Премини към съдържанието

Филтри за търсене

Показани резултати за тагове 'Решен'.

  • Търсене по таг

    Въведете тагове разделени със запетая
  • Търсене по автор

Търсене в


Форуми

  • Софтуер
    • Нови Програми
    • Търсене на Програми
    • Програми - Проблеми и Дискусии
    • Драйвери - Търсене, Проблеми, Линкове
    • Операционни системи
    • Сигурност и антивирусна защита
    • Игри
  • Хардуер
    • Общи хардуерни въпроси
    • Преносими компютри
    • Дънни платки
    • Запаметяващи устройства и памети
    • Монитори, Аудио и Видеокарти
    • Периферия
    • Овърклок и PC модинг
    • Нови конфигурации и части, въпроси, препоръки и мнения
  • Мобилни телефони, GSM, Мобилни приложения, Комуникации
    • Мобилни телефони - Въпроси, Проблеми, Софтуер
    • Съвети при избор на телефон
    • Мобилни Приложения (Apps)
    • Мобилни оператори, Мрежи, Промоции, Абонаменти, Услуги
    • Други теми относно мобилни телефони
  • Уеб дизайн, Графичен дизайн, Програмиране
    • Програмиране
    • Графичен Дизайн и Визуални изкуства
    • CMS, Форумни и Торент системи
    • Хостинг, Домейни, Уеб сървъри
    • SEO, Уеб оптимизация и стандарти
  • Битова Техника
    • Аудиотехника
    • Телевизори, Видео и Фото техника, Видео наблюдение
    • Климатици - проблеми, съвети, въпроси
    • Бойлери, Печки, Отопление
    • Друга битова техника
  • Интернет, Локални Мрежи и GPS Навигации
    • Интернет, WiFi, xDSL и Локална Мрежа
    • Биткойн и Криптовалути
    • Онлайн бизнес, AdSense, Affilate програми
    • Рутери, Модеми, Суичове
    • Facebook - проблеми, въпроси, вируси
    • Skype, VoIP - Интернет телефония
    • GPS, Навигационни системи - Въпроси, Карти, Проблеми
  • Изкуство
    • Музика
    • Кино и Телевизия
    • Поезия и Лично творчество
    • Изкуство - Изящно, Приложно и Сценично
    • Фотография и Фотографска техника
    • Литература, Книги (e-books, video trainings, tutorials & etc.)
  • Други
    • Статии и ревюта
    • Образование и обща култура
    • Религия, Мистика, Езотерика
    • История
    • Философия
    • Психология и Психотерапия
    • Новини от България и Света
    • Българите по света
    • Политика
    • Право и Юридически консултации
    • Здраве и Mедицина
    • Банки, Застраховане, Финанси, Кредити
    • Тийн Зона (Teen Zone)
    • Купувам / Продавам
    • Всичко останало
  • Хоби, Развлечение и Свободно време
  • За kaldata.com
  • Теми
  • Photoshop майнаци Теми
  • python3 data types
  • какви са ви любимите игри?? Темиигри за вас
  • супрески игри и рекорди Темиигри за вас

Блогове

Няма резултати

Няма резултати

Категории

  • Компютри
    • Компютърни конфигурации
    • Компютърни компоненти
    • Периферни устройства
    • Дънни платки
    • Мултимедия
    • Компютърни игри и софтуер
    • Администриране и интернет услуги
    • Компютърни аксесоари
    • Лаптопи и таблети
    • Видеокарти
    • Монитори
    • Процесори
    • Хард дискове и Памети
    • Други
  • Електроника
    • Телефони, GSM апарати
    • Аудио
    • Битова електроника
    • GPS и навигационни системи
    • Фотоапарати и обективи
    • TV и Видео
    • Други
  • Имоти
    • Гарсониери
    • Къщи и вили
    • Търговски площи
    • Гаражи
    • Апартаменти
    • Терени
    • Офиси
    • Други имоти в продажба
  • Авто-мото
    • Автомобили
    • Велосипеди
    • Лодки
    • Резервни части
    • Авто аксесоари
    • Мотоциклети
    • Скутери и ATV
    • Камиони и Автобуси
    • Авто сервизи и Rent-a-Car
    • Други
  • Работа
    • Работа в страната
    • Работа в чужбина
    • Стажове
    • Работа от вкъщи
    • Непълно работно време
  • Услуги
  • Строителство
  • Туризъм
  • Курсове и обучение
  • Домашни любимци
  • Други
  • супрески игри и рекорди Обяви
  • супрески игри и рекорди Обяви

Категории

  • Домашни любимци и Животни
  • Игри
  • Инциденти и Екстремни
  • Коли и превозни средства
  • Музика
    • Българска музика
    • Джаз
    • Електронна
    • Метъл и Рок
    • Народна и Фолклор
    • Поп и Диско
    • Поп-фолк
    • Рап и хип-хоп
    • Ритъм енд блус и соул
    • Друга
  • Новини и политика
  • Реклами
  • Смях и Развлечение
  • Спорт
  • Технологии, Компютри, Хардуер
  • ТВ Предавания и Шоу Програми
  • Хора и блогове
  • Филми и анимация
  • Други
  • Old School Hip-Hop and Electroo 80" Видео клипчета

Календари

  • Събития
  • Изложения
  • Семинари
  • Парти
  • Празници в България

Групи продукти

  • Банер Реклами

Търсене в...

Търси резултати които съдържат...


Дата

  • Начало

    Край


Последно обновяване

  • Начало

    Край


Филтриране по брой...

