Премини към съдържанието

stefanbkanev

Потребител
  • Публикации

    21
  • Регистрация

  • Последно онлайн

Харесвания

10 Добра репутация

Всичко за stefanbkanev

  • Титла
    Потребител
  1. Прикачвам файловете и от проверките с FRST и emsisoft. Addition.txt FRST.txt scan_160323-130758.txt
  2. Здравейте, сканирах с всички програми с Hitman и ADW ми изписа, че няма заразени файлове, а с останалите прикачвам .txt файловете. JRT.txt MAM.txt ZHPCleaner.txt
  3. Много се извинявам за късния отговор. Направих стъпка 1. И ми излезе файл DelFix.txt, който прикачвам. Антивирусните програми от точка 2 не ми тръгват, изписва ми, че Windows не може да намери директорията на файла, уверете се, че сте въвели правилно името. DelFix.txt
  4. Изпълних и тези две стъпки и всичко изглежда доста по-добре отпреди, дори лаптопа ми имам чувството, че работи по-бързо, отново го няма този досаден safe finder, дано сме се оттървали напълно вече. Fixlog.txt ZHPCleaner.txt
  5. Справих се с всички стъпки и прикачвам всичките файлове от всички програми. Десктопа ми заприлича на коледна елха нямам място на екрана от антивирусни системи, текстови и логови файлове. checkup.txt HitmanPro_20160321_1805.log HitmanPro_20160321_1807.log MAM.txt scan_160321-181540.txt ZHPCleaner.txt
  6. Прикачвам FRST.txt и ESET.log и се заемам с новите стъпки. ESETNecursCleaner.exe_20160320.214005.14556.log FRST.txt Имам известен проблем с използване на първата програма, като свърши сканирането ми излизат 30 бръмбъра (предполагам са вируси това) и после ми излиза ето този прозорец, на който не знам къде да кликна (прикачил съм снимка). Междувременно имам изключително лошата новина, safe finder отново се появи (дори не знам как и откъде, при положение, че днес не съм правил абсолютно нищичко на компютъра, а снощи си беше ОК).
  7. Да windows е вече активиран и чакам следващите инструкции. Още веднъж искам да изкажа огромни благодарности за професионализма на целият Ви екип.
  8. Още веднъж искам да изкажа огромните си благодарности за оказаната помощ. Изключително бързи и компетентни. Номер едно сте!!!
  9. Успях да отворя стъпка 2 и ги направих заедно с останалите стъпки. Прикачвам всички файлове, които ми се появиха. Междувременно вируса го няма вече и браузъра ми си работи нормално, за което съм изключително благодарен. Прикачих и една снимка при последното рестартиране ми се появи, че нямам ключ за windows (дадох попитай ме по-късно и засега си работи с малкото изключение, че ми се премахна картината на десктопа и каквато и да сложа си стои, като черен екран). Fixlog.txt AdwCleaner[C1].txt AdwCleaner[S1].txt AdwCleaner[S2].txt JRT.txt Addition.txt
  10. Приключих със стъпка 1, но имам проблем със стъпка 2, въобще не ми отваря страницата. Изписва ми: Не може да бъде установена връзка Firefox не може да установи връзка с general-changelog-team.fr. Страницата може да е временно недостъпна или твърде заета. Опитайте пак след малко. Ако не можете да заредите друга страница, проверете хардуера на компютъра. Ако компютърът или мрежата ви са зад защитна стена или прокси проверете дали на Firefox е разрешен достъпът до Интернет. Пробвах и с друг браузър и отново същото. Междувременно прикачвам файла от стъпка 1. Fixlog.txt
  11. Изпълних стъпките, само на стъпка 2 не ми излезе Do you want to restart your computer. Прикачвам новите резултати след изпълнението на стъпка 1 и 2. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 Ran by Stefan (administrator) on STEFAN-PC (20-03-2016 21:41:51) Running from C:\Users\Stefan\Downloads Loaded Profiles: Stefan & postgres (Available Profiles: Stefan & postgres) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Английски (Съединени щати) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe () C:\Program Files\BitTorrent\BitTorrent.exe (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\ProgramData\CloudPrinter\CloudPrinter.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe () C:\ProgramData\KMSAuto\KMSES.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\pg_ctl.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Windows\Installer\{3F34C515-AD21-CC86-6996-BAB248A3AE93}\syshost.exe (Microsoft Corporation) C:\Windows\SysWOW64\netsh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe () C:\ProgramData\afoir\afoir.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Windows\System32\slui.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE () C:\Program Files (x86)\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Program Files (x86)\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.12\deploy\LoLLauncher.exe () C:\Program Files (x86)\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.52\deploy\LoLPatcher.exe () C:\Program Files (x86)\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.188\deploy\LolClient.exe (BitTorrent Inc.) C:\Users\Stefan\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.) C:\Users\Stefan\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe (BitTorrent Inc.) C:\Users\Stefan\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Farbar) C:\Users\Stefan\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [178960 2012-03-15] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-25] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation) HKLM-x32\...\Run: [MobileConnect] => %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [592704 2015-09-29] (Razer Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation) HKLM-x32\...\Run: [syshost32] => C:\Windows\Installer\{3F34C515-AD21-CC86-6996-BAB248A3AE93}\syshost.exe Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [1337573597] => C:\ProgramData\msvddgr.exe [73427712 2010-11-21] () HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [uTorrent] => C:\Users\Stefan\AppData\Roaming\uTorrent\uTorrent.exe [2094080 2016-03-06] (BitTorrent Inc.) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-04] (Valve Corporation) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [{B64A3306-E5BC-4C45-8075-ABDC901C1837}] => powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\NcMrJwyXG').YFEXBDTAUQEL))); HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [909696 2010-12-21] (Microsoft Corporation) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50676864 2016-03-01] (Skype Technologies S.A.) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Voobly] => C:\Program Files (x86)\Voobly\voobly.exe [159744 2016-02-23] (Voobly) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {2bf66421-9032-11e5-8ebf-606c665b70ec} - F:\SETUP.EXE HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {2bf66425-9032-11e5-8ebf-606c665b70ec} - H:\SETUP.EXE HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {4acbd087-3947-11e5-8ca3-606c665b70ec} - F:\setup.exe HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {d69c4c94-9983-11e5-94d3-606c665b70ec} - F:\aocsetup.exe /autorun HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation) AppInit_DLLs: C:\ProgramData\afoir\Zoomhold.dll => C:\ProgramData\afoir\Zoomhold.dll [363520 2016-03-13] () AppInit_DLLs-x32: C:\ProgramData\afoir\Bioozekix.dll => C:\ProgramData\afoir\Bioozekix.dll [257536 2016-03-13] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{61418247-B566-47D0-BE75-6F77C03F365B}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLF0dPujPrN1bYvhG3ajvv2yu3GBQ7I4Yc17Hp2rRIy_2djBa5nUcY-CyiWCvtnEOeV_w40Ml0AZTEUJLD9Zqxx2A5hl_bUA, HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLF0dPujPrN1bYvhG3ajvv2yu3GBQ7I4Yc17Hp2rRIy_2djBa5nUcY-CyiWCvtnEOeV_w40Ml0AZTEUJLD9Zqxx2A5hl_bUA, HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} URLSearchHook: HKLM-x32 -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-353&apn_uid=9752226053614134&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2911250186-2008469882-1143044474-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2911250186-2008469882-1143044474-1004 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2911250186-2008469882-1143044474-1004 -> {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2012-08-16] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-24] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-24] (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\n61u4qmb.default-1458467973018 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-11] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-11] () FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-24] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-24] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\n61u4qmb.default-1458467973018\user.js [2016-03-20] FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-20] [not signed] Chrome: ======= CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1405030083&from=amt&uid=HGSTXHTS541010A9E680_JD1000191D7WLN1D7WLNX" CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Wallet) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-19] CHR HKLM-x32\...