1854901139-762114773-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Peiman91\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 130.244.127.161 - 130.244.127.169
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{B17A3016-E18F-4D3C-B1D2-2EADC68C9FA4}] => (Allow) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
FirewallRules: [{B678446C-78DE-4B76-8DBE-B961F36749B4}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe
FirewallRules: [{A4A9BE78-087D-46F7-87B5-8AEAA5088900}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Faulty Device Manager Devices =============

Name: Broadcom Bluetooth 4.0 USB
Description: Broadcom Bluetooth 4.0 USB
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/03/2016 08:44:17 PM) (Source: Windows Search Service) (EventID: 3079) (User: )
Description: Aviseringar för volymen C:\ är inte aktiva.

Kontext: program Windows

Information:
Journalen för volymändringar tas bort. (HRESULT : 0x8007049a) (0x8007049a)

Error: (09/03/2016 08:42:48 PM) (Source: Location Task Manager) (EventID: 0) (User: )
Description: (CheckLpdVersion()): Det gick inte att öppna common_lpd.xml, kontrollera om Location Awareness är installerat: C:\ProgramData\Lenovo\LocationAware\common_lpd.xml

Error: (09/03/2016 08:42:48 PM) (Source: Location Task Manager) (EventID: 0) (User: )
Description: (CheckLpdVersion()): Det går inte att hitta user_lpd.xml, kontrollera om Lenovo Settings är installerat: C:\Users\Peiman91\AppData\Local\Packages\LenovoCorporation.LenovoSettings_4642shxvsv8s2\LocalState\user_lpd.xml

Error: (09/03/2016 03:58:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Peiman)
Description: Appen DefaultBrowser_NOPUBLISHERID!Chrome.LHL3MVPUNIELVL32XKDKC4HDEI startade inte inom den tilldelade tiden.

Error: (09/03/2016 03:58:20 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Peiman)
Description: Aktiveringen av appen DefaultBrowser_NOPUBLISHERID!Chrome.LHL3MVPUNIELVL32XKDKC4HDEI misslyckades med felet: -2144927141 Mer information finns i loggen Microsoft-Windows-TWinUI/Operational.

Error: (09/03/2016 03:56:55 AM) (Source: Location Task Manager) (EventID: 0) (User: )
Description: (CheckLpdVersion()): Det gick inte att öppna common_lpd.xml, kontrollera om Location Awareness är installerat: C:\ProgramData\Lenovo\LocationAware\common_lpd.xml

Error: (09/03/2016 03:56:55 AM) (Source: Location Task Manager) (EventID: 0) (User: )
Description: (CheckLpdVersion()): Det går inte att hitta user_lpd.xml, kontrollera om Lenovo Settings är installerat: C:\Users\Peiman91\AppData\Local\Packages\LenovoCorporation.LenovoSettings_4642shxvsv8s2\LocalState\user_lpd.xml

Error: (09/03/2016 03:50:17 AM) (Source: Location Task Manager) (EventID: 0) (User: )
Description: (CheckLpdVersion()): Det gick inte att öppna common_lpd.xml, kontrollera om Location Awareness är installerat: C:\ProgramData\Lenovo\LocationAware\common_lpd.xml

Error: (09/03/2016 03:50:17 AM) (Source: Location Task Manager) (EventID: 0) (User: )
Description: (CheckLpdVersion()): Det går inte att hitta user_lpd.xml, kontrollera om Lenovo Settings är installerat: C:\Users\Peiman91\AppData\Local\Packages\LenovoCorporation.LenovoSettings_4642shxvsv8s2\LocalState\user_lpd.xml

Error: (09/03/2016 01:18:27 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Peiman)
Description: Aktiveringen av appen SymantecCorporation.NortonStudio_v68kp9n051hdp!App misslyckades med felet: -2147023170 Mer information finns i loggen Microsoft-Windows-TWinUI/Operational.