Регистрация

  • Начало

    Край


Група


Skype


Facebook


Google+


Twitter


ICQ


Yahoo


Интернет сайт


Град


Интереси

Открити 72 резултата

  1. Здравейте, Реших да поразчистя компютъра и направих сканиране с MBAM, която откри нежелани приложения. Потърсих информация в интернет и попаднах на този форум. Искрено се надявам, че с ваша помощ, ще изчистим тази гадинка.Изнесох и прилагам лог от сканирането с мбам. След това ще изпълня другите стъпки в ръководството. Благодаря предварително. Malwarebytes Anti-Malware www.malwarebytes.org Дата на сканиране: 22.4.2015 г. Час на сканиране: 17:02:02 Дневник: mbam.txt Администратор: Да Версия: 2.01.4.1018 База от данни за злонамерен софтуер: v2015.04.22.03 База от данни за рууткити: v2015.04.21.01 Лиценз: Безплатен Защита от злонамерен софтуер: Забранено Защита от злонамерени страници: Забранено Самозащита: Забранено Когато опитах да изтегля Farbar Recovery Scan Tool антивирусната ми програма Аваст, го разпозна като зловреден и го блокира.
  2. Здравейте.Сигурно компютъра е лепнал някаква гадина , от известно време е много трудно да се сърфира нормално из интернет ,постоянно излизат разни реклами .Другото което е като дам назад ,за да върна някоя страница трябва да натисна 5-6 пъти стрелката , за да се върне предходната страница (използвам chrome) Забелязах , че с отварянето на браузъра се стартира и някаква добавка - 7savae 2.2 Като я махна се пооправя малко но пак е доста муден Компютъра се използва от всички членове на семейството ,та незнам кой в какви сайтове се рови и какво се сваля,имам антивирусна ( microsoft security essentials) но явно е влезнало нещо . Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015 Ran by Tsvetan (administrator) on TSVETAN-PC on 13-03-2015 18:28:47 Running from C:\Users\Tsvetan\Desktop Loaded Profiles: Tsvetan (Available profiles: Tsvetan) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Autodata Limited) C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BlueSoleilCS.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsMobileCS.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsHelpCS.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BtTray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) AppInit_DLLs: 4 0 => 4 0 File Not Found GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.msn.com/?pc=BDT1&ocid=bdtdhp SearchScopes: HKLM -> DefaultScope {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzutDtDtC0F0CyC0B0B0FzztCtB0F0CtAyDtN0D0Tzu0CtByEzytN1L2XzutBtFtCtFtCtFtAtCtB&cr=316245494 SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> DefaultScope {3A40E547-20FD-44a2-94D0-1C98342D1507} URL = http://search.daum.net/search?nil_profile=ie&ref_code=ms&q={searchTerms} SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> Backup.Old.DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {3A40E547-20FD-44a2-94D0-1C98342D1507} URL = http://search.daum.net/search?nil_profile=ie&ref_code=ms&q={searchTerms} SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {5E55F9EC-CFEF-E453-B954-71D3D1222C2A} URL = http://search.babylon.com/?q={searchTerms}&AF=109130&tt=090212_noffx&babsrc=SP_ss&mntrId=784efc35000000000000001fc6bbf812 SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {8CB80152-FBCE-473C-ABCD-A81D5C6F4937} URL = http://www.bing.com/search?FORM=BDKTDF&PC=BDT1&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {DD77A081-619B-4378-A4EE-FD7BFBE6A1A5} URL = https://www.google.com/search?q={searchTerms} DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 195.24.90.1 195.24.88.1 Tcpip\..\Interfaces\{1CCA028E-5561-4405-9AAE-567FCDF37FD7}: [NameServer] 10.250.238.3 10.250.238.4 FireFox: ======== FF ProfilePath: C:\Users\Tsvetan\AppData\Roaming\Mozilla\Firefox\Profiles\5wjvx04s.default FF DefaultSearchEngine: WebSearch FF DefaultSearchEngine,S: WebSearch FF DefaultSearchUrl: hxxp://websearch.eazytosearch.info/?pid=724&r=2014/05/17&hid=16964448839413303893&lg=EN&cc=BG&l=1&q= FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.1,S: WebSearch FF SelectedSearchEngine: WebSearch FF SelectedSearchEngine,S: WebSearch FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-04] () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-25] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-25] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-04] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-04] (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-09-07] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-09-07] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npfd.dll [2013-03-27] (FreshDevices Corp.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\911bg.xml [2011-11-21] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\diribg.xml [2011-11-21] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\pe-bg.xml [2011-11-21] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\portalbgdict.xml [2011-11-21] FF Extension: tiAkeshiop - C:\Users\Tsvetan\AppData\Roaming\Mozilla\Firefox\Profiles\5wjvx04s.default\Extensions\[email protected] [2015-02-15] FF Extension: aDsy - C:\Users\Tsvetan\AppData\Roaming\Mozilla\Firefox\Profiles\5wjvx04s.default\Extensions\[email protected] [2015-02-15] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2013-11-06] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Tsvetan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (7savae) - C:\ProgramData\hcokglkhkdpieiligmplpiebcicfkmin\ [] CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-03-16] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] Opera: ======= OPR StartupUrls: "hxxp://google.com/" ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Autodata Limited License Service; C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe [72704 2014-05-17] (Autodata Limited) [File not signed] R2 BlueSoleilCS; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BlueSoleilCS.exe [850432 2009-02-27] () [File not signed] R3 BsHelpCS; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsHelpCS.exe [98407 2009-02-27] () [File not signed] R2 BsMobileCS; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsMobileCS.exe [143467 2009-02-27] () [File not signed] R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] () S3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [33800 2008-11-25] (IVT Corporation.) S3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [27528 2008-11-25] (IVT Corporation.) R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [39304 2009-01-03] (IVT Corporation.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [20744 2009-01-07] (IVT Corporation.) R3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [30088 2008-12-07] () R3 BTNetFilter; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\Device\Win2k\BTNetFilter.sys [22416 2006-11-22] (IVT Corporation.) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-03-16] (DT Soft Ltd) S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [27672 2008-04-22] (EnTech Taiwan) R3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [26248 2008-07-02] (IVT Corporation.) R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [48640 2009-08-23] (Atheros Communications, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [14856 2008-01-21] (IVT Corporation.) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [31880 2009-01-08] (IVT Corporation.) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1841272 2012-10-22] (VIA Technologies, Inc.) R3 vodafone_K3805-z_dc_enum; C:\Windows\System32\DRIVERS\vodafone_K3805-z_dc_enum.sys [61952 2010-03-01] (Vodafone) R1 wStLib; C:\Windows\System32\drivers\wStLib.sys [52928 2014-03-19] (StdLib) S3 ZTEusbvoice; C:\Windows\System32\DRIVERS\ZTEusbvoice.sys [105856 2010-04-19] (ZTE Incorporated) S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [193536 2011-04-09] (ZTE Incorporated) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 BT; system32\DRIVERS\btnetdrv.sys [X] S0 BTHidEnum; System32\Drivers\vbtenum.sys [X] S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-13 18:28 - 2015-03-13 18:29 - 00016803 _____ () C:\Users\Tsvetan\Desktop\FRST.txt 2015-03-13 18:28 - 2015-03-13 18:28 - 01135104 _____ (Farbar) C:\Users\Tsvetan\Desktop\FRST.exe 2015-03-13 18:28 - 2015-03-13 18:28 - 00000000 ____D () C:\FRST 2015-03-11 12:31 - 2015-03-06 07:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-03-11 12:31 - 2015-03-06 07:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-03-11 12:31 - 2015-03-06 07:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-03-11 12:31 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-03-11 12:31 - 2015-03-06 07:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-03-11 12:31 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-03-11 12:31 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-03-11 12:31 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-11 12:31 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-11 12:31 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-11 12:31 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-11 12:31 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-03-11 12:31 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-11 12:31 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-11 12:31 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-03-11 12:31 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-11 12:31 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-03-11 12:31 - 2015-02-20 04:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-03-11 12:31 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-11 12:31 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-03-11 12:31 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-03-11 12:31 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-11 12:31 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-11 12:31 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-03-11 12:31 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-03-11 12:31 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-03-11 12:31 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-11 12:31 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-03-11 12:31 - 2015-02-20 03:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-03-11 12:31 - 2015-02-20 03:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-11 12:31 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-11 12:31 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-11 12:31 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-11 12:31 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-11 12:31 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-11 12:31 - 2015-02-20 03:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-03-11 12:31 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-03-11 12:31 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-11 12:31 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-11 12:31 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-11 12:31 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-11 12:31 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-11 12:31 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-03-11 12:31 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-11 12:31 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-03-11 12:31 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-11 12:31 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-03-11 12:31 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-03-11 12:31 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-03-11 12:31 - 2015-02-03 05:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2015-03-11 12:31 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2015-03-11 12:31 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-03-11 12:31 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-03-11 12:31 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2015-03-11 12:31 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-03-11 12:31 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-11 12:31 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-11 12:31 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-11 12:31 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-03-11 12:31 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-11 12:31 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-11 12:31 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-11 12:31 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-02-25 15:54 - 2015-01-09 01:44 - 00419936 _____ () C:\Windows\system32\locale.nls 2015-02-25 14:19 - 2015-02-04 01:57 - 00606920 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe 2015-02-25 14:14 - 2015-02-04 05:35 - 24199824 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 15294096 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 11272048 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 11209376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 10702664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-02-25 14:14 - 2015-02-04 05:35 - 03987784 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 01060680 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234144.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 00911504 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234144.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 00908432 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 00870032 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2015-02-17 19:14 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-02-17 19:14 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-02-17 19:14 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-02-17 16:04 - 2015-02-17 16:04 - 01202848 _____ (Microsoft Corporation) C:\Windows\system32\FM20.DLL 2015-02-15 18:23 - 2015-02-15 18:23 - 00028878 _____ () C:\Users\Tsvetan\Downloads\247.degrees.fahrenheit.2011.brrip.xvid-lycan(subsunacs.net) (1).rar 2015-02-15 18:23 - 2015-02-15 18:23 - 00000000 ____D () C:\Users\Tsvetan\Desktop\247.degrees.fahrenheit.2011.brrip.xvid-lycan(subsunacs.net) (1) 2015-02-15 18:20 - 2015-02-15 18:20 - 00028878 _____ () C:\Users\Tsvetan\Downloads\247.degrees.fahrenheit.2011.brrip.xvid-lycan(subsunacs.net).rar 2015-02-15 17:46 - 2015-02-15 17:46 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (6).torrent 2015-02-15 17:44 - 2015-02-15 17:44 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (5).torrent 2015-02-15 17:44 - 2015-02-15 17:44 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (4).torrent 2015-02-15 17:43 - 2015-02-15 17:43 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (3).torrent 2015-02-15 17:43 - 2015-02-15 17:43 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (2).torrent 2015-02-15 17:42 - 2015-02-15 17:42 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (1).torrent 2015-02-15 17:41 - 2015-02-15 17:41 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to].torrent 2015-02-13 15:51 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-13 15:50 - 2015-02-04 04:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-02-13 15:50 - 2015-02-04 04:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-02-13 15:50 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-02-13 15:50 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-13 18:22 - 2012-09-03 19:13 - 00000988 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-13 18:22 - 2011-12-13 16:42 - 01428287 _____ () C:\Windows\WindowsUpdate.log 2015-03-13 18:21 - 2013-03-27 17:27 - 00006510 _____ () C:\Windows\system32\LOCALSERVICE.INI 2015-03-13 18:21 - 2013-03-27 17:27 - 00000102 _____ () C:\Windows\system32\LOCALDEVICE.INI 2015-03-13 18:21 - 2009-02-27 17:04 - 00001152 _____ () C:\Windows\system32\bscs.ini 2015-03-13 18:17 - 2009-07-14 06:34 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-13 18:17 - 2009-07-14 06:34 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-13 18:10 - 2014-09-23 17:37 - 00027962 _____ () C:\Windows\setupact.log 2015-03-13 18:10 - 2012-09-03 19:13 - 00000984 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-13 18:10 - 2011-12-13 17:28 - 00001016 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3399673831-2713686379-3482629517-1000UA.job 2015-03-13 18:10 - 2011-12-13 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-03-13 18:10 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-12 20:36 - 2012-05-04 15:04 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-12 19:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2015-03-12 19:41 - 2011-12-13 17:28 - 00000964 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3399673831-2713686379-3482629517-1000Core.job 2015-03-12 17:37 - 2009-07-14 06:33 - 00406024 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-11 15:09 - 2011-12-15 14:29 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-11 15:08 - 2013-08-18 20:39 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-11 15:03 - 2011-12-13 20:52 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-11 12:25 - 2014-10-03 20:00 - 00000000 ____D () C:\Program Files\Opera 2015-03-09 14:31 - 2010-11-20 23:01 - 00786514 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-03-03 15:16 - 2011-12-13 17:37 - 00246920 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-02-25 22:11 - 2013-11-11 19:32 - 00000000 ____D () C:\Users\Tsvetan\AppData\Local\Viber 2015-02-25 22:10 - 2013-11-11 19:32 - 00000000 ____D () C:\Users\Tsvetan\AppData\Roaming\ViberPC 2015-02-25 14:19 - 2014-02-18 21:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-02-22 20:21 - 2011-12-13 18:56 - 00000000 ____D () C:\Users\Tsvetan\AppData\Roaming\Skype 2015-02-18 18:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\tracing 2015-02-15 21:00 - 2011-12-13 18:33 - 00000000 ____D () C:\Users\Tsvetan\AppData\Roaming\uTorrent 2015-02-15 12:36 - 2014-12-12 09:45 - 00000000 ____D () C:\Windows\system32\appraiser 2015-02-15 12:36 - 2014-05-07 15:17 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-02-13 16:26 - 2012-05-01 12:00 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2015-02-13 16:26 - 2012-01-09 21:46 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2015-02-13 16:26 - 2011-12-13 18:54 - 00001945 _____ () C:\Windows\epplauncher.mif ==================== Files in the root of some directories ======= 2014-11-23 18:57 - 2014-12-12 18:52 - 0000004 _____ () C:\Users\Tsvetan\AppData\Roaming\appdataFr2.bin 2011-12-19 15:09 - 2014-06-25 10:56 - 0000088 _____ () C:\Users\Tsvetan\AppData\Roaming\default.pls 2013-12-09 20:09 - 2013-12-09 20:09 - 0004608 _____ () C:\Users\Tsvetan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-09-09 13:11 - 2013-09-09 13:11 - 0003366 _____ () C:\Users\Tsvetan\AppData\Local\HWVendorDetection.log 2012-09-09 19:23 - 2013-07-09 17:10 - 0007634 _____ () C:\Users\Tsvetan\AppData\Local\Resmon.ResmonCfg 2010-04-22 19:37 - 2010-04-22 19:37 - 0155474 ____R () C:\ProgramData\DeviceManager.xml.rc4 2011-12-13 18:57 - 2011-12-13 18:57 - 0000056 ____H () C:\ProgramData\ezsidmv.dat 2014-05-17 16:11 - 2014-07-15 15:02 - 0000483 _____ () C:\ProgramData\Sls.ini Some content of TEMP: ==================== C:\Users\Tsvetan\AppData\Local\temp\jre-8u31-windows-au.exe C:\Users\Tsvetan\AppData\Local\temp\nvSCPAPI.dll C:\Users\Tsvetan\AppData\Local\temp\nvStInst.exe C:\Users\Tsvetan\AppData\Local\temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-06 15:52 Addition.txt