\Chrome\Extension: [fcgnigmofekcllgbiejhmigggmgehkip] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 afoir; C:\ProgramData\\afoir\\afoir.exe [529408 2016-03-13] () [File not signed] R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 BitTorrent; C:\Program Files\BitTorrent\BitTorrent.exe [383488 2016-03-13] () [File not signed] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [761856 2016-03-13] () [File not signed] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation) R2 KMSEmulator; C:\ProgramData\KMSAuto\KMSES.exe [249344 2013-11-16] () [File not signed] S2 KMSServerService; D:\Торенти\KMSAuto Easy 1.06.V6 (Activator For Windows 7,8,8.1 and Office 1\KMSServerService.exe [260608 2013-11-16] (My Digital Life Forums) [File not signed] S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation) S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation) R2 postgresql-x64-9.0; C:\Program Files\PostgreSQL\9.0\bin\pg_ctl.exe [111104 2012-09-21] (PostgreSQL Global Development Group) [File not signed] S2 pyodqctprodlct; C:\Users\Stefan\AppData\Local\Konkstrip.exe [28160 2016-03-13] () [File not signed] R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] () S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1042304 2016-03-20] (Enigma Software Group USA, LLC.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH) S2 TunMirror; D:\Торенти\KMSAuto Easy 1.06.V6 (Activator For Windows 7,8,8.1 and Office 1\TunMirror.exe [10752 2013-11-16] () [File not signed] R2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S1 20354967; C:\Windows\system32\drivers\20354967.sys [92120 2016-01-06] () [File not signed] S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-08-08] (Disc Soft Ltd) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-12-18] (DT Soft Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-03-20] () S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation) R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [50392 2015-08-13] (Razer Inc) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129472 2015-06-27] (Razer, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381608 2015-08-08] (Duplex Secure Ltd.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-20 21:41 - 2016-03-20 21:41 - 02374144 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64(1).exe 2016-03-20 21:37 - 2016-03-20 21:37 - 00260296 _____ (ESET) C:\Users\Stefan\Desktop\ESETNecursCleaner.exe 2016-03-20 21:32 - 2016-03-20 21:35 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Geek Uninstaller 2016-03-20 21:32 - 2016-03-20 21:32 - 02587378 _____ C:\Users\Stefan\Desktop\geek.zip 2016-03-20 21:32 - 2016-02-01 01:28 - 06358040 _____ (Geek Uninstaller) C:\Users\Stefan\Desktop\geek.exe 2016-03-20 21:27 - 2016-03-20 21:27 - 00000000 ____D C:\Users\Stefan\AppData\LocalLow\uTorrent 2016-03-20 19:43 - 2016-03-20 19:43 - 00052700 _____ C:\Users\Stefan\Desktop\Addition.txt 2016-03-20 19:37 - 2016-03-20 21:41 - 00026011 _____ C:\Users\Stefan\Downloads\FRST.txt 2016-03-20 19:37 - 2016-03-20 21:41 - 00000000 ____D C:\FRST 2016-03-20 19:37 - 2016-03-20 19:42 - 00052700 _____ C:\Users\Stefan\Downloads\Addition.txt 2016-03-20 19:36 - 2016-03-20 19:36 - 02374144 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64.exe 2016-03-20 11:59 - 2016-03-20 11:59 - 00000000 ____D C:\Users\Stefan\Desktop\Стари данни Firefox 2016-03-20 11:35 - 2016-03-20 11:35 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Stefan\Downloads\SpyHunter-Installer.exe 2016-03-20 11:07 - 2016-03-20 11:07 - 00000000 _____ C:\autoexec.bat 2016-03-20 11:06 - 2016-03-20 11:06 - 00003332 _____ C:\Windows\System32\Tasks\SpyHunter4Startup 2016-03-20 11:06 - 2016-03-20 11:06 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2016-03-20 11:06 - 2016-03-20 11:06 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Enigma Software Group 2016-03-20 11:06 - 2016-03-20 11:06 - 00000000 ____D C:\sh4ldr 2016-03-20 11:05 - 2016-03-20 11:05 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys 2016-03-20 11:05 - 2016-03-20 11:05 - 00000000 ____D C:\Program Files\Enigma Software Group 2016-03-20 01:16 - 2016-03-20 10:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-03-14 18:16 - 2016-03-14 18:16 - 00003248 _____ C:\Windows\System32\Tasks\psv_Zaamtom 2016-03-14 18:15 - 2016-03-14 18:15 - 00003262 _____ C:\Windows\System32\Tasks\psv_TresQuoeco 2016-03-14 17:49 - 2016-03-14 17:49 - 00003234 _____ C:\Windows\System32\Tasks\producadoo 2016-03-14 06:14 - 2016-03-14 06:14 - 00003388 _____ C:\Windows\System32\Tasks\o3zplhly 2016-03-14 06:14 - 2016-03-14 06:14 - 00000000 ____D C:\Program Files\Common Files\pmk10zge 2016-03-14 05:14 - 2016-03-14 05:14 - 00003388 _____ C:\Windows\System32\Tasks\cnt5j0b3 2016-03-14 05:14 - 2016-03-14 05:14 - 00000000 ____D C:\Program Files\Common Files\m2pxazue 2016-03-14 04:14 - 2016-03-14 04:14 - 00003388 _____ C:\Windows\System32\Tasks\drf40eed 2016-03-14 04:14 - 2016-03-14 04:14 - 00000000 ____D C:\Program Files\Common Files\zivb3dwl 2016-03-14 03:14 - 2016-03-14 03:14 - 00003388 _____ C:\Windows\System32\Tasks\jaancasl 2016-03-14 03:14 - 2016-03-14 03:14 - 00000000 ____D C:\Program Files\Common Files\hykbkrt4 2016-03-14 02:14 - 2016-03-14 02:14 - 00003388 _____ C:\Windows\System32\Tasks\shypmcwx 2016-03-14 02:14 - 2016-03-14 02:14 - 00000000 ____D C:\Program Files\Common Files\dchpkqot 2016-03-14 01:14 - 2016-03-14 01:14 - 00003388 _____ C:\Windows\System32\Tasks\0ksidqpu 2016-03-14 01:14 - 2016-03-14 01:14 - 00000000 ____D C:\Program Files\Common Files\y1315233 2016-03-14 00:14 - 2016-03-14 00:14 - 00003388 _____ C:\Windows\System32\Tasks\z253j3j1 2016-03-14 00:14 - 2016-03-14 00:14 - 00000000 ____D C:\Program Files\Common Files\wr1evdgk 2016-03-13 23:14 - 2016-03-19 23:43 - 00000000 ____D C:\ProgramData\afoir 2016-03-13 23:14 - 2016-03-13 23:14 - 00003388 _____ C:\Windows\System32\Tasks\lruw24vh 2016-03-13 23:14 - 2016-03-13 23:14 - 00000000 ____D C:\ProgramData\afoirs 2016-03-13 23:14 - 2016-03-13 23:14 - 00000000 ____D C:\Program Files\Common Files\blo2ut03 2016-03-13 22:14 - 2016-03-13 22:14 - 00003388 _____ C:\Windows\System32\Tasks\zw5cgoyc 2016-03-13 22:14 - 2016-03-13 22:14 - 00000000 ____D C:\Program Files\Common Files\ea3ostxi 2016-03-13 21:14 - 2016-03-13 21:14 - 00003388 _____ C:\Windows\System32\Tasks\i0w24las 2016-03-13 21:14 - 2016-03-13 21:14 - 00000000 ____D C:\Program Files\Common Files\3nkjdsje 2016-03-13 20:15 - 2016-03-13 20:15 - 00001734 _____ C:\Users\Stefan\Desktop\Counter-Strike WaRzOnE.lnk 2016-03-13 20:14 - 2016-03-13 23:14 - 00000000 ____D C:\Program Files\BitTorrent 2016-03-13 20:13 - 2016-03-19 23:43 - 00002394 _____ C:\Windows\SysWOW64\findit.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 07600640 _____ C:\Users\Stefan\AppData\Roaming\agent.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 01787264 _____ C:\Users\Stefan\AppData\Roaming\ViaNimphase.tst 2016-03-13 20:13 - 2016-03-13 20:13 - 00848437 _____ C:\Users\Stefan\AppData\Roaming\Nimtom.bin 2016-03-13 20:13 - 2016-03-13 20:13 - 00189695 _____ () C:\Users\Stefan\AppData\Roaming\Sanla.bin 2016-03-13 20:13 - 2016-03-13 20:13 - 00126464 _____ C:\Users\Stefan\AppData\Roaming\noah.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00126464 _____ C:\Users\Stefan\AppData\Roaming\lobby.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00072714 _____ C:\Users\Stefan\AppData\Roaming\Domlam.tst 2016-03-13 20:13 - 2016-03-13 20:13 - 00065040 _____ C:\Users\Stefan\AppData\Roaming\Config.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 00054272 _____ C:\Users\Stefan\AppData\Roaming\ApplicationHosting.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00041472 _____ C:\Users\Stefan\AppData\Local\Konkstrip.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00028160 _____ C:\Users\Stefan\AppData\Local\Konkstrip.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 00018432 _____ C:\Users\Stefan\AppData\Roaming\Main.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00005568 _____ C:\Users\Stefan\AppData\Roaming\md.