System errors:
=============
Error: (09/03/2016 08:40:43 PM) (Source: DCOM) (EventID: 10016) (User: NT instans)
Description: datorstandardvärdeLokalAktivering{7160A13D-73DA-4CEA-95B9-37356478588A}Inte tillgängligNT instansLokal tjänstS-1-5-19LocalHost (med LRPC)Inte tillgängligInte tillgänglig

Error: (09/03/2016 08:40:43 PM) (Source: DCOM) (EventID: 10016) (User: NT instans)
Description: datorstandardvärdeLokalAktivering{7160A13D-73DA-4CEA-95B9-37356478588A}Inte tillgängligNT instansLokal tjänstS-1-5-19LocalHost (med LRPC)Inte tillgängligInte tillgänglig

Error: (09/03/2016 08:40:32 PM) (Source: DCOM) (EventID: 10016) (User: NT instans)
Description: datorstandardvärdeLokalAktivering{7160A13D-73DA-4CEA-95B9-37356478588A}Inte tillgängligNT instansLokal tjänstS-1-5-19LocalHost (med LRPC)Inte tillgängligInte tillgänglig

Error: (09/03/2016 08:40:32 PM) (Source: DCOM) (EventID: 10016) (User: NT instans)
Description: datorstandardvärdeLokalAktivering{7160A13D-73DA-4CEA-95B9-37356478588A}Inte tillgängligNT instansLokal tjänstS-1-5-19LocalHost (med LRPC)Inte tillgängligInte tillgänglig

Error: (09/03/2016 08:40:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjänsten Tele2 Mobile Partner. OUC kunde inte startas på grund av följande fel:
%%1053

Error: (09/03/2016 08:40:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: En timeout (30000 ms) inträffade vid väntan på att tjänsten Tele2 Mobile Partner. OUC skulle ansluta.

Error: (09/03/2016 08:40:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjänsten Mobile Partner. OUC kunde inte startas på grund av följande fel:
%%1053

Error: (09/03/2016 08:40:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: En timeout (30000 ms) inträffade vid väntan på att tjänsten Mobile Partner. OUC skulle ansluta.

Error: (09/03/2016 03:58:20 AM) (Source: DCOM) (EventID: 10010) (User: Peiman)
Description: DefaultBrowser.DefaultBrowserActivatableClass

Error: (09/03/2016 03:54:40 AM) (Source: DCOM) (EventID: 10016) (User: NT instans)
Description: datorstandardvärdeLokalAktivering{7160A13D-73DA-4CEA-95B9-37356478588A}Inte tillgängligNT instansLokal tjänstS-1-5-19LocalHost (med LRPC)Inte tillgängligInte tillgänglig


CodeIntegrity:
===================================
Date: 2016-09-03 01:18:25.195
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-08-24 21:43:49.758
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-08-21 21:55:05.527
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-08-08 23:51:31.362
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-08-05 17:25:58.081
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-08-02 23:22:11.036
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-07-29 22:34:22.075
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-07-26 21:52:29.345
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-07-24 22:17:33.329
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\diStTask.dll with signing level Unsigned while the system requires signing level 6 or better to load.

Date: 2016-07-22 10:44:32.885
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SysWOW64\backgroundTaskHost.exe) attempted to load \Device\HarddiskVolume4\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.98_x86__v68kp9n051hdp\Settings.dll with signing level Unsigned while the system requires signing level 6 or better to load.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2348M CPU @ 2.30GHz
Percentage of memory in use: 60%
Total physical RAM: 3948.22 MB
Available physical RAM: 1554.49 MB
Total Virtual: 5062.74 MB
Available Virtual: 2111.02 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:913.54 GB) (Free:875.84 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (Tele2 3G-modem) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 2F859DC9)

Partition: GPT.

==================== End of Addition.txt ============================
 

NovusVirtae

New Member
Thread author
Sep 3, 2016
2
I may add that a website opens up with:

ATTENTION!YOUR FILES ARE ENCRYPTED.
Write down the information to notebook (excercise book!) and reboot the computer.

For more specific instructions,please visit your personal home page, there are a few different addresses pointing to your page below:
Code:
http://ccjlwb22w6c22p2k.onion.to
http://ccjlwb22w6c22p2k.onion.city
If for some reasons the addresses are not available, follow these steps:

  1. Download and install tor-browser: https://torproject.org/projects/torbrowser.html
  2. After a successful installation, run the browser
  3. Type in the address bar:
Code:
http://ccjlwb22w6c22p2k.onion
  1. Follow the instructions on the site.

 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top