  3. Здравейте, Имам голям проблем с троянски кон. Този вид е известен като Dark Comet. Всичко тръгна от един приятел който беше правил клип как се работи с него и аз го изтеглих. ( за което съжалявам много ) След малко цъкнах на програмата да се пусне и нищо не стана, затворих папката след 10 секунди я отворих отново и програмката избягала чак в C диска, папка Users и така така някъде си навътре... Четох много постове и изтеглих някои програми: - Malwarebytes Anti-Malware - esetsmartinstaller_enu - noscript - CryptoPrevent - MyDefrag - FRST64 И изтрих стара ми антивирусна Advanced System Care 8. Програмата Malwarebytes Anti-Malware я пусках да изчисти уж някои неща и какво да видя... Последно не си спомням колко бяха, но говорим за повече от 150. Така, така сега търся помощ в смисъл какво ви е нужно освен двата текстови документа от FRST които прикачих. И както ви е известно четох малко за този троянски кон и както си пише така и стана ... Метнал се е на csrss, но нещо не знам какво направих и изчезна и тей тей си вървъ из файловете, до одеве ми местеше иконите.. Та ся утихна малко тоз кон и се оставям на ваши ръце. Благодаря предварително ! Addition.txt FRST.txt
  4. Здравейте, за първи път пиша във форума и моля да ме извините ако тук не е точното място на моя въпрос. От няколко дни имам проблем - при зареждане на страници ми изкача прозорец, който блокира съдържанието на страницата. Обикновено се отваря нов прозорец със следното съдържание - data:text/html,<script>window.close();</script> или конкретна реклама на онлайн магазин или досадните "Вие спечелихте...". Използвам Avast, Malwarebytes и adwcleaner, които не индикират проблем. Моля за помощ от Ваша страна. Благодаря за отделеното време и внимание. Хубав и успешен ден!
  5. Здравейте!!!Пиша Ви за пореден път, но този път не става въпрос за моята машина , а за тази на мой приятел. Проблема е следния, без да е отворен никакъв прозорец, лаптопа се товари на 80-100 % и вдига много висока температура. А когато тръне да зарежда примерно Експлорер, ужасно много бави. Ето и логовете: FRST Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-11-2014 Ran by Dzhemal (administrator) on DZHEMAL-HP on 21-11-2014 21:29:56 Running from C:\Users\Dzhemal\Desktop Loaded Profile: Dzhemal (Available profiles: Dzhemal & Guest) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (Beijing ELEX Technology Co., Ltd.) C:\Program Files (x86)\Software Plate\svcgdp.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe () C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (SafeIP) C:\Program Files (x86)\SafeIP\SafeIPS.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Nullsoft) C:\Program Files (x86)\Winamp\winampa.exe () C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\IObit\Advanced SystemCare 7\RealTimeProtector.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [synTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated) HKLM\...\Run: [sysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.) HKLM-x32\...\Run: [iAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation) HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-16] (Hewlett-Packard Development Company L.P.) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-03-16] (EasyBits Software AS) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [39424 2009-12-18] (Nullsoft) HKLM-x32\...\Run: [ModemListener] => C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe [98304 2010-01-27] () HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [Google Update] => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-06-26] (Google Inc.) HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22869088 2014-10-21] (Google) HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2283808 2013-11-11] (IObit) HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {29828cb2-d0cf-11e0-a9ce-2c27d7dba7d9} - F:\AutoRun.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {29828cc7-d0cf-11e0-a9ce-2c27d7dba7d9} - J:\AutoRun.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {3a1324f1-d301-11e0-ab1e-2c27d7dba7d9} - F:\AutoRun.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {41892756-f045-11e0-8c31-2c27d7dba7d9} - F:\AutoRun.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {41892759-f045-11e0-8c31-2c27d7dba7d9} - F:\AutoRun.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {50066d0f-265a-11e1-b5ec-2c27d7dba7d9} - I:\autorun.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {c37f0e3a-c19d-11e3-a6a1-2c27d7dba7d9} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\MountPoints2: {e165778e-d16b-11e0-8bcc-2c27d7dba7d9} - F:\AutoRun.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-966336249-240343522-4042860801-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/ URLSearchHook: HKLM-x32 - Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) URLSearchHook: HKU\S-1-5-21-966336249-240343522-4042860801-1000 - Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) SearchScopes: HKLM -> DefaultScope value is missing. SearchScopes: HKLM -> {903E9084-8050-4C90-870A-226613C1C2F5} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20131222185642776&tb_oid=22-12-2013&tb_mrud=22-12-2013 SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 -> {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20131222185642776&tb_oid=22-12-2013&tb_mrud=22-12-2013 SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20131222185642776&tb_oid=22-12-2013&tb_mrud=22-12-2013 SearchScopes: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> {EF87F31E-38AE-4881-B513-151ED9619405} URL = http://search.yahoo.com/search?fr=mcafee&p={SearchTerms} BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus) BHO-x32: Winamp Toolbar Loader -> {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -> C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Advanced SystemCare Browser Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit) BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Proxy Help -> {F386E548-C533-472E-8C61-C026FB14FEB9} -> C:\Windows\SysWow64\Newtabs_22find.dll (Newtabs. inc) BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) Toolbar: HKU\S-1-5-21-966336249-240343522-4042860801-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} https://ebb.ubb.bg/CAPICOM/capicom.cab DPF: HKLM-x32 {B015B944-7316-49AE-AC84-ACCA9379EA32} http://77.85.205.2:90/IPCamPluginMJPEG.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-04-20] (EasyBits Software Corp.) Winsock: Catalog9 01 C:\Windows\SysWOW64\SafeIPs.dll [380608] (SafeIP) Winsock: Catalog9 02 C:\Windows\SysWOW64\SafeIPs.dll [380608] (SafeIP) Winsock: Catalog9 03 C:\Windows\SysWOW64\SafeIPs.dll [380608] (SafeIP) Winsock: Catalog9 04 C:\Windows\SysWOW64\SafeIPs.dll [380608] (SafeIP) Winsock: Catalog9 15 C:\Windows\SysWOW64\SafeIPs.dll [380608] (SafeIP) Winsock: Catalog9-x64 01 C:\Windows\system32\SafeIPs64.dll [540864] (SafeIP) Winsock: Catalog9-x64 02 C:\Windows\system32\SafeIPs64.dll [540864] (SafeIP) Winsock: Catalog9-x64 03 C:\Windows\system32\SafeIPs64.dll [540864] (SafeIP) Winsock: Catalog9-x64 04 C:\Windows\system32\SafeIPs64.dll [540864] (SafeIP) Winsock: Catalog9-x64 15 C:\Windows\system32\SafeIPs64.dll [540864] (SafeIP) Hosts: 127.0.0.1 localhost Tcpip\Parameters: [DhcpNameServer] 192.168.43.1 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-966336249-240343522-4042860801-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-966336249-240343522-4042860801-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFF [2013-10-12] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn [2014-11-21] FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\39.0.2171.65\gcswf32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\39.0.2171.65\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\Application\39.0.2171.65\pdf.dll () CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File CHR Profile: C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Диск) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-09] CHR Extension: (YouTube) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-01] CHR Extension: (Adblock Plus) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-07-22] CHR Extension: (Google Търсене) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-01] CHR Extension: (Skype Click to Call) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-02-05] CHR Extension: (Google Wallet) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Gmail) - C:\Users\Dzhemal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-01] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-11-22] CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\Exts\Chrome.crx [2013-09-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [878368 2013-10-25] (IObit) R2 DeviceManager; C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe [40960 2009-11-17] () [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed] R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2372096 2011-02-19] (Realsil Microelectronics Inc.) [File not signed] S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151232 2013-12-02] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-15] (Nero AG) [File not signed] R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [138272 2012-06-16] (Symantec Corporation) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [266240 2007-01-15] (Nero AG) [File not signed] R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R3 SafeIPS; C:\Program Files (x86)\SafeIP\SafeIPs.exe [3797184 2012-12-17] (SafeIP) R2 svcgdp; C:\Program Files (x86)\Software Plate\svcgdp.exe [224416 2012-07-02] (Beijing ELEX Technology Co., Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20141118.001\BHDrvx64.sys [1587416 2014-10-16] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [167072 2012-06-07] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-10-23] (Symantec Corporation) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20141120.001\IDSvia64.sys [637656 2014-11-14] (Symantec Corporation) S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [119680 2009-11-17] (TCT International Mobile Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-21] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20141109.003\ENG64.SYS [129752 2014-10-24] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20141109.003\EX64.SYS [2137304 2014-10-24] (Symantec Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2012-01-03] () [File not signed] R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [737952 2012-07-06] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [37536 2012-07-06] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMDS64.SYS [451192 2012-04-17] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [1129120 2012-05-22] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-12-24] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [190072 2012-04-18] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [405624 2012-04-18] (Symantec Corporation) S3 utmxnjk0; No ImagePath S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] U2 wuaserv; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-21 21:28 - 2014-11-21 21:29 - 00030994 _____ () C:\Users\Dzhemal\Desktop\Addition.txt 2014-11-21 21:27 - 2014-11-21 21:30 - 00025889 _____ () C:\Users\Dzhemal\Desktop\FRST.txt 2014-11-21 21:27 - 2014-11-21 21:30 - 00000000 ____D () C:\FRST 2014-11-21 21:25 - 2014-11-21 21:27 - 02117632 _____ (Farbar) C:\Users\Dzhemal\Desktop\FRST64.exe 2014-11-21 00:25 - 2014-11-21 00:25 - 00000000 __SHD () C:\Users\Dzhemal\AppData\Local\EmieBrowserModeList 2014-11-21 00:11 - 2014-11-21 00:11 - 00007601 _____ () C:\Users\Dzhemal\AppData\Local\Resmon.ResmonCfg 2014-11-21 00:07 - 2014-11-21 00:07 - 00000056 _____ () C:\Windows\setupact.log 2014-11-21 00:07 - 2014-11-21 00:07 - 00000000 _____ () C:\Windows\setuperr.log 2014-11-21 00:06 - 2014-11-21 00:06 - 00005986 _____ () C:\Windows\PFRO.log 2014-11-21 00:05 - 2014-11-21 00:05 - 00000000 _____ () C:\asc_rdflag 2014-11-20 23:26 - 2014-11-07 21:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-20 23:26 - 2014-11-07 21:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-20 23:26 - 2014-11-06 06:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-20 23:26 - 2014-11-06 06:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-11-20 23:26 - 2014-11-06 05:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-20 23:26 - 2014-11-06 05:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-11-20 23:26 - 2014-11-06 05:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-20 23:26 - 2014-11-06 05:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-20 23:26 - 2014-11-06 05:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-20 23:26 - 2014-11-06 05:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-11-20 23:26 - 2014-11-06 05:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-11-20 23:26 - 2014-11-06 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-20 23:26 - 2014-11-06 05:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-11-20 23:26 - 2014-11-06 05:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-11-20 23:26 - 2014-11-06 05:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-20 23:26 - 2014-11-06 05:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-20 23:26 - 2014-11-06 05:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-20 23:26 - 2014-11-06 05:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-20 23:26 - 2014-11-06 05:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-11-20 23:26 - 2014-11-06 05:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-20 23:26 - 2014-11-06 05:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-20 23:26 - 2014-11-06 05:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-20 23:26 - 2014-11-06 05:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-11-20 23:26 - 2014-11-06 04:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-11-20 23:26 - 2014-11-06 04:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-11-20 23:26 - 2014-11-06 04:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-20 23:26 - 2014-11-06 04:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-20 23:26 - 2014-11-06 04:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-20 23:26 - 2014-11-06 04:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-20 23:26 - 2014-11-06 04:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-20 23:26 - 2014-11-06 04:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-20 23:26 - 2014-11-06 04:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-20 23:26 - 2014-11-06 04:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-20 23:26 - 2014-11-06 04:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-20 23:26 - 2014-11-06 04:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-20 23:26 - 2014-11-06 04:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-20 23:26 - 2014-11-06 04:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-20 23:26 - 2014-11-06 04:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-11-20 23:26 - 2014-11-06 04:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-20 23:26 - 2014-11-06 04:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-20 23:26 - 2014-11-06 03:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-11-20 23:26 - 2014-11-06 03:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-20 23:26 - 2014-11-06 03:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-20 23:26 - 2014-11-06 03:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-11-20 23:25 - 2014-11-06 06:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-20 23:25 - 2014-11-06 05:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-11-20 23:25 - 2014-11-06 05:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-11-20 23:25 - 2014-11-06 05:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-11-20 23:25 - 2014-11-06 05:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-11-20 23:25 - 2014-11-06 05:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-20 23:25 - 2014-11-06 05:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-20 23:25 - 2014-11-06 05:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-20 23:25 - 2014-11-06 05:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-20 23:25 - 2014-11-06 04:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-11-20 