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 00000187 _____ C:\Users\Stefan\AppData\Local\Konkstrip.exe.config 2016-03-13 20:13 - 2016-03-13 20:13 - 00000000 ____D C:\ProgramData\Ronzaps 2016-03-13 20:13 - 2016-03-13 20:13 - 00000000 ____D C:\ProgramData\CloudPrinter 2016-03-13 20:13 - 2016-03-13 20:12 - 00761856 _____ C:\Users\Stefan\AppData\Roaming\ViaNimphase.exe 2016-03-13 20:13 - 2016-03-13 20:12 - 00761856 _____ C:\Users\Stefan\AppData\Roaming\Domlam.exe 2016-03-13 20:12 - 2016-03-13 20:13 - 00016992 _____ C:\Users\Stefan\AppData\Roaming\InstallationConfiguration.xml 2016-03-13 20:12 - 2016-03-13 20:12 - 00127488 _____ C:\Users\Stefan\AppData\Roaming\Installer.dat 2016-03-13 20:00 - 2016-03-13 20:00 - 00001948 _____ C:\Users\postgres\Desktop\Counter Strike 1.6 Non Steam.lnk 2016-03-13 20:00 - 2016-03-13 20:00 - 00001928 _____ C:\Users\postgres\Desktop\Dedicated Server.lnk 2016-03-13 19:59 - 2016-03-13 20:00 - 00000000 ____D C:\Program Files (x86)\Valve 2016-03-13 00:24 - 2016-03-13 00:24 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\NVIDIA 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HLDS 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Half-Life 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Games 2016-03-12 01:22 - 2013-01-27 18:32 - 00066331 _____ C:\Program Files (x86)\EULA.eng 2016-03-12 01:19 - 2016-03-12 01:19 - 00002033 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\888poker.lnk 2016-03-12 01:19 - 2016-03-12 01:19 - 00002009 _____ C:\Users\postgres\Desktop\888poker.lnk 2016-03-12 01:19 - 2016-03-12 01:19 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\PacificPoker 2016-03-12 01:19 - 2016-03-12 01:19 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\888poker 2016-03-12 01:19 - 2016-03-12 01:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\888poker 2016-03-12 01:18 - 2016-03-12 01:18 - 00000000 ____D C:\Program Files (x86)\888poker.net 2016-03-12 01:14 - 2016-03-12 01:23 - 00000000 ____D C:\Program Files (x86)\PacificPoker 2016-03-12 01:11 - 2016-03-12 01:26 - 00000000 ____D C:\Users\Stefan\Documents\888poker 2016-03-11 10:36 - 2016-03-20 21:33 - 00000000 ____D C:\Users\Stefan\AppData\Local\CrashDumps 2016-03-11 01:13 - 2016-03-14 18:13 - 00000000 ____D C:\Windows\SysWOW64\NV 2016-03-11 01:13 - 2016-03-14 18:13 - 00000000 ____D C:\Windows\system32\NV 2016-03-11 01:11 - 2016-03-08 12:07 - 42968120 _____ C:\Windows\system32\nvcompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 37609528 _____ C:\Windows\SysWOW64\nvcompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 22932928 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 21313024 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 20854680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 18990976 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 18879544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 17725040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 17318184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 17246680 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 16439328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 12564024 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-03-11 01:11 - 2016-03-08 12:07 - 10546944 _____ C:\Windows\system32\nvptxJitCompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 08658120 _____ C:\Windows\SysWOW64\nvptxJitCompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 03233336 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 02808768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 01924152 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436451.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 01571776 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436451.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00956984 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00886840 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00749504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00693816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00678520 _____ C:\Windows\system32\nvfatbinaryLoader.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00571912 _____ C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00473056 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00151368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00039992 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2016-03-11 01:11 - 2016-03-08 12:07 - 00000139 _____ C:\Windows\SysWOW64\nv-vk32.json 2016-03-11 01:11 - 2016-03-08 12:07 - 00000139 _____ C:\Windows\system32\nv-vk64.json 2016-03-08 22:52 - 2016-03-08 22:55 - 00000000 ____D C:\Program Files (x86)\PKR 2016-03-08 22:52 - 2016-03-08 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PKR 2016-03-08 21:37 - 2016-03-08 21:38 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-03-08 21:37 - 2016-03-08 21:37 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-03-08 21:30 - 2015-12-18 08:11 - 00047760 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-03-08 21:30 - 2015-12-18 08:10 - 00099472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2016-03-08 21:30 - 2015-12-18 08:10 - 00090768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 14128496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 00391632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 00175552 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2016-03-08 21:27 - 2016-02-24 01:58 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436200.dll 2016-03-08 21:27 - 2016-02-24 01:58 - 01571776 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436200.dll 2016-03-08 21:20 - 2016-02-17 08:40 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2016-03-08 21:20 - 2016-02-17 08:40 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2016-03-08 21:20 - 2016-02-17 08:40 - 00112216 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2016-03-08 21:19 - 2016-03-11 01:14 - 00000000 ____D C:\ProgramData\Package Cache 2016-02-25 13:03 - 2016-02-25 13:03 - 00001654 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk 2016-02-25 13:03 - 2016-02-25 13:03 - 00001642 _____ C:\Users\Public\Desktop\Poker at bet365.lnk 2016-02-25 13:02 - 2016-03-02 15:00 - 00000000 ____D C:\Program Files (x86)\Poker at bet365 2016-02-19 05:49 - 2016-02-19 05:49 - 00001078 _____ C:\Users\postgres\Desktop\PokerTracker 4.lnk 2016-02-19 05:49 - 2016-02-19 05:49 - 00000016 _____ C:\ProgramData\mntemp ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-20 21:41 - 2013-11-17 14:38 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Skype 2016-03-20 21:41 - 2013-11-16 00:30 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\uTorrent 2016-03-20 21:32 - 2009-07-14 06:45 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-03-20 21:32 - 2009-07-14 06:45 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-03-20 21:30 - 2013-11-17 15:11 - 00000000 ____D C:\Program Files (x86)\The KMPlayer 2016-03-20 21:16 - 2013-11-16 00:20 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-03-20 20:54 - 2013-11-16 00:20 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-03-20 20:54 - 2013-11-16 00:20 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-03-20 20:39 - 2015-11-03 03:42 - 00000000 ____D C:\Users\Stefan\AppData\Local\PokerStars.BG 2016-03-20 20:37 - 2014-09-26 22:46 - 00000000 ____D C:\Program Files (x86)\PokerStars.BG 2016-03-20 19:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-03-20 10:59 - 2015-12-20 21:31 - 00000000 ____D C:\Program Files (x86)\Voobly 2016-03-20 10:51 - 2013-11-17 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-03-20 02:38 - 2015-07-19 19:50 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-03-19 23:43 - 2013-11-17 14:34 - 00001169 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-03-19 23:43 - 2013-11-17 14:34 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-03-19 23:43 - 2013-11-16 01:44 - 00002294 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-19 23:43 - 2013-11-15 22:30 - 00001405 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-03-18 00:57 - 2014-06-11 20:53 - 00003864 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1384553415 2016-03-18 00:57 - 2013-11-16 00:10 - 00000000 ____D C:\Program Files (x86)\Opera 2016-03-17 07:44 - 2013-11-17 14:38 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-03-17 07:44 - 2013-11-17 14:37 - 00000000 ____D C:\ProgramData\Skype 2016-03-14 23:32 - 2015-09-13 18:49 - 00000000 ____D C:\Program Files (x86)\Steam 2016-03-14 18:19 - 2009-07-14 07:13 - 00782882 _____ C:\Windows\system32\PerfStringBackup.INI 2016-03-14 18:13 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-03-14 17:49 - 2014-11-09 23:30 - 00003254 _____ C:\Windows\System32\Tasks\PC Speed Maximizer Schedule 2016-03-13 22:20 - 2015-11-10 23:51 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk 2016-03-13 22:20 - 2015-11-10 23:51 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk 2016-03-13 22:20 - 2013-11-22 21:42 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-03-13 21:12 - 2014-02-13 15:04 - 00000000 ____D C:\Users\Stefan\AppData\Local\PokerTracker 4 2016-03-13 21:12 - 2014-02-13 15:04 - 00000000 ____D C:\Program Files (x86)\PokerTracker 4 2016-03-13 19:59 - 2013-11-16 00:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-12 01:19 - 2015-12-18 23:04 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2016-03-11 18:16 - 2015-07-19 19:50 - 00003890 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-03-11 18:16 - 2013-11-16 00:20 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-03-11 18:16 - 2013-11-16 00:20 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-11 18:16 - 2013-11-16 00:20 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-03-11 01:12 - 2013-11-15 23:24 - 00000000 ____D C:\ProgramData\NVIDIA 2016-03-08 21:38 - 2015-01-29 19:56 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-03-08 21:37 - 2013-11-16 00:50 - 00000000 ____D C:\ProgramData\Adobe 2016-03-08 21:31 - 2013-11-26 20:42 - 00000000 ____D C:\Users\Stefan\AppData\Local\NVIDIA Corporation 2016-03-08 21:31 - 2013-11-26 20:40 - 00000000 ____D C:\Users\Stefan\AppData\Local\NVIDIA 2016-03-08 21:31 - 2013-11-15 23:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-03-08 21:29 - 2013-11-15 23:23 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-03-08 21:28 - 2013-11-15 23:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-03-08 12:07 - 2013-11-17 14:37 - 03283896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2016-03-08 12:07 - 2013-04-08 13:32 - 03711024 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2016-03-08 12:07 - 2013-04-08 13:32 - 00036743 _____ C:\Windows\system32\nvinfo.pb 2016-03-08 08:27 - 2013-11-15 23:24 - 06369728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 02994232 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 02561472 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 01264064 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2016-03-08 08:27 - 2013-11-15 23:24 - 00532536 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2016-03-07 06:23 - 2013-11-15 23:24 - 06203411 _____ C:\Windows\system32\nvcoproc.bin 2016-03-06 15:09 - 2015-04-10 14:30 - 00000000 ____D C:\Users\Stefan\AppData\Local\Steam 2016-03-04 01:11 - 2013-11-16 01:06 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite 2016-03-04 01:09 - 2014-01-23 21:16 - 00000000 ____D C:\Windows\Minidump 2016-03-03 03:21 - 2013-11-22 21:52 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\TeamViewer 2016-03-02 21:08 - 2015-07-17 09:03 - 00003414 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily 2016-03-02 21:08 - 2015-07-17 09:03 - 00003288 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine 2016-03-02 21:08 - 2015-07-17 09:03 - 00000000 ____D C:\Program Files (x86)\Gyazo 2016-03-02 14:53 - 2015-06-26 19:36 - 00000000 ____D C:\Rua Gaming 2016-02-26 09:21 - 2015-12-20 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voobly 2016-02-24 01:58 - 2013-11-15 23:08 - 00215608 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL 2016-02-24 01:58 - 2013-11-15 23:08 - 00201664 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL 2016-02-19 05:50 - 2013-11-17 15:06 - 00000000 ____D C:\Program Files (x86)\PokerStars ==================== Files in the root of some directories ======= 2016-03-12 01:22 - 2013-01-27 18:32 - 0066331 _____ () C:\Program Files (x86)\EULA.eng 2013-11-16 01:50 - 2013-11-16 01:51 - 8138498 _____ () C:\Program Files (x86)\saplatform.com_12Beta1.zip 2016-03-13 20:13 - 2016-03-13 20:13 - 7600640 _____ () C:\Users\Stefan\AppData\Roaming\agent.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0054272 _____ () C:\Users\Stefan\AppData\Roaming\ApplicationHosting.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0065040 _____ () C:\Users\Stefan\AppData\Roaming\Config.xml 2016-03-13 20:13 - 2016-03-13 20:12 - 0761856 _____ () C:\Users\Stefan\AppData\Roaming\Domlam.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 0072714 _____ () C:\Users\Stefan\AppData\Roaming\Domlam.tst 2016-03-13 20:12 - 2016-03-13 20:13 - 0016992 _____ () C:\Users\Stefan\AppData\Roaming\InstallationConfiguration.xml 2016-03-13 20:12 - 2016-03-13 20:12 - 0127488 _____ () C:\Users\Stefan\AppData\Roaming\Installer.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0126464 _____ () C:\Users\Stefan\AppData\Roaming\lobby.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0018432 _____ () C:\Users\Stefan\AppData\Roaming\Main.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0005568 _____ () C:\Users\Stefan\AppData\Roaming\md.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 0848437 _____ () C:\Users\Stefan\AppData\Roaming\Nimtom.bin 2016-03-13 20:13 - 2016-03-13 20:13 - 0126464 _____ () C:\Users\Stefan\AppData\Roaming\noah.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0189695 _____ () C:\Users\Stefan\AppData\Roaming\Sanla.bin 2016-03-13 20:14 - 2016-03-13 20:14 - 0001150 _____ () C:\Users\Stefan\AppData\Roaming\uninstall_temp.ico 2016-03-13 20:13 - 2016-03-13 20:12 - 0761856 _____ () C:\Users\Stefan\AppData\Roaming\ViaNimphase.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 1787264 _____ () C:\Users\Stefan\AppData\Roaming\ViaNimphase.tst 2016-03-13 20:13 - 2016-03-13 20:13 - 0041472 _____ () C:\Users\Stefan\AppData\Local\Konkstrip.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0028160 _____ () C:\Users\Stefan\AppData\Local\Konkstrip.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 0000187 _____ () C:\Users\Stefan\AppData\Local\Konkstrip.exe.config 2008-05-23 16:48 - 2008-05-23 16:48 - 0020270 _____ () C:\ProgramData\DeviceInstaller.xml 2008-06-23 12:02 - 2008-06-23 12:02 - 0097410 ____R () C:\ProgramData\DeviceManager.xml.rc4 2014-02-13 15:04 - 2014-02-13 15:04 - 0004900 _____ () C:\ProgramData\flwjycbm.bab 2016-02-19 05:49 - 2016-02-19 05:49 - 0000016 _____ () C:\ProgramData\mntemp 2010-11-21 05:24 - 2010-11-21 05:24 - 73427712 ___SH () C:\ProgramData\msvddgr.exe Files to move or delete: ==================== C:\ProgramData\msvddgr.exe Some files in TEMP: ==================== C:\Users\Stefan\AppData\Local\Temp\geek_x64.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll [2010-11-21 05:24] - [2013-11-15 22:28] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79 C:\Windows\SysWOW64\User32.dll [2010-11-21 05:24] - [2013-11-15 22:28] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-03-19 04:53 ==================== End of FRST.txt ============================ Addition.txt
  12. Здравейте, Много моля за съдействие от няколко дена прехванах някакъв вирус в browsera safe finder, прецака ми се търсачката, отварям табове по 5-6-7 пъти, докато ми отвори, това което искам. Опитах се да изтрия програмата от control panel (изтрих я), но без никакъв успех, преинсталирах Mozilla (това ми е браузъра по подразбиране) и отново никакъв ефект. Много моля за вашето съдействие. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 Ran by Stefan (administrator) on STEFAN-PC (20-03-2016 19:37:10) Running from C:\Users\Stefan\Downloads Loaded Profiles: Stefan & postgres (Available Profiles: Stefan & postgres) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Английски (Съединени щати) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe () C:\Program Files\BitTorrent\BitTorrent.exe (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\ProgramData\CloudPrinter\CloudPrinter.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe () C:\ProgramData\KMSAuto\KMSES.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\pg_ctl.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe (MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Windows\Installer\{3F34C515-AD21-CC86-6996-BAB248A3AE93}\syshost.exe (Microsoft Corporation) C:\Windows\SysWOW64\netsh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Just Develop It) C:\Program Files (x86)\MyPC Backup\BackupStack.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe () C:\ProgramData\afoir\afoir.exe (Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe (PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Windows\System32\slui.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [178960 2012-03-15] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-25] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation) HKLM-x32\...\Run: [MobileConnect] => %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [592704 2015-09-29] (Razer Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation) HKLM-x32\...\Run: [syshost32] => C:\Windows\Installer\{3F34C515-AD21-CC86-6996-BAB248A3AE93}\syshost.exe Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [1337573597] => C:\ProgramData\msvddgr.exe [73427712 2010-11-21] () HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [uTorrent] => C:\Users\Stefan\AppData\Roaming\uTorrent\uTorrent.exe [2094080 2016-03-06] (BitTorrent Inc.) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-04] (Valve Corporation) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [{B64A3306-E5BC-4C45-8075-ABDC901C1837}] => powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\NcMrJwyXG').YFEXBDTAUQEL))); HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [909696 2010-12-21] (Microsoft Corporation) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50676864 2016-03-01] (Skype Technologies S.A.) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\Run: [Voobly] => C:\Program Files (x86)\Voobly\voobly.exe [159744 2016-02-23] (Voobly) HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {2bf66421-9032-11e5-8ebf-606c665b70ec} - F:\SETUP.EXE HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {2bf66425-9032-11e5-8ebf-606c665b70ec} - H:\SETUP.EXE HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {4acbd087-3947-11e5-8ca3-606c665b70ec} - F:\setup.exe HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\...\MountPoints2: {d69c4c94-9983-11e5-94d3-606c665b70ec} - F:\aocsetup.exe /autorun HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation) AppInit_DLLs: C:\ProgramData\afoir\Zoomhold.dll => C:\ProgramData\afoir\Zoomhold.dll [363520 2016-03-13] () AppInit_DLLs-x32: C:\ProgramData\afoir\Bioozekix.dll => C:\ProgramData\afoir\Bioozekix.dll [257536 2016-03-13] () Startup: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2014-07-16] ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{61418247-B566-47D0-BE75-6F77C03F365B}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLF0dPujPrN1bYvhG3ajvv2yu3GBQ7I4Yc17Hp2rRIy_2djBa5nUcY-CyiWCvtnEOeV_w40Ml0AZTEUJLD9Zqxx2A5hl_bUA, HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLF0dPujPrN1bYvhG3ajvv2yu3GBQ7I4Yc17Hp2rRIy_2djBa5nUcY-CyiWCvtnEOeV_w40Ml0AZTEUJLD9Zqxx2A5hl_bUA, HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} HKU\S-1-5-21-2911250186-2008469882-1143044474-1004\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} URLSearchHook: HKLM-x32 -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-353&apn_uid=9752226053614134&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2911250186-2008469882-1143044474-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2911250186-2008469882-1143044474-1004 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2911250186-2008469882-1143044474-1004 -> {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaGWBzMpXPRmi4hopKfidXZkRv6blzxu94dGhq3Nl1hoQey-SRZn8F_--75UmsrikyazbHGGJNMOOLFH6byIrfFjs24F_OfewHZm6KxoeSQaVIzRApUJLXXdm6TKM6NVoVf0mxbRTyADxqSHqoKHtrjRllu4XXVCLun_uQ_5OGI0,&q={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2012-08-16] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: AtuZi -> {65daaf6f-90ac-49a4-9b47-d353c427367a} -> C:\Program Files (x86)\AtuZi\AtuZibho.dll [2014-06-30] (AtuZi) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-24] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-24] (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\n61u4qmb.default-1458467973018 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-11] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-11] () FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-24] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-24] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-20] [not signed] Chrome: ======= CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1405030083&from=amt&uid=HGSTXHTS541010A9E680_JD1000191D7WLN1D7WLNX" CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Wallet) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-19] CHR HKLM-x32\...\Chrome\Extension: [fcgnigmofekcllgbiejhmigggmgehkip] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 afoir; C:\ProgramData\\afoir\\afoir.exe [529408 2016-03-13] () [File not signed] R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53320 2014-11-13] (Just Develop It) <==== ATTENTION R2 BitTorrent; C:\Program Files\BitTorrent\BitTorrent.exe [383488 2016-03-13] () [File not signed] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [761856 2016-03-13] () [File not signed] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation) R2 KMSEmulator; C:\ProgramData\KMSAuto\KMSES.exe [249344 2013-11-16] () [File not signed] S2 KMSServerService; D:\Торенти\KMSAuto Easy 1.06.V6 (Activator For Windows 7,8,8.1 and Office 1\KMSServerService.exe [260608 2013-11-16] (My Digital Life Forums) [File not signed] S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation) S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation) R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2016-03-16] (Pandora.TV) R2 postgresql-x64-9.0; C:\Program Files\PostgreSQL\9.0\bin\pg_ctl.exe [111104 2012-09-21] (PostgreSQL Global Development Group) [File not signed] S2 pyodqctprodlct; C:\Users\Stefan\AppData\Local\Konkstrip.exe [28160 2016-03-13] () [File not signed] R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] () S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1042304 2016-03-20] (Enigma Software Group USA, LLC.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH) S2 TunMirror; D:\Торенти\KMSAuto Easy 1.06.V6 (Activator For Windows 7,8,8.1 and Office 1\TunMirror.exe [10752 2013-11-16] () [File not signed] R2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S1 20354967; C:\Windows\system32\drivers\20354967.sys [92120 2016-01-06] () [File not signed] S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-08-08] (Disc Soft Ltd) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-12-18] (DT Soft Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-03-20] () S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation) R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [50392 2015-08-13] (Razer Inc) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129472 2015-06-27] (Razer, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381608 2015-08-08] (Duplex Secure Ltd.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-20 19:37 - 2016-03-20 19:37 - 00025848 _____ C:\Users\Stefan\Downloads\FRST.txt 2016-03-20 19:37 - 2016-03-20 19:37 - 00000000 ____D C:\FRST 2016-03-20 19:36 - 2016-03-20 19:36 - 02374144 _____ (Farbar) C:\Users\Stefan\Downloads\FRST64.exe 2016-03-20 11:59 - 2016-03-20 11:59 - 00000000 ____D C:\Users\Stefan\Desktop\Стари данни Firefox 2016-03-20 11:35 - 2016-03-20 11:35 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Stefan\Downloads\SpyHunter-Installer.exe 2016-03-20 11:07 - 2016-03-20 11:07 - 00000000 _____ C:\autoexec.bat 2016-03-20 11:06 - 2016-03-20 11:06 - 00003332 _____ C:\Windows\System32\Tasks\SpyHunter4Startup 2016-03-20 11:06 - 2016-03-20 11:06 - 00001087 _____ C:\Users\Stefan\Desktop\SpyHunter.lnk 2016-03-20 11:06 - 2016-03-20 11:06 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2016-03-20 11:06 - 2016-03-20 11:06 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Enigma Software Group 2016-03-20 11:06 - 2016-03-20 11:06 - 00000000 ____D C:\sh4ldr 2016-03-20 11:05 - 2016-03-20 11:05 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Stefan\Desktop\SpyHunter-Installer.exe 2016-03-20 11:05 - 2016-03-20 11:05 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys 2016-03-20 11:05 - 2016-03-20 11:05 - 00000000 ____D C:\Program Files\Enigma Software Group 2016-03-20 01:16 - 2016-03-20 10:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-03-14 18:16 - 2016-03-14 18:16 - 00003248 _____ C:\Windows\System32\Tasks\psv_Zaamtom 2016-03-14 18:15 - 2016-03-14 18:15 - 00003262 _____ C:\Windows\System32\Tasks\psv_TresQuoeco 2016-03-14 17:49 - 2016-03-14 17:49 - 00003234 _____ C:\Windows\System32\Tasks\producadoo 2016-03-14 06:14 - 2016-03-14 06:14 - 00003388 _____ C:\Windows\System32\Tasks\o3zplhly 2016-03-14 06:14 - 2016-03-14 06:14 - 00000000 ____D C:\Program Files\Common Files\pmk10zge 2016-03-14 05:14 - 2016-03-14 05:14 - 00003388 _____ C:\Windows\System32\Tasks\cnt5j0b3 2016-03-14 05:14 - 2016-03-14 05:14 - 00000000 ____D C:\Program Files\Common Files\m2pxazue 2016-03-14 04:14 - 2016-03-14 04:14 - 00003388 _____ C:\Windows\System32\Tasks\drf40eed 2016-03-14 04:14 - 2016-03-14 04:14 - 00000000 ____D C:\Program Files\Common Files\zivb3dwl 2016-03-14 03:14 - 2016-03-14 03:14 - 00003388 _____ C:\Windows\System32\Tasks\jaancasl 2016-03-14 03:14 - 2016-03-14 03:14 - 00000000 ____D C:\Program Files\Common Files\hykbkrt4 2016-03-14 02:14 - 2016-03-14 02:14 - 00003388 _____ C:\Windows\System32\Tasks\shypmcwx 2016-03-14 02:14 - 2016-03-14 02:14 - 00000000 ____D C:\Program Files\Common Files\dchpkqot 2016-03-14 01:14 - 2016-03-14 01:14 - 00003388 _____ C:\Windows\System32\Tasks\0ksidqpu 2016-03-14 01:14 - 2016-03-14 01:14 - 00000000 ____D C:\Program Files\Common Files\y1315233 2016-03-14 00:14 - 2016-03-14 00:14 - 00003388 _____ C:\Windows\System32\Tasks\z253j3j1 2016-03-14 00:14 - 2016-03-14 00:14 - 00000000 ____D C:\Program Files\Common Files\wr1evdgk 2016-03-13 23:14 - 2016-03-19 23:43 - 00000000 ____D C:\ProgramData\afoir 2016-03-13 23:14 - 2016-03-13 23:14 - 00003388 _____ C:\Windows\System32\Tasks\lruw24vh 2016-03-13 23:14 - 2016-03-13 23:14 - 00000000 ____D C:\ProgramData\afoirs 2016-03-13 23:14 - 2016-03-13 23:14 - 00000000 ____D C:\Program Files\Common Files\blo2ut03 2016-03-13 22:14 - 2016-03-13 22:14 - 00003388 _____ C:\Windows\System32\Tasks\zw5cgoyc 2016-03-13 22:14 - 2016-03-13 22:14 - 00000000 ____D C:\Program Files\Common Files\ea3ostxi 2016-03-13 21:14 - 2016-03-13 21:14 - 00003388 _____ C:\Windows\System32\Tasks\i0w24las 2016-03-13 21:14 - 2016-03-13 21:14 - 00000000 ____D C:\Program Files\Common Files\3nkjdsje 2016-03-13 20:15 - 2016-03-13 20:15 - 00001734 _____ C:\Users\Stefan\Desktop\Counter-Strike WaRzOnE.lnk 2016-03-13 20:14 - 2016-03-13 23:14 - 00000000 ____D C:\Program Files\BitTorrent 2016-03-13 20:13 - 2016-03-19 23:43 - 00002394 _____ C:\Windows\SysWOW64\findit.