23:25 - 2014-11-06 04:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-20 23:25 - 2014-11-06 04:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-20 21:38 - 2014-11-21 19:53 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-20 21:38 - 2014-11-20 21:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-11-20 21:38 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-11-20 21:38 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-11-20 19:36 - 2014-09-19 11:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-20 19:36 - 2014-09-19 11:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-20 19:36 - 2014-09-19 11:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-20 19:36 - 2014-09-19 11:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-20 19:36 - 2014-09-19 11:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-20 19:36 - 2014-09-19 11:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-20 19:36 - 2014-09-19 11:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-11-20 19:36 - 2014-09-19 11:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-20 19:36 - 2014-09-19 11:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-11-20 19:36 - 2014-09-19 11:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-11-20 19:36 - 2014-09-19 11:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-11-20 19:36 - 2014-09-19 11:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-11-20 19:24 - 2014-11-11 05:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-20 19:24 - 2014-11-11 05:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-20 19:24 - 2014-11-11 04:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-20 19:24 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-20 19:24 - 2014-10-14 04:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-20 19:24 - 2014-10-14 04:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-20 19:24 - 2014-10-14 03:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-11-20 19:24 - 2014-10-14 03:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-11-20 19:23 - 2014-10-14 04:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-20 19:23 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-20 19:20 - 2014-10-14 04:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-20 19:20 - 2014-10-14 04:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-20 19:20 - 2014-10-14 04:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-20 19:20 - 2014-10-14 03:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-20 19:20 - 2014-10-14 03:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-20 18:41 - 2014-08-21 08:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-20 18:41 - 2014-08-21 08:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-20 18:41 - 2014-08-21 08:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-20 18:41 - 2014-08-21 08:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-11-20 18:36 - 2014-10-03 04:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-20 18:36 - 2014-10-03 04:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-20 18:36 - 2014-10-03 04:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-20 18:36 - 2014-10-03 04:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-20 18:36 - 2014-10-03 04:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-20 18:36 - 2014-10-03 03:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-20 18:36 - 2014-10-03 03:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-11-20 18:36 - 2014-10-03 03:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-11-20 18:36 - 2014-08-12 04:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-20 18:36 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2014-11-20 18:06 - 2014-10-10 02:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-20 16:57 - 2014-10-25 03:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-20 16:57 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-20 16:52 - 2014-10-18 04:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-20 16:52 - 2014-10-18 03:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-19 23:59 - 2014-11-19 23:59 - 00000000 ____D () C:\Program Files (x86)\HTC 2014-11-19 23:57 - 2014-11-19 23:59 - 00000000 ____D () C:\Temp 2014-11-19 23:57 - 2014-11-19 23:57 - 00000000 ____D () C:\ProgramData\HTC 2014-11-19 23:57 - 2010-03-08 22:08 - 00121800 _____ (QUALCOMM Incorporated) C:\Windows\system32\Drivers\HtcVComV64.sys 2014-10-25 15:43 - 2014-10-25 15:43 - 00000000 ____D () C:\Program Files\Adblock Plus for IE 2014-10-24 23:47 - 2014-10-24 23:48 - 00000000 ____D () C:\Users\Dzhemal\Downloads\Salmon.Fishing.in.the.Yemen.2011.HDRip.XviD.BGAUDiO-SiSO 2014-10-24 17:12 - 2014-10-24 19:42 - 00000000 ____D () C:\g ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-21 21:12 - 2013-07-22 21:45 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-21 21:09 - 2011-08-19 21:05 - 00000000 ____D () C:\Users\Dzhemal\AppData\Roaming\Skype 2014-11-21 21:03 - 2012-06-26 16:50 - 00001016 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA.job 2014-11-21 20:43 - 2012-08-18 16:51 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-21 20:27 - 2011-05-30 09:52 - 01801248 _____ () C:\Windows\WindowsUpdate.log 2014-11-21 18:39 - 2013-01-28 16:19 - 00000000 ____D () C:\Users\Dzhemal\Desktop\Джемал Рупчев 2012 2014-11-21 18:27 - 2013-12-22 20:50 - 00000000 ____D () C:\Users\Dzhemal\AppData\Roaming\Winamp 2014-11-21 15:03 - 2012-06-26 16:50 - 00000964 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core.job 2014-11-21 11:50 - 2011-08-19 19:40 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-11-21 10:43 - 2009-07-14 07:13 - 00006260 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-21 09:43 - 2012-08-18 16:51 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-21 00:12 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-21 00:12 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-21 00:09 - 2014-01-07 09:43 - 00000000 ____D () C:\ProgramData\ProductData 2014-11-21 00:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-21 00:07 - 2009-07-14 06:45 - 00340568 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-21 00:05 - 2014-02-16 17:23 - 72785920 _____ () C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2014-11-21 00:05 - 2014-02-16 17:23 - 00671744 _____ () C:\Windows\system32\config\DEFAULT.iodefrag.bak 2014-11-21 00:05 - 2014-02-16 17:23 - 00061440 _____ () C:\Windows\system32\config\SAM.iodefrag.bak 2014-11-21 00:05 - 2014-02-16 17:23 - 00028672 _____ () C:\Windows\system32\config\SECURITY.iodefrag.bak 2014-11-21 00:05 - 2011-08-19 17:03 - 00000000 ____D () C:\Users\Dzhemal 2014-11-20 23:56 - 2013-07-25 19:53 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-20 23:47 - 2012-12-21 23:16 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-20 21:38 - 2013-07-22 18:33 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-11-20 21:38 - 2013-07-22 18:33 - 00000000 ____D () C:\Users\Dzhemal\AppData\Roaming\Malwarebytes 2014-11-20 21:38 - 2013-07-22 18:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-20 21:38 - 2013-07-22 18:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-11-20 16:03 - 2011-05-30 10:01 - 00000000 ____D () C:\ProgramData\Norton 2014-11-18 17:18 - 2014-04-10 06:30 - 00003198 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForDzhemal 2014-11-18 17:18 - 2014-04-10 06:30 - 00000340 _____ () C:\Windows\Tasks\HPCeeScheduleForDzhemal.job 2014-11-18 00:35 - 2014-01-07 09:51 - 00002205 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk 2014-11-18 00:34 - 2011-08-28 14:21 - 00000000 ____D () C:\Users\Dzhemal\AppData\Roaming\uTorrent 2014-11-17 01:28 - 2014-03-31 18:14 - 43892736 _____ () C:\Windows\system32\config\COMPONENTS.iodefrag.bak 2014-11-14 14:58 - 2012-06-26 16:50 - 00003990 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA 2014-11-14 14:58 - 2012-06-26 16:50 - 00003594 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core 2014-11-14 09:38 - 2012-08-18 16:51 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-11-14 09:38 - 2012-08-18 16:51 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-11-07 08:28 - 2012-08-21 11:02 - 00000000 ____D () C:\Users\Dzhemal\Desktop\Bambina 2014-11-05 21:17 - 2013-07-09 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-11-01 17:27 - 2013-05-09 08:36 - 00000000 ____D () C:\Users\Public\Downloads\Norton 2014-10-25 09:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-10-25 07:02 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-17 17:20 ==================== End Of Log ============================ Addition Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-11-2014 Ran by Dzhemal at 2014-11-21 21:30:55 Running from C:\Users\Dzhemal\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Internet Security (Disabled - Out of date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Enabled - Out of date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKLM-x32\...\uTorrent) (Version: 3.1.3 - ) µTorrent (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\uTorrent) (Version: 3.3.2.30488 - BitTorrent Inc.) 50 FREE MP3s +1 Free Audiobook! (HKLM-x32\...\eMusic Promotion) (Version: 1.0.0.1 - eMusic.com Inc) Adblock Plus за IE (32-битов и 64-битов) (HKLM\...\{04F1B8BC-8D13-48FB-9D17-A168BFA0A560}) (Version: 99.9 - Eyeo GmbH) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.94 - Adobe Systems Incorporated) Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated) Advanced SystemCare 7 (HKLM-x32\...\Advanced SystemCare 7_is1) (Version: 7.0.6 - IObit) Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden Ashampoo Magical Optimizer 1.22 (HKLM-x32\...\Ashampoo Magical Optimizer_is1) (Version: 1.2.2 - Ashampoo GmbH & Co. KG) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bejeweled 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation) Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.63.1071 - AB Team, d.o.o.) Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.1.3922 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden Download Updater (AOL LLC) (HKLM-x32\...\SoftwareUpdUtility) (Version: - ) <==== ATTENTION Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Evernote v. 4.2.2 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.2.3979 - Evernote Corp.) Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE - The Traitor Soul (x32 Version: 2.2.0.95 - WildTangent) Hidden Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden Google Chrome (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Drive (HKLM-x32\...\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden HP Connection Manager (HKLM-x32\...\{795AADBF-58C2-42D0-B779-E730702A247E}) (Version: 4.0.45.1 - Hewlett-Packard Company) HP Documentation (HKLM-x32\...\{6C453C9C-38AE-494D-BF89-7AA0DE87F3E5}) (Version: 1.2.0.0 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.4 - WildTangent) HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{7E799992-5DA0-4A1A-9443-B1836B063FEC}) (Version: 1.4.8 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{210A03F5-B2ED-4947-B27E-516F50CBB292}) (Version: 8.6.4530.3651 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13253.3682 - Hewlett-Packard Company) HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT) Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2279 - Intel Corporation) Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.0.5.1228 - IObit) IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC) Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 6.0.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.0 - ) Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS) Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden Malwarebytes Anti-Malware, версия 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mystery P.I. - Stolen in San Francisco (x32 Version: 2.2.0.95 - WildTangent) Hidden Namco All-Stars PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden Nero 7 Premium (HKLM-x32\...\{FC98FBE9-E931-494C-8717-497185371033}) (Version: 7.02.4712 - Nero AG) NewTabs Uninstall (HKLM-x32\...\NewTabs) (Version: - ELEX Technology) <==== ATTENTION Norton Internet Security (HKLM-x32\...\NIS) (Version: 19.9.1.14 - Symantec Corporation) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden Ralink RT5390 802.11b/g/n WiFi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.13.0 - Ralink) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.77 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 2.0.0 - Hewlett-Packard) Hidden SA Dictionary 2008 Beta 4 (HKLM-x32\...\{055A5AF0-9FEB-440D-B00A-18935C7C171C}) (Version: 6.6.12 - Stefan Angelov) SafeIP (HKLM-x32\...\SAFEIP_is1) (Version: - SafeIP) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.4.11328 - Skype Technologies S.A.) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Slingo Supreme (x32 Version: 2.2.0.95 - WildTangent) Hidden Software Plate (HKLM-x32\...\Software Plate) (Version: 1.0.1 - XingCloud) <==== ATTENTION Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.4.4 - Synaptics Incorporated) The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: - ) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden VIVACOM 3G USB MODEM (HKLM-x32\...\VIVACOM 3G USB MODEM ALCATEL_is1) (Version: - Alcatel) WildTangent Games App (HP Games) (x32 Version: 4.0.10.16 - WildTangent) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.57 - Nullsoft, Inc) Winamp Application Detect (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Winamp Toolbar (HKLM-x32\...\Winamp Toolbar) (Version: - ) <==== ATTENTION Winamp Toolbar (HKU\S-1-5-21-966336249-240343522-4042860801-1000\...\Winamp Toolbar) (Version: - ) <==== ATTENTION Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - ) Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-966336249-240343522-4042860801-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dzhemal\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.) ==================== Restore Points ========================= 02-11-2014 17:00:26 Windows Backup 09-11-2014 18:00:01 Windows Backup 16-11-2014 18:42:29 Windows Backup 17-11-2014 07:21:45 Windows Update 19-11-2014 21:47:34 Windows Update 20-11-2014 04:31:44 Windows Update 20-11-2014 21:45:07 Windows Update 21-11-2014 08:37:53 Windows Update 21-11-2014 09:34:30 Windows Update 21-11-2014 09:50:23 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2013-07-22 17:26 - 00000741 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {3219DB7E-175F-4B87-8107-981363264FD7} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe [2013-02-02] (Symantec Corporation) Task: {3295386A-7074-4758-B958-E1289893B2D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-18] (Google Inc.) Task: {4244458F-6275-43A1-96A7-9E6D1A73D267} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation) Task: {49CDAC2F-0D0A-4BFE-B501-C3AB44CDBA1D} - System32\Tasks\ASC7_SkipUac_Dzhemal => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2013-11-18] (IObit) Task: {57CA1EE8-5FB9-4E8E-A104-E0405DC70F0D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-02-10] (Hewlett-Packard) Task: {7763808A-020E-4E55-AA5D-A528C2E856A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe Task: {7A2EF186-422E-444D-A394-1C25FC6ABFEA} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-22] (CyberLink) Task: {84580A75-01D4-43F3-8772-E815648600DB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-18] (Google Inc.) Task: {878BED2C-6AA2-4C05-97CE-B4AD9D1508E0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-26] (Google Inc.) Task: {9D31538F-8BE4-42A1-9CA2-FDC7A3456732} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-26] (Google Inc.) Task: {B58F9550-E595-4BE4-8D78-59DBD1B80F7A} - System32\Tasks\HPCeeScheduleForDzhemal => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {B7F35B8F-DFB7-4B6F-AEB0-03C8342E329B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-22] (Adobe Systems Incorporated) Task: {BB7344DA-96B9-4934-B74A-40E023454747} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\SymErr.exe [2012-02-04] (Symantec Corporation) Task: {BF0C8C1F-2C36-461D-8DA0-8404076366C9} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe [2013-11-11] (IObit) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000Core.job => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-966336249-240343522-4042860801-1000UA.job => C:\Users\Dzhemal\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForDzhemal.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2011-12-14 15:50 - 2009-11-17 10:44 - 00040960 _____ () C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe 2013-10-17 15:27 - 2013-10-17 15:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe 2011-12-14 15:50 - 2010-01-27 11:08 - 00098304 _____ () C:\Program Files (x86)\VIVACOM 3G USB MODEM\ModemListener.exe 2014-01-07 09:51 - 2013-10-25 12:07 - 01120032 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\RealTimeProtector.exe 2014-01-07 09:51 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll 2014-01-07 09:51 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\webres.dll 2014-11-21 00:08 - 2014-11-21 00:08 - 00098816 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32api.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00110080 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\pywintypes27.dll 2014-11-21 00:08 - 2014-11-21 00:08 - 00364544 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\pythoncom27.dll 2014-11-21 00:08 - 2014-11-21 00:08 - 00045568 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\_socket.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 01160704 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\_ssl.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00320512 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32com.shell.shell.