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 07600640 _____ C:\Users\Stefan\AppData\Roaming\agent.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 01787264 _____ C:\Users\Stefan\AppData\Roaming\ViaNimphase.tst 2016-03-13 20:13 - 2016-03-13 20:13 - 00848437 _____ C:\Users\Stefan\AppData\Roaming\Nimtom.bin 2016-03-13 20:13 - 2016-03-13 20:13 - 00189695 _____ () C:\Users\Stefan\AppData\Roaming\Sanla.bin 2016-03-13 20:13 - 2016-03-13 20:13 - 00126464 _____ C:\Users\Stefan\AppData\Roaming\noah.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00126464 _____ C:\Users\Stefan\AppData\Roaming\lobby.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00072714 _____ C:\Users\Stefan\AppData\Roaming\Domlam.tst 2016-03-13 20:13 - 2016-03-13 20:13 - 00065040 _____ C:\Users\Stefan\AppData\Roaming\Config.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 00054272 _____ C:\Users\Stefan\AppData\Roaming\ApplicationHosting.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00041472 _____ C:\Users\Stefan\AppData\Local\Konkstrip.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00028160 _____ C:\Users\Stefan\AppData\Local\Konkstrip.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 00018432 _____ C:\Users\Stefan\AppData\Roaming\Main.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 00005568 _____ C:\Users\Stefan\AppData\Roaming\md.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 00000187 _____ C:\Users\Stefan\AppData\Local\Konkstrip.exe.config 2016-03-13 20:13 - 2016-03-13 20:13 - 00000000 ____D C:\ProgramData\Ronzaps 2016-03-13 20:13 - 2016-03-13 20:13 - 00000000 ____D C:\ProgramData\CloudPrinter 2016-03-13 20:13 - 2016-03-13 20:12 - 00761856 _____ C:\Users\Stefan\AppData\Roaming\ViaNimphase.exe 2016-03-13 20:13 - 2016-03-13 20:12 - 00761856 _____ C:\Users\Stefan\AppData\Roaming\Domlam.exe 2016-03-13 20:12 - 2016-03-13 20:13 - 00016992 _____ C:\Users\Stefan\AppData\Roaming\InstallationConfiguration.xml 2016-03-13 20:12 - 2016-03-13 20:12 - 00127488 _____ C:\Users\Stefan\AppData\Roaming\Installer.dat 2016-03-13 20:00 - 2016-03-13 20:00 - 00001948 _____ C:\Users\postgres\Desktop\Counter Strike 1.6 Non Steam.lnk 2016-03-13 20:00 - 2016-03-13 20:00 - 00001928 _____ C:\Users\postgres\Desktop\Dedicated Server.lnk 2016-03-13 19:59 - 2016-03-13 20:00 - 00000000 ____D C:\Program Files (x86)\Valve 2016-03-13 00:24 - 2016-03-13 00:24 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\NVIDIA 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HLDS 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Half-Life 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 2016-03-13 00:23 - 2016-03-13 00:23 - 00000000 ____D C:\Games 2016-03-12 01:22 - 2013-01-27 18:32 - 00066331 _____ C:\Program Files (x86)\EULA.eng 2016-03-12 01:19 - 2016-03-12 01:19 - 00002033 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\888poker.lnk 2016-03-12 01:19 - 2016-03-12 01:19 - 00002009 _____ C:\Users\postgres\Desktop\888poker.lnk 2016-03-12 01:19 - 2016-03-12 01:19 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\PacificPoker 2016-03-12 01:19 - 2016-03-12 01:19 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\888poker 2016-03-12 01:19 - 2016-03-12 01:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\888poker 2016-03-12 01:18 - 2016-03-12 01:18 - 00000000 ____D C:\Program Files (x86)\888poker.net 2016-03-12 01:14 - 2016-03-12 01:23 - 00000000 ____D C:\Program Files (x86)\PacificPoker 2016-03-12 01:11 - 2016-03-12 01:26 - 00000000 ____D C:\Users\Stefan\Documents\888poker 2016-03-11 10:36 - 2016-03-20 12:12 - 00000000 ____D C:\Users\Stefan\AppData\Local\CrashDumps 2016-03-11 01:13 - 2016-03-14 18:13 - 00000000 ____D C:\Windows\SysWOW64\NV 2016-03-11 01:13 - 2016-03-14 18:13 - 00000000 ____D C:\Windows\system32\NV 2016-03-11 01:11 - 2016-03-08 12:07 - 42968120 _____ C:\Windows\system32\nvcompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 37609528 _____ C:\Windows\SysWOW64\nvcompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 22932928 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 21313024 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 20854680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 18990976 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 18879544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 17725040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 17318184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 17246680 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 16439328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 12564024 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-03-11 01:11 - 2016-03-08 12:07 - 10546944 _____ C:\Windows\system32\nvptxJitCompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 08658120 _____ C:\Windows\SysWOW64\nvptxJitCompiler.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 03233336 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 02808768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 01924152 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436451.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 01571776 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436451.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00956984 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00886840 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00749504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00693816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00678520 _____ C:\Windows\system32\nvfatbinaryLoader.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00571912 _____ C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00473056 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00151368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2016-03-11 01:11 - 2016-03-08 12:07 - 00039992 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2016-03-11 01:11 - 2016-03-08 12:07 - 00000139 _____ C:\Windows\SysWOW64\nv-vk32.json 2016-03-11 01:11 - 2016-03-08 12:07 - 00000139 _____ C:\Windows\system32\nv-vk64.json 2016-03-08 22:52 - 2016-03-08 22:55 - 00000000 ____D C:\Program Files (x86)\PKR 2016-03-08 22:52 - 2016-03-08 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PKR 2016-03-08 21:37 - 2016-03-08 21:38 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-03-08 21:37 - 2016-03-08 21:37 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-03-08 21:30 - 2015-12-18 08:11 - 00047760 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-03-08 21:30 - 2015-12-18 08:10 - 00099472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2016-03-08 21:30 - 2015-12-18 08:10 - 00090768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 14128496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 00391632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 00175552 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2016-03-08 21:27 - 2016-03-08 12:07 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2016-03-08 21:27 - 2016-02-24 01:58 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436200.dll 2016-03-08 21:27 - 2016-02-24 01:58 - 01571776 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436200.dll 2016-03-08 21:20 - 2016-02-17 08:40 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2016-03-08 21:20 - 2016-02-17 08:40 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2016-03-08 21:20 - 2016-02-17 08:40 - 00112216 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2016-03-08 21:19 - 2016-03-11 01:14 - 00000000 ____D C:\ProgramData\Package Cache 2016-02-25 13:03 - 2016-02-25 13:03 - 00001654 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk 2016-02-25 13:03 - 2016-02-25 13:03 - 00001642 _____ C:\Users\Public\Desktop\Poker at bet365.lnk 2016-02-25 13:02 - 2016-03-02 15:00 - 00000000 ____D C:\Program Files (x86)\Poker at bet365 2016-02-19 05:49 - 2016-02-19 05:49 - 00001078 _____ C:\Users\postgres\Desktop\PokerTracker 4.lnk 2016-02-19 05:49 - 2016-02-19 05:49 - 00000016 _____ C:\ProgramData\mntemp ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-20 19:36 - 2013-11-17 14:38 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Skype 2016-03-20 19:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-03-20 19:33 - 2013-11-16 00:20 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-03-20 19:32 - 2013-11-16 00:20 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-03-20 19:32 - 2009-07-14 06:45 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-03-20 19:32 - 2009-07-14 06:45 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-03-20 12:12 - 2013-11-16 00:30 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\uTorrent 2016-03-20 10:59 - 2015-12-20 21:31 - 00000000 ____D C:\Program Files (x86)\Voobly 2016-03-20 10:51 - 2013-11-17 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-03-20 10:43 - 2013-11-17 15:11 - 00000000 ____D C:\Program Files (x86)\The KMPlayer 2016-03-20 02:38 - 2015-07-19 19:50 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-03-19 23:58 - 2013-11-16 00:20 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-03-19 23:43 - 2013-11-17 14:34 - 00001169 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-03-19 23:43 - 2013-11-17 14:34 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-03-19 23:43 - 2013-11-16 01:44 - 00002294 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-19 23:43 - 2013-11-15 22:30 - 00001405 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-03-18 00:57 - 2014-06-11 20:53 - 00003864 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1384553415 2016-03-18 00:57 - 2013-11-16 00:10 - 00000000 ____D C:\Program Files (x86)\Opera 2016-03-17 07:44 - 2013-11-17 14:38 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-03-17 07:44 - 2013-11-17 14:37 - 00000000 ____D C:\ProgramData\Skype 2016-03-14 23:32 - 2015-09-13 18:49 - 00000000 ____D C:\Program Files (x86)\Steam 2016-03-14 18:19 - 2009-07-14 07:13 - 00782882 _____ C:\Windows\system32\PerfStringBackup.INI 2016-03-14 18:13 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-03-14 17:49 - 2014-11-09 23:30 - 00003254 _____ C:\Windows\System32\Tasks\PC Speed Maximizer Schedule 2016-03-13 22:20 - 2015-11-10 23:51 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk 2016-03-13 22:20 - 2015-11-10 23:51 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk 2016-03-13 22:20 - 2013-11-22 21:42 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-03-13 21:12 - 2014-02-13 15:04 - 00000000 ____D C:\Users\Stefan\AppData\Local\PokerTracker 4 2016-03-13 21:12 - 2014-02-13 15:04 - 00000000 ____D C:\Program Files (x86)\PokerTracker 4 2016-03-13 19:59 - 2013-11-16 00:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-12 01:19 - 2015-12-18 23:04 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2016-03-11 18:16 - 2015-07-19 19:50 - 00003890 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-03-11 18:16 - 2013-11-16 00:20 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-03-11 18:16 - 2013-11-16 00:20 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-11 18:16 - 2013-11-16 00:20 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-03-11 01:12 - 2013-11-15 23:24 - 00000000 ____D C:\ProgramData\NVIDIA 2016-03-08 21:38 - 2015-01-29 19:56 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-03-08 21:37 - 2013-11-16 00:50 - 00000000 ____D C:\ProgramData\Adobe 2016-03-08 21:31 - 2013-11-26 20:42 - 00000000 ____D C:\Users\Stefan\AppData\Local\NVIDIA Corporation 2016-03-08 21:31 - 2013-11-26 20:40 - 00000000 ____D C:\Users\Stefan\AppData\Local\NVIDIA 2016-03-08 21:31 - 2013-11-15 23:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-03-08 21:29 - 2013-11-15 23:23 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-03-08 21:28 - 2013-11-15 23:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-03-08 12:07 - 2013-11-17 14:37 - 03283896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2016-03-08 12:07 - 2013-04-08 13:32 - 03711024 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2016-03-08 12:07 - 2013-04-08 13:32 - 00036743 _____ C:\Windows\system32\nvinfo.pb 2016-03-08 08:27 - 2013-11-15 23:24 - 06369728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 02994232 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 02561472 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 01264064 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2016-03-08 08:27 - 2013-11-15 23:24 - 00532536 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2016-03-08 08:27 - 2013-11-15 23:24 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2016-03-07 06:23 - 2013-11-15 23:24 - 06203411 _____ C:\Windows\system32\nvcoproc.bin 2016-03-06 15:09 - 2015-04-10 14:30 - 00000000 ____D C:\Users\Stefan\AppData\Local\Steam 2016-03-04 01:11 - 2013-11-16 01:06 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite 2016-03-04 01:09 - 2014-01-23 21:16 - 00000000 ____D C:\Windows\Minidump 2016-03-03 03:21 - 2013-11-22 21:52 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\TeamViewer 2016-03-02 21:08 - 2015-07-17 09:03 - 00003414 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily 2016-03-02 21:08 - 2015-07-17 09:03 - 00003288 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine 2016-03-02 21:08 - 2015-07-17 09:03 - 00000000 ____D C:\Program Files (x86)\Gyazo 2016-03-02 14:53 - 2015-06-26 19:36 - 00000000 ____D C:\Rua Gaming 2016-02-26 09:21 - 2015-12-20 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voobly 2016-02-24 01:58 - 2013-11-15 23:08 - 00215608 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL 2016-02-24 01:58 - 2013-11-15 23:08 - 00201664 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL 2016-02-19 05:50 - 2015-11-03 03:42 - 00000000 ____D C:\Users\Stefan\AppData\Local\PokerStars.BG 2016-02-19 05:50 - 2014-09-26 22:46 - 00000000 ____D C:\Program Files (x86)\PokerStars.BG 2016-02-19 05:50 - 2013-11-17 15:06 - 00000000 ____D C:\Program Files (x86)\PokerStars ==================== Files in the root of some directories ======= 2016-03-12 01:22 - 2013-01-27 18:32 - 0066331 _____ () C:\Program Files (x86)\EULA.eng 2013-11-16 01:50 - 2013-11-16 01:51 - 8138498 _____ () C:\Program Files (x86)\saplatform.com_12Beta1.zip 2016-03-13 20:13 - 2016-03-13 20:13 - 7600640 _____ () C:\Users\Stefan\AppData\Roaming\agent.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0054272 _____ () C:\Users\Stefan\AppData\Roaming\ApplicationHosting.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0065040 _____ () C:\Users\Stefan\AppData\Roaming\Config.xml 2016-03-13 20:13 - 2016-03-13 20:12 - 0761856 _____ () C:\Users\Stefan\AppData\Roaming\Domlam.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 0072714 _____ () C:\Users\Stefan\AppData\Roaming\Domlam.tst 2016-03-13 20:12 - 2016-03-13 20:13 - 0016992 _____ () C:\Users\Stefan\AppData\Roaming\InstallationConfiguration.xml 2016-03-13 20:12 - 2016-03-13 20:12 - 0127488 _____ () C:\Users\Stefan\AppData\Roaming\Installer.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0126464 _____ () C:\Users\Stefan\AppData\Roaming\lobby.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0018432 _____ () C:\Users\Stefan\AppData\Roaming\Main.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0005568 _____ () C:\Users\Stefan\AppData\Roaming\md.xml 2016-03-13 20:13 - 2016-03-13 20:13 - 0848437 _____ () C:\Users\Stefan\AppData\Roaming\Nimtom.bin 2016-03-13 20:13 - 2016-03-13 20:13 - 0126464 _____ () C:\Users\Stefan\AppData\Roaming\noah.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0189695 _____ () C:\Users\Stefan\AppData\Roaming\Sanla.bin 2016-03-13 20:14 - 2016-03-13 20:14 - 0001150 _____ () C:\Users\Stefan\AppData\Roaming\uninstall_temp.ico 2016-03-13 20:13 - 2016-03-13 20:12 - 0761856 _____ () C:\Users\Stefan\AppData\Roaming\ViaNimphase.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 1787264 _____ () C:\Users\Stefan\AppData\Roaming\ViaNimphase.tst 2016-03-13 20:13 - 2016-03-13 20:13 - 0041472 _____ () C:\Users\Stefan\AppData\Local\Konkstrip.dat 2016-03-13 20:13 - 2016-03-13 20:13 - 0028160 _____ () C:\Users\Stefan\AppData\Local\Konkstrip.exe 2016-03-13 20:13 - 2016-03-13 20:13 - 0000187 _____ () C:\Users\Stefan\AppData\Local\Konkstrip.exe.config 2008-05-23 16:48 - 2008-05-23 16:48 - 0020270 _____ () C:\ProgramData\DeviceInstaller.xml 2008-06-23 12:02 - 2008-06-23 12:02 - 0097410 ____R () C:\ProgramData\DeviceManager.xml.rc4 2014-02-13 15:04 - 2014-02-13 15:04 - 0004900 _____ () C:\ProgramData\flwjycbm.bab 2016-02-19 05:49 - 2016-02-19 05:49 - 0000016 _____ () C:\ProgramData\mntemp 2010-11-21 05:24 - 2010-11-21 05:24 - 73427712 ___SH () C:\ProgramData\msvddgr.exe Files to move or delete: ==================== C:\ProgramData\msvddgr.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll [2010-11-21 05:24] - [2013-11-15 22:28] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79 C:\Windows\SysWOW64\User32.dll [2010-11-21 05:24] - [2013-11-15 22:28] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-03-19 04:53 ==================== End of FRST.txt ============================ Addition.txt
  13. Проблем с процесора