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00713216 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\_hashlib.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 01175040 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._core_.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00805888 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._gdi_.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00811008 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._windows_.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 01062400 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._controls_.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00735232 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._misc_.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00128512 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\_elementtree.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00127488 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\pyexpat.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00557056 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\pysqlite2._sqlite.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00087552 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\_ctypes.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00119808 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32file.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00108544 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32security.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00007168 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\hashobjs_ext.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00167936 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32gui.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00018432 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32event.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00038912 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32inet.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00011264 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32crypt.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00070656 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._html2.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00027136 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\_multiprocessing.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00035840 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32process.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00686080 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\unicodedata.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00122368 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._wizard.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00024064 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32pipe.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00025600 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32pdh.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00525640 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\windows._lib_cacheinvalidation.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00010240 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\select.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00017408 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32profile.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00022528 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\win32ts.pyd 2014-11-21 00:08 - 2014-11-21 00:08 - 00078336 _____ () C:\Users\Dzhemal\AppData\Local\Temp\_MEI41682\wx._animate.pyd 2014-01-07 09:51 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madExcept_.bpl 2014-01-07 09:51 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madBasic_.bpl 2014-01-07 09:51 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madDisAsm_.bpl 2014-10-25 07:15 - 2014-10-25 07:15 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9b1cac8d98bd69d3e56a26ff2f96f266\IsdiInterop.ni.dll 2011-05-30 09:50 - 2011-01-13 02:56 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SafeIPS => ""="service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => MSCONFIG\startupreg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" MSCONFIG\startupreg: DAEMON Tools Lite => MSCONFIG\startupreg: SunJavaUpdateSched => ========================= Accounts: ========================== Administrator (S-1-5-21-966336249-240343522-4042860801-500 - Administrator - Disabled) Dzhemal (S-1-5-21-966336249-240343522-4042860801-1000 - Administrator - Enabled) => C:\Users\Dzhemal Guest (S-1-5-21-966336249-240343522-4042860801-501 - Limited - Disabled) => C:\Users\Guest ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/21/2014 10:43:18 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service ASP.NET (ASP.NET) failed. The first DWORD in the Data section contains the error code. Error: (11/21/2014 10:43:18 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/21/2014 00:15:11 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/21/2014 00:15:11 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/21/2014 00:08:13 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/18/2014 08:07:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/18/2014 08:07:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/18/2014 08:02:00 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/18/2014 00:28:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/18/2014 00:28:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. System errors: ============= Error: (11/21/2014 08:48:14 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:48:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:48:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:48:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:48:08 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:36:35 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:36:34 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:36:33 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 08:11:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (11/21/2014 07:52:09 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. Microsoft Office Sessions: ========================= Error: (12/11/2012 01:16:48 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 8123 seconds with 3420 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel® Pentium® CPU B940 @ 2.00GHz Percentage of memory in use: 57% Total physical RAM: 4043.86 MB Available physical RAM: 1699.19 MB Total Pagefile: 8085.9 MB Available Pagefile: 5035.25 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:342.96 GB) (Free:250.13 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:13.51 GB) (Free:1.48 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive g: (Local Disk) (Fixed) (Total:341.86 GB) (Free:140.32 GB) NTFS Drive h: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: D91F86F8) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Active) - (Size=199 MB) - (Type=42) Partition 3: (Not Active) - (Size=343 GB) - (Type=42) Partition 4: (Not Active) - (Size=355.5 GB) - (Type=42) ==================== End Of Log ============================ Благодаря!!!!
  6. Здравейте. От скоро забелязах, че двата диска C и D се пълнят без известна за мен причина.Дори понякога при диск C нямаше и един килобайт свободно пространство.Почистих ги от ненужни файлове и програми, но нямаше голям ефект. По какви ли начини не пробвах - ефекта винаги беше минимален. Последно пробвах да изчистя с програмата CCleaner и успя да ми освободи голяма част пространства при диск C и за момента нямам проблеми с него ( не знам дали отново ще се напълни ), но при диск D нямаше резултат. В момента съм най-близо до истината, че в компютъра ми има зловреден софтуер. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-11-2014 01 Ran by User (administrator) on USER-PC on 16-11-2014 16:29:33 Running from C:\Users\User\Downloads Loaded Profile: User (Available profiles: User) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Български (България) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe () C:\Program Files\Mobogenie\MgAssist.exe (Mobogenie.com) C:\Program Files\Mobogenie3\MobogenieService.exe (TorchMedia Inc.) C:\Users\User\AppData\Local\Torch\Update\TorchCrashHandler.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe (Realtek Semiconductor Corp.) C:\Windows\RTHDCPL.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files\AVG SafeGuard toolbar\vprot.exe () C:\Program Files\Mobogenie\DaemonProcess.exe () C:\Program Files\Unlocker\UnlockerAssistant.exe (Bandoo Media Inc.) C:\Users\User\AppData\Local\iLivid\iLivid.exe (Softonic) C:\Users\User\AppData\Local\Softonic\Softonic.exe () C:\Program Files\Datecs\FlexType 2K\FType2K.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (mobogenie.com) C:\Program Files\Mobogenie3\mobogenieP2sp.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDCPL] => C:\Windows\RTHDCPL.EXE [16116224 2007-02-06] (Realtek Semiconductor Corp.) HKLM\...\Run: [skyTel] => C:\Windows\SkyTel.EXE [2879488 2006-05-23] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] => C:\Windows\ALCMTR.EXE [69632 2005-05-10] (Realtek Semiconductor Corp.) HKLM\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [995184 2013-07-18] (Microsoft Corporation) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [vProt] => C:\Program Files\AVG SafeGuard toolbar\vprot.exe [2640408 2014-11-06] () HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe [748736 2014-06-01] () HKLM\...\Run: [kbdsprt] => [X] HKLM\...\Run: [unlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-04] () HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [EA Core] => "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\User\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=cfe8a617691547d39ae0d154265d5fc8-89c0334d3c6a5b62b955185ab8fbc974c007b18e /CMPID=1213b HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [iLivid] => C:\Users\User\AppData\Local\iLivid\iLivid.exe [6827008 2013-09-09] (Bandoo Media Inc.) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [softonic for Windows] => C:\Users\User\AppData\Local\Softonic\Softonic.exe [4170224 2014-04-29] (Softonic) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\MountPoints2: {66178fc2-3664-11e3-b5d3-001d60b9b63b} - G:\setup.exe HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\MountPoints2: {e59f4acc-5383-11e4-95d6-001d60b9b63b} - F:\setup.exe AppInit_DLLs: C:\PROGRA~2\Wincert\WIN32C~1.DLL => C:\PROGRA~2\Wincert\WIN32C~1.DLL File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browsemngr.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browsermngr.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe IFEO\cltmngsvc.exe: [Debugger] tasklist.exe IFEO\delta babylon.exe: [Debugger] tasklist.exe IFEO\delta tb.exe: [Debugger] tasklist.exe IFEO\delta2.exe: [Debugger] tasklist.exe IFEO\deltainstaller.exe: [Debugger] tasklist.exe IFEO\deltasetup.exe: [Debugger] tasklist.exe IFEO\deltatb.exe: [Debugger] tasklist.exe IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\iminentsetup.exe: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\rjatydimofu.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\sweetimsetup.exe: [Debugger] tasklist.exe IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FlexType 2K.lnk ShortcutTarget: FlexType 2K.lnk -> C:\Program Files\Datecs\FlexType 2K\FType2K.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Изрязване на екран и стартиране на OneNote 2007.lnk ShortcutTarget: Изрязване на екран и стартиране на OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll <===== ATTENTION ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=1235&systemid=406&v=u11465-250&apn_uid=8953571358224052&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^bg&si=pconvIE&ptb=5C62C4C4-EBC7-46CC-89A9-1CDEDF560188&ind=2014050305&n=780bf801&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKCU - {0773FA4C-3093-46A9-9E15-92E8BB088A57} URL = http://www.mysearchresults.com/search?c=8004&t=11&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=94C1001D60B9B63B&affID=128129&tsp=5147 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={F4AB6EFA-9A33-4482-97C5-19776A4B5267}&mid=cfe8a617691547d39ae0d154265d5fc8-89c0334d3c6a5b62b955185ab8fbc974c007b18e&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-0611:12:01&v=18.0.5.292&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=1235&systemid=406&v=u11465-250&apn_uid=8953571358224052&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^bg&si=pconvIE&ptb=5C62C4C4-EBC7-46CC-89A9-1CDEDF560188&ind=2014050305&n=780bf801&psa=&st=sb&searchfor={searchTerms} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Zula Games -> {2A836234-186C-41A0-9863-40BECDEDED9F} -> C:\Program Files\Zula Games\ScriptHost.dll No File BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Toolbar: HKLM - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search) Tcpip\..\Interfaces\{11412AFA-D2F1-4B36-B258-39C0F2202FC1}: [NameServer] 192.168.15.12,195.24.48.5 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: hxxp://istart.webssearches.com/?type=hp&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll No File FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: TorchVLC -> C:\Users\User\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\webssearches.xml FF Extension: VideoDownloadConverter - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\Extensions\[email protected]_4z.com [2014-11-12] FF Extension: Fast Start - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\Extensions\[email protected] [2014-07-13] FF Extension: DownloadHelper - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-15] FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\User\AppData\Roaming\Mozilla\Extensions\[email protected] FF Extension: Zula Games - C:\Users\User\AppData\Roaming\Mozilla\Extensions\[email protected] [2013-10-17] FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\User\AppData\Roaming\Mozilla\Extensions\[email protected] FF Extension: No Name - C:\Users\User\AppData\Roaming\Mozilla\Extensions\[email protected] [2013-10-17] FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799 FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799 [2014-08-28] FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\extensions\[email protected] Chrome: ======= CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (VideoDownloadConverter) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeljlhkkoipjimklndofjoafhpccdfjo [2014-08-02] CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-07] CHR HKLM\...\Chrome\Extension: [adldappccjhelkmbkpiibilgnnjakieg] - C:\Program Files\VideoDownloadConverter_4z Chrome Extension\bar\[email protected] [] CHR HKLM\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Users\User\AppData\Roaming\BabSolution\CR\BabylonChrome1.crx [] CHR HKLM\...\Chrome\Extension: [kdidombaedgpfiiedeimiebkmbilgmlc] - C:\Program Files\DefaultTab\DefaultTab.crx [] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.) S2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] R2 MgAssistService; C:\Program Files\Mobogenie\MgAssist.exe [105664 2014-07-22] () R2 MobogenieService; C:\Program Files\Mobogenie3\MobogenieService.exe [116928 2014-11-12] (Mobogenie.com) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-07-18] (Microsoft Corporation) R2 TorchCrashHandler; C:\Users\User\AppData\Local\Torch\Update\TorchCrashHandler.exe [1217032 2014-10-29] (TorchMedia Inc.) <==== ATTENTION R2 vToolbarUpdater18.1.9; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search) S3 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-08-06] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [197400 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-11] (AVG Technologies) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-10-15] (Disc Soft Ltd) R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-14] (VIA Technologies, Inc. ) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-06-14] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () S1 MpKslb3189f59; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E4CFFD5A-C876-4E80-B999-7C2C8B1B1C08}\MpKslb3189f59.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-16 16:28 - 2014-11-16 16:29 - 00022048 _____ () C:\Users\User\Downloads\Addition.txt 2014-11-16 16:27 - 2014-11-16 16:29 - 00022066 _____ () C:\Users\User\Downloads\FRST.txt 2014-11-16 16:26 - 2014-11-16 16:29 - 00000000 ____D () C:\FRST 2014-11-16 16:26 - 2014-11-16 16:26 - 01108992 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2014-11-16 16:13 - 2014-11-16 16:13 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-11-16 16:13 - 2014-11-16 16:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-11-16 16:12 - 2014-11-16 16:13 - 00000000 ____D () C:\Program Files\CCleaner 2014-11-16 16:10 - 2014-11-16 16:11 - 04976136 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup419pro.exe 2014-11-15 22:30 - 2014-11-15 22:30 - 00000011 ____R () C:\Windows\amunres.lsl 2014-11-15 22:12 - 2014-11-16 16:19 - 00000000 ____D () C:\Program Files\Steam 2014-11-15 22:10 - 2014-11-15 22:11 - 01142392 _____ () C:\Users\User\Downloads\SteamSetup.exe 2014-11-15 14:16 - 2014-11-15 14:16 - 38381556 _____ () C:\Users\User\Downloads\HideNSeek_BM.dem 2014-11-14 23:09 - 2014-11-15 13:09 - 48651703 _____ () C:\Users\User\Downloads\flipeR.dem 2014-11-13 01:53 - 2014-11-13 01:53 - 00000000 ____D () C:\Users\User\mobogenieP2sp 2014-11-06 22:11 - 2014-11-06 22:11 - 00000000 ____D () C:\ProgramData\Avg_Update_1114tb 2014-11-03 00:05 - 2014-11-03 00:05 - 00017101 _____ () C:\Users\User\Downloads\Deja.Vu.2006.480p.BRRip.AC3.BGAUDIO-SlzD.torrent 2014-11-01 14:41 - 2014-11-01 14:41 - 222995856 _____ () C:\Users\User\cstrike 2014-11-01 14-41-20-99.avi 2014-11-01 14:40 - 2014-11-01 14:40 - 220153856 _____ () C:\Users\User\cstrike 2014-11-01 14-40-25-02.avi 2014-11-01 14:39 - 2014-11-01 14:40 - 221507616 _____ () C:\Users\User\cstrike 2014-11-01 14-39-52-28.avi 2014-11-01 14:39 - 2014-11-01 14:39 - 224203344 _____ () C:\Users\User\cstrike 2014-11-01 14-39-19-88.avi 2014-11-01 14:38 - 2014-11-01 14:39 - 219093188 _____ () C:\Users\User\cstrike 2014-11-01 14-38-42-11.avi 2014-11-01 14:38 - 2014-11-01 14:38 - 215116608 _____ () C:\Users\User\cstrike 2014-11-01 14-38-09-40.avi 2014-11-01 14:37 - 2014-11-01 14:38 - 228522404 _____ () C:\Users\User\cstrike 2014-11-01 14-37-36-12.avi 2014-11-01 14:37 - 2014-11-01 14:37 - 212516652 _____ () C:\Users\User\cstrike 2014-11-01 14-37-03-47.avi 2014-11-01 14:36 - 2014-11-01 14:37 - 230608452 _____ () C:\Users\User\cstrike 2014-11-01 14-36-30-17.avi 2014-11-01 14:33 - 2014-11-01 14:33 - 16519164 _____ () C:\Users\User\cstrike 2014-11-01 14-33-08-79.avi 2014-11-01 14:31 - 2014-11-01 14:31 - 224039848 _____ () C:\Users\User\cstrike 2014-11-01 14-31-25-65.avi 2014-11-01 14:13 - 2014-11-16 16:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps 2014-11-01 14:13 - 2014-11-01 14:13 - 00036079 _____ (Beepa Pty Ltd) C:\Users\Fraps\uninstall.exe 2014-11-01 14:13 - 2014-11-01 14:13 - 00000000 ____D () C:\Users\Fraps\HELP 2014-11-01 14:12 - 2014-11-01 14:13 - 00000000 ____D () C:\Users\Fraps 2014-11-01 14:11 - 2014-11-01 14:12 - 02326976 _____ (Beepa Pty Ltd) C:\Users\User\Downloads\setup.