    Вие сте най-добрите! Благодаря за положеното усилие и разрешаването на проблема! Искам да изразя сърдечни благодарности към вас и ви желая да бъдете живи, здрави и щастливи! Възхищавам се на желанието, скоростта и разбирането, с което работите. Най-добрия български сайт за софтуер и хардуер!!!
  14. Проблем с процесора

    Междудругото няма и следа от прегряванията на процесора. Макар и с нов никнейм, за пореден път се уверявам, че сте сайт номер 1 в борбата с всякакви компютърни проблеми!! Fixlog.txt Fixlog.txt
  15. Проблем с процесора

    HitmanPro 3.7.9.220www.hitmanpro.com Computer name . . . . : STEFAN-PC Windows . . . . . . . : 6.1.1.7601.X64/8 User name . . . . . . : Stefan-PCStefan UAC . . . . . . . . . : Disabled License . . . . . . . : Free Scan date . . . . . . : 2014-07-14 00:58:51 Scan mode . . . . . . : Normal Scan duration . . . . : 3m 32s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 3 Traces . . . . . . . : 42 Objects scanned . . . : 1 268 681 Files scanned . . . . : 15 575 Remnants scanned . . : 368 756 files / 884 350 keysMalware _____________________________________________________________________ C:WindowsSysWOW64hfnapi.dll Size . . . . . . . : 108 544 bytes Age . . . . . . . : 3.0 days (2014-07-11 01:07:39) Entropy . . . . . : 6.4 SHA-256 . . . . . : 73D818F4F48DE93E70273E76729450BB5CBB470B5D9C2EE0CEF5ADF0242D4BAB Product . . . . . : NetFilterSDK LanguageID . . . . : 0 > Bitdefender . . . : Adware.SwiftBrowse.AJ > Kaspersky . . . . : Trojan-Downloader.Win32.Agent.heqj Fuzzy . . . . . . : 110.0 C:WindowsTempcrpt.exe Size . . . . . . . : 144 384 bytes Age . . . . . . . : 0.4 days (2014-07-13 15:39:49) Entropy . . . . . : 6.8 SHA-256 . . . . . : DE7422D9D0E457824DDB68B0405586674EA5FF995746E9677425B0DB3984608C > Kaspersky . . . . : not-a-virus:RiskTool.Win32.Crypter.hp Fuzzy . . . . . . : 108.0 Forensic Cluster -15.2s C:WindowsTemp~BF89.tmp -0.0s C:WindowsTempcstart.bat -0.0s C:WindowsTemplibcurl-4.dll -0.0s C:WindowsTemppthreadGC2-w64.dll 0.0s C:WindowsTempcrpt.exe 2.8s C:FRSTQuarantineCWindowsTempdgen.exe.xBAD 5.2s C:WindowsTempl.txt 5.3s C:WindowsTempl1.txtSuspicious files ____________________________________________________________ C:UsersStefanDesktopНова папкаFRST64.exe Size . . . . . . . : 2 086 912 bytes Age . . . . . . . : 0.4 days (2014-07-13 16:25:03) Entropy . . . . . : 7.5 SHA-256 . . . . . : 31E1132CC59020B164493C5EFB31C2BFFC4A3599CFAFB29CAACD5D43B4302A19 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. C:UsersStefanDownloadsFRST64(1).exe Size . . . . . . . : 2 086 912 bytes Age . . . . . . . : 0.3 days (2014-07-13 17:42:02) Entropy . . . . . : 7.5 SHA-256 . . . . . : 31E1132CC59020B164493C5EFB31C2BFFC4A3599CFAFB29CAACD5D43B4302A19 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -8.8s C:UsersStefanAppDataLocalMicrosoftWindowsWERReportArchiveAppHang_FRST64.exe_a6e163adaaf3491f1595787f5698a1d3f9d0233e_1a62a13d -8.8s C:UsersStefanAppDataLocalMicrosoftWindowsWERReportArchiveAppHang_FRST64.exe_a6e163adaaf3491f1595787f5698a1d3f9d0233e_1a62a13dReport.wer -6.0s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache9BA -6.0s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache9BAB33BEd01 -5.9s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache4B9 -5.9s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache4B96D5E7d01 -5.8s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache11D -5.8s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache11D04684d01 -5.6s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheD55 -5.6s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheD55914F1d01 -3.7s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheCC0 -3.7s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheCC0FA5DEd01 0.0s C:UsersStefanDownloadsFRST64(1).exe C:UsersStefanDownloadsFRST64.exe Size . . . . . . . : 2 086 912 bytes Age . . . . . . . : 0.3 days (2014-07-13 17:40:48) Entropy . . . . . : 7.5 SHA-256 . . . . . : 31E1132CC59020B164493C5EFB31C2BFFC4A3599CFAFB29CAACD5D43B4302A19 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -15.5s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache44F -15.5s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache44FB3F40d01 -15.2s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache590 -15.2s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache590164FFd01 -15.0s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache749 -15.0s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache74991AEEd01 -14.8s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache30C -14.8s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache30C523EDd01 -14.5s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache5DA -14.5s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache5DA8CAC1d01 -14.4s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache4AF -14.4s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache4AF36F32d01 -14.4s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheC5A -14.4s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheC5A35AF6d01 -13.8s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheD17 -13.8s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheD17EE627d01 -13.7s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheF74 -13.7s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheF74409CFd01 -13.6s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheD01 -13.6s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCacheD011AA1Dd01 -3.7s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache18A -3.7s C:UsersStefanAppDataLocalMozillaFirefoxProfilesrrqcf72a.defaultCache18AEFD54d01 0.0s C:UsersStefanDownloadsFRST64.exeMalware remnants ____________________________________________________________ HKLMSOFTWAREClassesInterface{EFC32678-546B-4367-8B25-B40BF45CC1A3} (BuenoSearch)Potential Unwanted Programs _________________________________________________ HKLMSOFTWAREMicrosoftInternet ExplorerSearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} (AskBar) HKLMSYSTEMControlSet001EnumRootLEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622 (Linkey) HKLMSYSTEMControlSet002EnumRootLEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622 (Linkey) HKLMSYSTEMCurrentControlSetEnumRootLEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622 (Linkey) HKUS-1-5-21-2911250186-2008469882-1143044474-1000SoftwareMicrosoftInternet ExplorerApproved Extensions{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} (iLivid) HKUS-1-5-21-2911250186-2008469882-1143044474-1001SoftwareConduit (Conduit)Cookies _____________________________________________________________________ C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ad.360yield.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.ad4game.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.creative-serving.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.displayincloud.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.kaldata.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.mediade.sk C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.p161.net C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.pubmatic.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ads.yahoo.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:adserver.abv.bg C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:adtech.de C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:adtechus.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:advertising.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:at.atwola.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:atdmt.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:burstnet.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:casalemedia.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:diff3.smartadserver.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:doubleclick.net C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:in.getclicky.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:media6degrees.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:premiumtv.122.2o7.net C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:revsci.net C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:ru4.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:serving-sys.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:smartadserver.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:track.adform.net C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:tribalfusion.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:www.googleadservices.com C:UsersStefanAppDataRoamingMozillaFirefoxProfilesrrqcf72a.defaultcookies.sqlite:yadro.ru
  • Разглеждащи в момента   0 потребители

    Няма регистрирани потребители разглеждащи тази страница.

×

Информация

Поставихме бисквитки на устройството ви за най-добро потребителско изживяване. Можете да промените настройките си за бисквитки, или в противен случай приемаме, че сте съгласни с нашите условия за ползване.