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-16 16:27 - 2013-10-16 15:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype 2014-11-16 16:22 - 2014-04-20 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2014 2014-11-16 16:22 - 2014-03-15 19:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Custom Strike 2014-11-16 16:22 - 2013-12-16 05:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2014-11-16 16:22 - 2013-12-12 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 2014-11-16 16:22 - 2013-10-30 16:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Casino at bet365 2014-11-16 16:22 - 2013-10-20 16:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resource Hacker 2014-11-16 16:22 - 2013-10-17 15:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2014-11-16 16:22 - 2013-10-16 15:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 2014-11-16 16:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-11-16 16:19 - 2013-12-21 14:56 - 00000000 ____D () C:\Users\User\AppData\Roaming\TeamViewer 2014-11-16 16:19 - 2013-10-16 15:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\uTorrent 2014-11-16 16:19 - 2013-10-16 15:28 - 00000000 ____D () C:\Users\User\AppData\Roaming\DAEMON Tools Lite 2014-11-16 16:18 - 2014-09-13 22:05 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps 2014-11-16 16:18 - 2013-10-16 15:49 - 00000000 ____D () C:\Windows\Panther 2014-11-16 15:59 - 2013-10-16 15:31 - 00000986 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-16 15:56 - 2013-10-16 15:12 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-16 14:37 - 2013-10-16 04:53 - 01106300 ____N () C:\Windows\WindowsUpdate.log 2014-11-16 07:55 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-16 07:55 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-16 07:54 - 2010-11-20 23:01 - 00782154 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-16 07:48 - 2014-07-17 08:40 - 00000000 ____D () C:\Program Files\Mobogenie3 2014-11-16 07:48 - 2014-02-06 10:25 - 00000000 ____D () C:\ProgramData\TorchCrashHandler 2014-11-16 07:48 - 2013-10-16 16:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-11-16 07:48 - 2013-10-16 15:31 - 00000982 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-16 07:48 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-15 22:30 - 2014-09-05 03:25 - 00000000 ____D () C:\Users\User\AppData\Roaming\Software Informer 2014-11-15 22:12 - 2014-02-06 17:52 - 00000921 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-11-14 22:22 - 2014-09-30 15:03 - 00000000 ____D () C:\Program Files\mozilla firefox 2014-11-13 23:56 - 2013-10-16 15:12 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-13 23:56 - 2013-10-16 15:12 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-10 23:06 - 2014-10-16 14:53 - 00000749 _____ () C:\Users\User\Desktop\Нов текстов документ.txt 2014-11-06 22:11 - 2014-08-28 13:53 - 00000000 ____D () C:\Program Files\AVG Security Toolbar 2014-11-05 10:54 - 2014-06-13 04:39 - 00002000 _____ () C:\Users\Public\Desktop\Google Slides.lnk 2014-11-05 10:54 - 2014-06-13 04:39 - 00001998 _____ () C:\Users\Public\Desktop\Google Sheets.lnk 2014-11-05 10:54 - 2014-06-13 04:39 - 00001988 _____ () C:\Users\Public\Desktop\Google Docs.lnk 2014-11-05 10:54 - 2014-01-27 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-11-04 10:51 - 2014-03-29 11:56 - 00000069 _____ () C:\Windows\NeroDigital.ini 2014-11-03 21:41 - 2014-02-06 10:24 - 00000000 ____D () C:\Users\User\AppData\Local\Torch 2014-11-03 21:40 - 2014-02-06 10:25 - 00001206 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk 2014-11-03 21:23 - 2013-11-28 23:17 - 00000000 ____D () C:\Windows\Minidump 2014-10-30 13:24 - 2013-10-16 15:28 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-27 23:55 - 2014-06-03 15:33 - 00002327 _____ () C:\Users\Public\Desktop\Google Chrome.lnk Files to move or delete: ==================== C:\Users\Fraps\fraps.exe C:\Users\Fraps\fraps32.dll C:\Users\Fraps\fraps64.dat C:\Users\Fraps\fraps64.dll C:\Users\Fraps\frapslcd.dll C:\Users\Fraps\uninstall.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-15 04:51 ==================== End Of Log ============================ Addition_16-11-2014_16-30-43.txt
  7. Здравейте имам странен проблем с компютъра,например като чатя във фейсбук или скайп започва да праща някакви линкове,също така работи бавно и не се показват целите прозорци. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:06-08-2015 Ran by W (administrator) on W-F081D34368844 (07-08-2015 12:39:14) Running from C:\Documents and Settings\W\Desktop Loaded Profiles: W (Available Profiles: W & Administrator) Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe () C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe (Skype Technologies S.A.) C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe () C:\Program Files\TeamViewer3\TeamViewer_Host.exe (TeamViewer GmbH) C:\Program Files\TeamViewer3\TeamViewer.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe () C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe () C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) C:\WINDOWS\system32\osk.exe (Microsoft Corporation) C:\WINDOWS\system32\msswchx.exe (IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [14854144 2005-09-22] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [igfxhkcmd] => C:\WINDOWS\system32\hkcmd.exe [77824 2005-09-20] (Intel Corporation) HKLM\...\Run: [igfxpers] => C:\WINDOWS\system32\igfxpers.exe [114688 2005-09-20] (Intel Corporation) HKLM\...\Run: [bluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent HKLM\...\Run: [btTray] => C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe [278016 2009-02-27] () HKLM\...\Run: [] => [X] HKU\S-1-5-19\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-19\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-20\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-20\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-21-1757981266-1004336348-1606980848-1003\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [53288576 2015-06-30] (Skype Technologies S.A.) HKU\S-1-5-21-1757981266-1004336348-1606980848-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKU\S-1-5-21-1757981266-1004336348-1606980848-1003\...\Run: [Google Update] => C:\Documents and Settings\W\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [107912 2014-10-27] (Google Inc.) HKU\S-1-5-18\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-18\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-18\...\RunOnce: [RunNarrator] => C:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-1757981266-1004336348-1606980848-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.mail.ru/?ieverfix=1&fr=ieverfix_sg HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1757981266-1004336348-1606980848-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-1757981266-1004336348-1606980848-1003 -> {105E99FF-8B9A-4492-B155-06194B9056D2} URL = http://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1757981266-1004336348-1606980848-1003 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = http://go.mail.ru/search?q={SearchTerms}&ieverfix=1&fr=ieverfix_dse BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2015-07-06] (IObit) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12] (Microsoft Corporation) BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-12] (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 89.215.233.2 89.215.246.40 Tcpip\..\Interfaces\{A0223CA6-B160-42B4-A7BB-61FD22352FCD}: [DhcpNameServer] 89.215.233.2 89.215.246.40 FireFox: ======== FF ProfilePath: C:\Documents and Settings\W\Application Data\Mozilla\Firefox\Profiles\7iz7rnn2.default FF SelectedSearchEngine: Поиск@Mail.Ru FF Homepage: google.bg FF Keyword.URL: hxxp://go.mail.ru/search?fr=ntg&q= FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-07-06] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1203133.dll [2013-06-26] (Adobe Systems, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin HKU\S-1-5-21-1757981266-1004336348-1606980848-1003: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\W\Local Settings\Application Data\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.) FF Plugin HKU\S-1-5-21-1757981266-1004336348-1606980848-1003: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\W\Local Settings\Application Data\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-02-27] FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-02-27] FF Extension: Address Bar Search - C:\Documents and Settings\W\Application Data\Mozilla\Firefox\Profiles\7iz7rnn2.default\Extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} [2014-10-29] FF Extension: Adblock Plus - C:\Documents and Settings\W\Application Data\Mozilla\Firefox\Profiles\7iz7rnn2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-06] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-07] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-07] Chrome: ======= CHR Profile: C:\Documents and Settings\W\Local Settings\Application Data\Google\Chrome\User Data\Default CHR Extension: (Skype Click to Call) - C:\Documents and Settings\W\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-08-06] CHR Extension: (Google Wallet) - C:\Documents and Settings\W\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-22] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-05-14] StartMenuInternet: chrome.exe - C:\Documents and Settings\W\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 BlueSoleilCS; C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe [850432 2009-02-27] () [File not signed] R3 BsHelpCS; C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe [98407 2009-02-27] () [File not signed] R2 BsMobileCS; C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe [143467 2009-02-27] () [File not signed] S2 HidServ; C:\WINDOWS\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation) S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit) R2 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3290304 2012-11-22] (Skype Technologies S.A.) R2 TeamViewer; C:\Program Files\TeamViewer3\TeamViewer_Host.exe [94208 2008-01-28] () [File not signed] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [14088 2008-12-07] (IVT Corporation.) S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [39304 2009-01-03] (IVT Corporation.) R0 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [20744 2009-01-07] (IVT Corporation.) R3 btnetBUs; C:\WINDOWS\System32\Drivers\btnetBus.sys [30088 2008-12-07] () S3 BTNetFilter; C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys [22416 2006-11-22] (IVT Corporation.) R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [232512 2012-04-03] (DT Soft Ltd) R3 IvtBtBUs; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [26248 2008-07-02] (IVT Corporation.) R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [15808 2013-12-24] (IObit) R3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [14856 2008-01-21] (IVT Corporation.) R3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [31880 2009-01-08] (IVT Corporation.) R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [223104 2004-10-27] (Marvell) S3 ALSysIO; \??\C:\DOCUME~1\W\LOCALS~1\Temp\ALSysIO.sys [X] U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [33800 2008-11-25] (IVT Corporation.) S4 IntelIde; No ImagePath U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-07 12:39 - 2015-08-07 12:39 - 00012145 _____ C:\Documents and Settings\W\Desktop\FRST.txt 2015-08-07 12:39 - 2015-08-07 12:39 - 00000000 ____D C:\FRST 2015-08-07 12:37 - 2015-08-07 12:37 - 01673728 _____ (Farbar) C:\Documents and Settings\W\Desktop\FRST.exe 2015-08-07 10:56 - 2015-08-07 12:35 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-08-06 11:04 - 2015-08-06 11:13 - 00004839 _____ C:\WINDOWS\setupapi.log ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-07 12:39 - 2015-07-06 18:05 - 00000000 ____D C:\Documents and Settings\W\Local Settings\Temp 2015-08-07 12:38 - 2015-05-31 20:03 - 00000000 ____D C:\Documents and Settings\W\My Documents\Изтегляния 2015-08-07 12:35 - 2012-04-25 20:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-08-07 12:35 - 2012-03-31 18:44 - 00422658 _____ C:\WINDOWS\WindowsUpdate.log 2015-08-07 12:33 - 2012-03-31 21:36 - 00360124 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-08-07 12:30 - 2012-06-28 10:13 - 00006244 _____ C:\WINDOWS\system32\LOCALSERVICE.INI 2015-08-07 12:30 - 2012-03-31 19:11 - 00000000 ____D C:\WINDOWS\system32\Lang 2015-08-07 12:29 - 2014-02-13 22:07 - 00000270 _____ C:\WINDOWS\Tasks\SmartDefrag3_Update.job 2015-08-07 12:29 - 2012-03-31 19:21 - 00000982 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-08-07 12:29 - 2012-03-31 18:56 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-08-07 12:29 - 2009-02-27 17:04 - 00001047 _____ C:\WINDOWS\system32\bscs.ini 2015-08-07 11:05 - 2015-07-06 14:08 - 00032644 _____ C:\WINDOWS\SchedLgU.Txt 2015-08-07 11:05 - 2012-03-31 18:57 - 00000178 ___SH C:\Documents and Settings\W\ntuser.ini 2015-08-07 11:01 - 2012-03-31 19:21 - 00000986 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-08-07 10:54 - 2012-09-15 13:00 - 00001010 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1004336348-1606980848-1003Core1cd9328f877505a.job 2015-08-07 10:54 - 2012-03-31 22:21 - 00001062 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1004336348-1606980848-1003UA.job 2015-08-06 16:02 - 2012-04-01 19:29 - 00000000 ____D C:\Documents and Settings\W\Application Data\Skype 2015-08-06 10:56 - 2012-03-31 22:22 - 00002250 _____ C:\Documents and Settings\W\Desktop\Google Chrome.lnk 2015-08-05 20:16 - 2001-08-23 10:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2015-08-04 15:58 - 2015-07-06 18:09 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ProductData 2015-07-26 13:17 - 2013-03-14 21:48 - 00000182 _____ C:\drwtsn32.log 2015-07-23 15:06 - 2012-04-03 14:12 - 00000000 ____D C:\Program Files\TeamViewer3 2015-07-17 22:03 - 2015-05-29 20:15 - 00000286 _____ C:\WINDOWS\Tasks\Program Manager.job 2015-07-10 14:46 - 2012-05-10 11:58 - 00000000 ____D C:\Documents and Settings\W\Desktop\imoti ==================== Files in the root of some directories ======= 2012-04-04 20:59 - 2015-02-17 18:21 - 0016896 _____ () C:\Documents and Settings\W\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End of log ============================ Addition.txt
  8. Здравейте, от няколко дни когато стартирам фаерфокса като начална страница ми зарежда delta-home, и други които аз не желая.При сканиране с Malwarebytes Anti-Malware откри около 60 проблема.Имам диск. Това е съдържанието на файла от FRST: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015 Ran by Boriv (administrator) on BORIS on 14-06-2015 08:47:50 Running from C:\Users\Boriv\Desktop Loaded Profiles: Boriv (Available Profiles: Boriv & Hristina) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Английски (Съединени щати) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Firebird Project) C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe (XTab system) C:\Program Files\MiuiTab\ProtectService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Nitro PDF Software) C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe (TODO: <公司名>) C:\Users\Boriv\AppData\Everything\ServiceEverything.exe (Software 2000 Limited) C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE (Firebird Project) C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe () C:\Users\Boriv\AppData\Everything\SFKEX.exe () C:\Users\Boriv\AppData\Everything\SearchBase.exe () C:\Users\Boriv\AppData\Everything\everything.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\tsnp2std.exe (Sonix) C:\Windows\vsnp2std.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (BitTorrent Inc.) C:\Users\Boriv\AppData\Roaming\uTorrent\uTorrent.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe () C:\Users\Boriv\AppData\Local\Viber\Viber.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Corporation) C:\Windows\System32\icacls.exe (LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\Update\SmartShareTray.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [tsnp2std] => C:\Windows\tsnp2std.exe [262144 2006-05-22] () HKLM\...\Run: [snp2std] => C:\Windows\vsnp2std.exe [675840 2006-05-15] (Sonix) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKU\S-1-5-21-1421139271-3807526133-746366484-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1421139271-3807526133-746366484-1001\...\Run: [uTorrent] => C:\Users\Boriv\AppData\Roaming\uTorrent\uTorrent.exe [1694560 2015-05-07] (BitTorrent Inc.) HKU\S-1-5-21-1421139271-3807526133-746366484-1001\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [28785792 2015-06-02] (Skype Technologies S.A.) HKU\S-1-5-21-1421139271-3807526133-746366484-1001\...\Run: [Viber] => C:\Users\Boriv\AppData\Local\Viber\Viber.exe [80036560 2015-05-25] () HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-12-22] (Microsoft Corporation) Startup: C:\Users\Boriv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Изрязване на екран и стартиране на OneNote 2007.lnk [2015-01-30] ShortcutTarget: Изрязване на екран и стартиране на OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1434011380&z=e5999adf96ef3125d60ea8ag6z7cazbe5g1g7c2bac&from=ient06110&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1420138572&from=kmp&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1434011380&z=e5999adf96ef3125d60ea8ag6z7cazbe5g1g7c2bac&from=ient06110&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1420138572&from=kmp&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6&q={searchTerms} HKU\S-1-5-21-1421139271-3807526133-746366484-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1434011380&z=e5999adf96ef3125d60ea8ag6z7cazbe5g1g7c2bac&from=ient06110&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6&q={searchTerms} HKU\S-1-5-21-1421139271-3807526133-746366484-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1434011380&z=e5999adf96ef3125d60ea8ag6z7cazbe5g1g7c2bac&from=ient06110&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6 HKU\S-1-5-21-1421139271-3807526133-746366484-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp HKU\S-1-5-21-1421139271-3807526133-746366484-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1434011380&z=e5999adf96ef3125d60ea8ag6z7cazbe5g1g7c2bac&from=ient06110&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6 HKU\S-1-5-21-1421139271-3807526133-746366484-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1434011380&z=e5999adf96ef3125d60ea8ag6z7cazbe5g1g7c2bac&from=ient06110&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6&q={searchTerms} SearchScopes: HKU\S-1-5-21-1421139271-3807526133-746366484-1001 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1421139271-3807526133-746366484-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1421139271-3807526133-746366484-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1421139271-3807526133-746366484-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1421139271-3807526133-746366484-1001 -> {516AB8DC-6CDF-43FA-B250-1817B5F25C5B} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1421139271-3807526133-746366484-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} BHO: LuckyTab Class -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> C:\Program Files\MiuiTab\SupTab.dll No File BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation) Tcpip\..\Interfaces\{3FB6B7E9-CDEE-4B8E-8123-60E10B838DDC}: [NameServer] 46.40.72.9,46.40.72.13 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1420138572&from=kmp&uid=ST3320620AS_9QF8MPW6XXXX9QF8MPW6 FireFox: ======== FF ProfilePath: C:\Users\Boriv\AppData\Roaming\Mozilla\Firefox\Profiles\lwd4qy02.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: delta-homes FF SelectedSearchEngine: delta-homes FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-03] () FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Pro 8\npnitromozilla.dll [2013-07-24] (Nitro PDF) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2014-11-26] FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2014-11-26] FF Extension: QuickSearch - C:\Users\Boriv\AppData\Roaming\Mozilla\Firefox\Profiles\lwd4qy02.default\Extensions\[email protected] [2015-06-11] FF Extension: Search Enginer - C:\Users\Boriv\AppData\Roaming\Mozilla\Firefox\Profiles\lwd4qy02.default\Extensions\[email protected] [2015-06-11] FF Extension: signTextJS - C:\Users\Boriv\AppData\Roaming\Mozilla\Firefox\Profiles\lwd4qy02.default\Extensions\[email protected] [2015-01-30] FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\Boriv\AppData\Roaming\Mozilla\Firefox\Profiles\lwd4qy02.default\extensions\[email protected] FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\Boriv\AppData\Roaming\Mozilla\Firefox\Profiles\lwd4qy02.default\extensions\[email protected] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe [98304 2010-09-17] (Firebird Project) [File not signed] R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe [3735552 2010-09-17] (Firebird Project) [File not signed] R2 IHProtect Service; C:\Program Files\MiuiTab\ProtectService.exe [125056 2015-06-11] (XTab system) R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation) R2 NitroDriverReadSpool8; C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe [196616 2013-07-24] (Nitro PDF Software) R2 ServiceEverything; C:\Users\Boriv\AppData\Everything\ServiceEverything.exe [295624 2015-06-11] (TODO: <公司名>) R3 TermService; C:\Windows\System32\termsrv.dll [523776 2014-12-22] (Microsoft Corporation) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-22] (Disc Soft Ltd) R3 ip100Avista; C:\Windows\System32\DRIVERS\ipfnd51.sys [31232 2010-11-23] (IC Plus Corp. ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [204432 2012-06-05] (Realtek Semiconductor Corp.) R3 SNP2STD; C:\Windows\System32\DRIVERS\snp2sxp.sys [10305280 2006-06-07] () [File not signed] R1 MpKslbf6b7b5a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1A8B2B79-CB1F-45D6-AF0B-60A3283009D1}\MpKslbf6b7b5a.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-14 08:47 - 2015-06-14 08:49 - 00014291 _____ C:\Users\Boriv\Desktop\FRST.txt 2015-06-14 08:46 - 2015-06-14 08:46 - 00000000 ____D C:\Users\Boriv\Desktop\FRST-OlderVersion 2015-06-14 08:21 - 2015-06-14 08:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-06-14 08:20 - 2015-06-14 08:20 - 00001060 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-06-14 08:20 - 2015-06-14 08:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-06-14 08:20 - 2015-06-14 08:20 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-06-14 08:20 - 2015-06-14 08:20 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware 2015-06-14 08:20 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-14 08:20 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-14 08:20 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-14 08:08 - 2015-06-14 08:08 - 35247384 _____ (Microsoft Corporation) C:\Users\Boriv\Desktop\mpas-fe.exe 2015-06-13 17:32 - 2015-06-13 17:32 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Boriv\Desktop\mbam-setup-2.1.6.1022.exe 2015-06-11 14:50 - 2015-06-11 14:59 - 00852480 _____ C:\Users\Hristina\Desktop\ценоразпис 06-15.xls 2015-06-11 14:10 - 2015-06-14 08:48 - 00000000 ____D C:\FRST 2015-06-11 14:08 - 2015-06-14 08:46 - 01148416 _____ (Farbar) C:\Users\Boriv\Desktop\FRST.exe 2015-06-11 11:30 - 2015-06-14 08:45 - 00000000 ____D C:\Program Files\MiuiTab 2015-06-11 11:30 - 2015-06-14 08:42 - 00000000 ____D C:\Users\Boriv\AppData\Everything 2015-06-11 11:30 - 2015-06-11 11:30 - 00000000 ____D C:\ProgramData\IHProtectUpDate 2015-06-10 20:54 - 2015-06-10 20:54 - 00000000 ____D C:\Users\Boriv\AppData\Roaming\Rovio Entertainment Ltd 2015-06-10 08:45 - 2015-06-10 08:45 - 00001937 _____ C:\Users\Hristina\Desktop\фтб 10.06.xls 2015-06-10 08:44 - 2015-06-10 08:44 - 00006316 _____ C:\Users\Hristina\Desktop\валер 10.06.xls 2015-06-10 06:15 - 2015-05-25 20:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-10 06:14 - 2015-06-02 22:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-10 06:14 - 2015-05-27 17:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-10 06:14 - 2015-05-23 06:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-10 06:14 - 2015-05-23 06:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 06:14 - 2015-05-23 06:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-10 06:14 - 2015-05-23 06:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-10 06:14 - 2015-05-23 06:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-10 06:14 - 2015-05-23 06:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-10 06:14 - 2015-05-23 06:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-10 06:14 - 2015-05-23 06:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-10 06:14 - 2015-05-23 06:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-10 06:14 - 2015-05-23 06:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-10 06:14 - 2015-05-23 06:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-10 06:14 - 2015-05-23 06:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-10 06:14 - 2015-05-23 06:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-10 06:14 - 2015-05-23 06:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-10 06:14 - 2015-05-23 06:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-10 06:14 - 2015-05-23 06:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 06:14 - 2015-05-23 05:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-10 06:14 - 2015-05-23 05:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 06:14 - 2015-05-23 05:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-10 06:14 - 2015-05-23 05:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-10 06:14 - 2015-05-23 05:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-10 06:14 - 2015-05-23 05:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-10 06:14 - 2015-05-23 05:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-10 06:14 - 2015-05-23 05:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-10 06:14 - 2015-05-23 05:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-10 06:14 - 2015-05-23 05:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-10 06:14 - 2015-05-23 05:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-10 06:14 - 2015-05-23 05:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-10 06:14 - 2015-05-23 05:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-10 06:14 - 2015-05-23 05:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-10 06:13 - 2015-05-09 06:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-10 06:13 - 2015-05-09 06:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-10 06:13 - 2015-05-09 06:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-10 06:13 - 2015-05-09 06:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-10 06:13 - 2015-05-09 06:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 04:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 04:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 06:13 - 2015-05-09 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 06:13 - 2015-04-29 21:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-10 06:13 - 2015-04-29 21:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-10 06:13 - 2015-04-29 21:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-10 06:13 - 2015-04-29 21:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-10 06:13 - 2015-04-29 21:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-10 06:13 - 2015-04-24 20:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-03 08:54 - 2015-06-03 08:54 - 00006867 _____ C:\Users\Hristina\Desktop\валери 04.06.xls 2015-06-03 08:50 - 2015-06-03 08:53 - 00002312 _____ C:\Users\Hristina\Desktop\фтб 04.06.xls 2015-06-02 19:26 - 2015-06-04 07:39 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-05-28 19:54 - 2015-05-28 19:54 - 00000000 ____D C:\Users\Boriv\Documents\My Games 2015-05-28 19:54 - 2015-05-28 19:54 - 00000000 ____D C:\ProgramData\Steam 2015-05-28 19:54 - 2015-05-28 19:54 - 00000000 ____D C:\ProgramData\Package Cache 2015-05-28 19:54 - 2015-05-28 19:54 - 00000000 ____D C:\ProgramData\Codemasters 2015-05-28 19:53 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2015-05-28 19:53 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2015-05-28 19:53 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2015-05-28 19:53 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2015-05-28 19:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2015-05-28 19:53 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2015-05-28 19:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2015-05-28 19:53 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2015-05-28 19:53 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2015-05-28 19:53 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2015-05-28 19:53 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2015-05-28 19:53 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2015-05-28 19:53 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2015-05-28 19:53 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2015-05-28 19:53 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2015-05-28 19:53 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2015-05-28 19:53 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2015-05-28 19:53 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2015-05-28 19:53 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2015-05-28 19:53 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2015-05-28 19:53 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2015-05-28 19:53 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2015-05-28 19:53 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2015-05-28 19:53 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2015-05-28 19:53 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2015-05-28 19:53 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2015-05-28 19:53 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2015-05-28 19:53 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2015-05-28 19:53 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2015-05-28 19:53 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2015-05-28 19:53 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2015-05-28 19:53 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2015-05-28 19:53 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2015-05-28 19:53 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2015-05-28 19:53 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2015-05-28 19:53 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2015-05-28 19:53 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2015-05-28 19:53 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2015-05-28 19:53 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2015-05-28 19:53 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2015-05-28 19:53 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2015-05-28 19:53 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2015-05-28 19:53 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2015-05-28 19:53 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2015-05-28 19:53 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2015-05-28 19:53 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2015-05-28 19:53 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2015-05-28 19:53 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2015-05-28 19:53 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2015-05-28 19:53 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2015-05-28 19:53 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2015-05-28 19:53 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2015-05-28 19:53 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2015-05-28 19:53 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2015-05-28 19:53 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2015-05-28 19:53 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2015-05-28 19:53 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2015-05-28 19:53 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2015-05-28 19:53 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2015-05-28 19:53 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2015-05-28 19:53 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2015-05-28 19:53 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2015-05-28 19:53 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2015-05-28 19:53 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2015-05-28 19:53 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2015-05-28 19:53 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2015-05-28 19:53 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2015-05-28 19:53 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2015-05-28 19:53 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2015-05-28 19:53 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2015-05-28 19:53 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2015-05-28 19:53 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2015-05-28 19:53 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2015-05-28 19:53 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2015-05-28 19:53 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2015-05-28 19:53 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2015-05-28 19:53 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2015-05-28 19:53 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2015-05-28 19:53 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2015-05-28 19:53 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2015-05-28 19:53 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2015-05-28 19:53 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2015-05-28 19:53 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2015-05-28 19:53 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2015-05-28 19:53 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2015-05-28 19:53 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2015-05-28 19:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2015-05-28 19:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2015-05-28 19:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2015-05-28 19:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2015-05-28 19:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2015-05-28 08:11 - 2015-05-28 19:53 - 00000000 ____D C:\Windows\system32\directx 2015-05-28 08:10 - 2015-05-28 08:10 - 00000649 _____ C:\Users\Boriv\Desktop\GRID Autosport.lnk 2015-05-28 08:10 - 2015-05-28 08:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GRID Autosport 2015-05-27 18:22 - 2015-05-27 18:23 - 00000000 ____D C:\Users\Hristina\Desktop\Стари данни Firefox 2015-05-25 14:28 - 2015-05-25 14:33 - 202332568 _____ C:\Users\Boriv\Desktop\555555.rar ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-14 08:50 - 2014-12-22 01:36 - 00000000 ____D C:\Users\Boriv\AppData\Roaming\uTorrent 2015-06-14 08:47 - 2014-12-22 10:12 - 01712113 _____ C:\Windows\WindowsUpdate.log 2015-06-14 08:46 - 2015-02-14 12:43 - 00000000 ____D C:\Users\Boriv\AppData\Roaming\ViberPC 2015-06-14 08:46 - 2014-12-24 14:11 - 00000000 ____D C:\Users\Boriv\AppData\Roaming\Skype 2015-06-14 08:44 - 2014-12-22 00:33 - 00009196 _____ C:\Windows\PFRO.log 2015-06-14 08:44 - 2009-07-14 07:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-14 08:44 - 2009-07-14 07:39 - 00031317 _____ C:\Windows\setupact.log 2015-06-13 21:28 - 2009-07-14 07:34 - 00022448 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-13 21:28 - 2009-07-14 07:34 - 00022448 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-13 18:31 - 2014-12-22 02:12 - 00000000 ____D C:\ProgramData\firebird 2015-06-13 16:57 - 2014-12-22 21:13 - 00007597 _____ C:\Users\Boriv\AppData\Local\Resmon.ResmonCfg 2015-06-12 14:01 - 2014-12-24 09:41 - 00000000 __SHD C:\Users\Boriv\AppData\Local\EmieUserList 2015-06-12 14:01 - 2014-12-24 09:41 - 00000000 __SHD C:\Users\Boriv\AppData\Local\EmieSiteList 2015-06-12 14:01 - 2014-12-24 09:41 - 00000000 __SHD C:\Users\Boriv\AppData\Local\EmieBrowserModeList 2015-06-11 17:28 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\NDF 2015-06-11 15:02 - 2015-01-07 10:13 - 00000000 ____D C:\Users\Hristina\AppData\Roaming\Skype 2015-06-11 11:29 - 2015-01-01 22:00 - 00000000 ____D C:\ProgramData\IePluginServices 2015-06-11 11:29 - 2014-12-22 00:37 - 00001411 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-06-11 11:29 - 2014-12-22 00:37 - 00001399 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-06-11 11:29 - 2014-12-22 00:17 - 00001707 _____ C:\Users\Boriv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-06-11 07:57 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\rescache 2015-06-11 07:06 - 2009-07-14 07:33 - 00414560 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-11 07:04 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\bg-BG 2015-06-10 23:45 - 2014-12-22 01:25 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-10 23:44 - 2014-12-22 00:38 - 00000000 ____D C:\Windows\system32\MRT 2015-06-10 23:40 - 2014-12-22 00:38 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-06 07:32 - 2014-12-24 14:10 - 00000000 ____D C:\ProgramData\Skype 2015-06-04 07:39 - 2014-12-22 00:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-06-03 06:55 - 2014-12-22 01:29 - 00000000 ____D C:\Users\Boriv\AppData\Local\Adobe 2015-06-03 06:53 - 2014-12-22 01:31 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-06-03 06:53 - 2014-12-22 01:31 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-06-02 22:35 - 2015-01-01 21:52 - 00000000 ____D C:\The KMPlayer 2015-06-02 22:11 - 2014-12-22 00:21 - 00726316 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-02 11:22 - 2015-02-17 12:06 - 00086016 _____ C:\Users\Hristina\Desktop\OT4ET MAGAZIN 2015.xls 2015-05-29 09:08 - 2015-02-14 12:43 - 00000993 _____ C:\Users\Boriv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk 2015-05-29 09:08 - 2015-02-14 12:43 - 00000985 _____ C:\Users\Boriv\Desktop\Viber.lnk 2015-05-29 09:08 - 2015-02-14 12:43 - 00000000 ____D C:\Users\Boriv\AppData\Local\Viber 2015-05-28 19:52 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\Microsoft.NET 2015-05-26 21:21 - 2015-04-02 18:01 - 195762745 _____ C:\Users\Boriv\Desktop\Navteq_Greece_2014.09.rar 2015-05-20 12:35 - 2015-05-14 22:50 - 00000000 ____D C:\Users\Boriv\AppData\Roaming\Nitro PDF 2015-05-18 10:49 - 2015-04-22 18:28 - 00000000 ____D C:\Users\Boriv\Desktop\Scener ==================== Files in the root of some directories ======= 2014-12-22 21:13 - 2015-06-13 16:57 - 0007597 _____ () C:\Users\Boriv\AppData\Local\Resmon.ResmonCfg Some files in TEMP: ==================== C:\Users\Boriv\AppData\Local\Temp\bitool.dll C:\Users\Boriv\AppData\Local\Temp\InitBDE.exe C:\Users\Boriv\AppData\Local\Temp\KMP_3.9.1.131.exe C:\Users\Boriv\AppData\Local\Temp\ose00000.exe C:\Users\Boriv\AppData\Local\Temp\SimBundD.exe C:\Users\Boriv\AppData\Local\Temp\SkypeSetup.exe C:\Users\Hristina\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-13 14:34 ==================== End of log ============================ Addition.txt
  9. Всеки ден като си пусна компютъра Malwarebytes Anti-Malware открива като заплаха вируса,който е посочен в заглавието на тази тема.Всеки път го слагам под карантина и на другия ден пак същата история.Не разполагам с компакт диск за моята операционна система. Съдържанието на файла FRST.txt ---> Addition.txt Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-05-2015 Ran by danitooo (administrator) on DANITOOO-PC on 10-05-2015 21:32:35 Running from C:\Users\danitooo\Downloads Loaded Profiles: danitooo & UpdatusUser (Available profiles: danitooo & UpdatusUser) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe (Skillbrains) C:\Program Files\Skillbrains\lightshot\5.2.1.1\Lightshot.exe () C:\Program Files\RocketDock\RocketDock.exe (BitTorrent Inc.) C:\Users\danitooo\AppData\Roaming\uTorrent\uTorrent.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winamp.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-07] (AVAST Software) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12111576 2015-01-25] (Realtek Semiconductor) HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] () HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\Run: [Advanced SystemCare 8] => C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe [2429728 2015-04-08] (IObit) HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\Run: [uTorrent] => C:\Users\danitooo\AppData\Roaming\uTorrent\uTorrent.exe [1742928 2015-03-04] (BitTorrent Inc.) HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd) HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\MountPoints2: {052dd93d-eb45-11e3-84ab-001e9048b044} - E:\Autorun.exe HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\MountPoints2: {052dd946-eb45-11e3-84ab-001e9048b044} - E:\SETUP.EXE HKU\S-1-5-21-3170674983-682481904-2544561987-1001\...\MountPoints2: {c165d3ac-c00b-11e3-8e0d-001e9048b044} - E:\Autorun.exe IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\ChangeIcon.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\DriverBooster.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\IObitDownloader.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\MakeSFX.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\Promote.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\Scheduler.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\SetupHlp.exe: [Debugger] C:\Program Files\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2014-08-07] (AVAST Software) BootExecute: autocheck autochk * SmartDefragBootTime.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-3170674983-682481904-2544561987-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = SearchScopes: HKU\S-1-5-21-3170674983-682481904-2544561987-1001 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = SearchScopes: HKU\S-1-5-21-3170674983-682481904-2544561987-1001 -> {5B9026C0-EAE3-46E1-8B86-56DDA1A6D821} URL = http://search.us.com/serp?guid={EE5D42FD-60EC-4AAD-8B86-81EAE235F6C7}&action=default_search&k={searchTerms} SearchScopes: HKU\S-1-5-21-3170674983-682481904-2544561987-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = SearchScopes: HKU\S-1-5-21-3170674983-682481904-2544561987-1001 -> {A5886355-8636-48EF-8242-33B8EF5D1AA7} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10513 SearchScopes: HKU\S-1-5-21-3170674983-682481904-2544561987-1001 -> {AA12B683-D02A-484C-9700-AAAEFBB5A2A9} URL = http://search.us.com/serp?guid={5224BF52-C871-4857-80DB-31F6ECDAEA44}&action=default_search&k={searchTerms} SearchScopes: HKU\S-1-5-21-3170674983-682481904-2544561987-1001 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> No File BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2015-02-10] (IObit) BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation) BHO: No Name -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> No File BHO: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11] (Adblock) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit) BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\..\Interfaces\{42C8C059-8EB6-45F6-8D21-F808FF8DCBFA}: [NameServer] 89.215.246.40 89.215.233.2 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-14] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1217157.dll [2015-02-16] (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll No File FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-29] (Adobe Systems) FF Plugin HKU\S-1-5-21-3170674983-682481904-2544561987-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\danitooo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-20] (Unity Technologies ApS) FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-07] Chrome: ======= CHR HomePage: Default -> hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=C055001E9048B044&affID=128403&tsp=5212 CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Profile: C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-22] CHR Extension: (Google Drive) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-22] CHR Extension: (YouTube) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-22] CHR Extension: (Google Search) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-22] CHR Extension: (Blur) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2015-03-26] CHR Extension: (AdBlock) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-11-30] CHR Extension: (Bookmark Manager) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16] CHR Extension: (Avast Online Security) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-22] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13] CHR Extension: (Google Wallet) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-22] CHR Extension: (video2mp3) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oljlcbniifdjapjocdfamhlnmpkojdkm [2014-12-06] CHR Extension: (Gmail) - C:\Users\danitooo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-22] CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-07] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-07] (AVAST Software) R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S4 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [344864 2015-01-27] (IObit) S4 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-03-26] (IObit) R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2014-03-12] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-08-07] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-08-07] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-08-07] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-08-07] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-11-22] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-08-07] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [71944 2014-08-07] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-08-07] () S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-08-29] (Windows ® Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-06-04] (Disc Soft Ltd) S4 FileMonitor; C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [21480 2014-11-10] (IObit) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-01-03] (REALiX) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-10] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation) S3 RegFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [32288 2014-11-10] (IObit.com) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18624 2014-06-04] (IObit) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project) S3 UrlFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [20944 2014-11-10] (IObit.com) S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 vtany; \??\C:\Windows\vtany.sys [X] S3 XDva405; \??\C:\Windows\system32\XDva405.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-10 21:32 - 2015-05-10 21:33 - 00018392 _____ () C:\Users\danitooo\Downloads\FRST.txt 2015-05-10 21:32 - 2015-05-10 21:32 - 00000000 ____D () C:\FRST 2015-05-10 21:31 - 2015-05-10 21:32 - 01141248 _____ (Farbar) C:\Users\danitooo\Downloads\FRST.exe 2015-05-10 03:56 - 2015-05-10 03:56 - 00006596 _____ () C:\Users\danitooo\Downloads\BabyGotBoobs - Anya Ivy.torrent 2015-05-10 03:55 - 2015-05-10 03:55 - 00011609 _____ () C:\Users\danitooo\Downloads\BigTitCreamPie - Peta Jensen.torrent 2015-05-10 03:53 - 2015-05-10 03:53 - 00016165 _____ () C:\Users\danitooo\Downloads\CFNMSecret - Annika Albrite, Peta Jensen.torrent 2015-05-10 03:50 - 2015-05-10 03:50 - 00019829 _____ () C:\Users\danitooo\Downloads\MyWifesHotFriend - August Ames.torrent 2015-05-10 01:43 - 2015-05-10 01:43 - 00001020 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-05-09 20:57 - 2015-05-09 20:57 - 00027840 _____ () C:\Users\danitooo\Downloads\American_Pie_UNRATED_1999_720p_BluRay_DTS_x264_CtrlHD.(subs.sab.bz).rar 2015-05-09 20:57 - 2015-05-09 20:57 - 00011287 _____ () C:\Users\danitooo\Downloads\American.Pie.1999.UNRATED.BRRip.XviD.AC3.YeeP.torrent 2015-05-09 20:52 - 2015-05-09 20:52 - 00011918 _____ () C:\Users\danitooo\Downloads\American.Pie.6.Beta.House.2007.DVDRip.XviD.AC3.BGAUDIO-SlzD.torrent 2015-05-09 02:22 - 2015-05-09 02:22 - 00014536 _____ () C:\Users\danitooo\Downloads\BigTitsAtSchool - Madison Ivy, Monique Alexander (Are You Staring At Your Teacher's Tits).torrent 2015-05-09 02:19 - 2015-05-09 02:19 - 00014836 _____ () C:\Users\danitooo\Downloads\Neighbor Affair - Monique Alexander.torrent 2015-05-09 02:16 - 2015-05-09 02:16 - 00011521 _____ () C:\Users\danitooo\Downloads\[MonstersOfCock] - Monique Alexander - Monique Alexander swallows black cock [bangBros] - NEW 18 NOVEMBER 2014 NEW.torrent 2015-05-09 02:13 - 2015-05-09 02:13 - 00018416 _____ () C:\Users\danitooo\Downloads\2csthollymoniquejohnny_mobile.mp4.torrent 2015-05-07 22:27 - 2015-05-07 22:27 - 00011566 _____ () C:\Users\danitooo\Downloads\MommyGotBoobs - Diamond Jackson - Busted and Busty.torrent 2015-05-07 22:26 - 2015-05-07 22:26 - 00014777 _____ () C:\Users\danitooo\Downloads\MomsInControl - Tia Layne & Tina Hot (Movie Night) NEW February 9 2015 SD MP4s.torrent 2015-05-07 22:23 - 2015-05-07 22:23 - 00017990 _____ () C:\Users\danitooo\Downloads\Massaging Your Mum's Muff - Vanilla Deville , Michael Vegas.torrent 2015-05-07 22:21 - 2015-05-07 22:21 - 00028141 _____ () C:\Users\danitooo\Downloads\AssHoleFever - Anastasia Squirt -Cock-hungry slut.torrent 2015-05-07 11:25 - 2015-05-07 11:25 - 00159880 _____ () C:\Windows\Minidump\050715-29967-01.dmp 2015-05-06 23:51 - 2015-05-07 00:48 - 00000000 ____D () C:\Users\danitooo\AppData\Roaming\HearthstoneDeckTracker 2015-05-06 17:24 - 2015-05-06 17:24 - 00013496 _____ () C:\Users\danitooo\Downloads\Shes Gonna Squirt - Jayden Lee.torrent 2015-05-06 17:19 - 2015-05-06 17:19 - 00020411 _____ () C:\Users\danitooo\Downloads\PublicBang - Sharon Lee.torrent 2015-05-06 17:19 - 2015-05-06 17:19 - 00013445 _____ () C:\Users\danitooo\Downloads\PublicBang - Sharon Lee - Big Tit Asian Chick Fucked In Public.torrent 2015-05-06 17:17 - 2015-05-06 17:17 - 00012113 _____ () C:\Users\danitooo\Downloads\TeensLikeItBig - Kalina Ryu & Morgan Lee (Rub N Tug Trainee) NEW April 25 2015 SD MP4s (1).torrent 2015-05-06 15:07 - 2015-05-10 01:30 - 00000726 _____ () C:\Windows\PFRO.log 2015-05-06 15:07 - 2015-05-10 01:30 - 00000336 _____ () C:\Windows\setupact.log 2015-05-06 15:07 - 2015-05-06 15:07 - 00000000 _____ () C:\Windows\setuperr.log 2015-05-06 03:12 - 2015-05-06 03:12 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-05-06 03:12 - 2015-05-06 03:12 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-05-06 03:10 - 2015-05-06 03:10 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll 2015-05-05 02:06 - 2015-05-05 02:06 - 00013881 _____ () C:\Users\danitooo\Downloads\MommyGotBoobs - Kendra Lust.torrent 2015-05-05 02:05 - 2015-05-05 02:05 - 00020882 _____ () C:\Users\danitooo\Downloads\MilfsLikeItBig - Ashton Blake (Dont Fuck With This Milf) NEW December 5, 2014 480p sd.torrent 2015-05-03 03:19 - 2015-05-03 03:19 - 00017484 _____ () C:\Users\danitooo\Downloads\hot_and_ready_big.mp4.torrent 2015-05-02 18:29 - 2015-05-02 18:29 - 00012245 _____ () C:\Users\danitooo\Downloads\Pounding Out The Project - Reena Sky & Johnny Sins (720p).torrent 2015-05-02 18:25 - 2015-05-02 18:25 - 00016331 _____ () C:\Users\danitooo\Downloads\Your Dad Doesn't Understand - Amirah Adara, Mercedes Carrera & Xander Corvus (720p).torrent 2015-05-02 02:09 - 2015-05-02 02:09 - 00013822 _____ () C:\Users\danitooo\Downloads\The New Porno Order - Peta Jensen & Johnny Sins (720p).torrent 2015-05-02 02:03 - 2015-05-02 02:03 - 00012703 _____ () C:\Users\danitooo\Downloads\Brazzers House Episode Five (720p).torrent 2015-05-02 02:01 - 2015-05-02 02:01 - 00013262 _____ () C:\Users\danitooo\Downloads\iktg_kitana_lure_fa121814_480p_1000.mp4.torrent 2015-05-01 01:57 - 2015-05-01 01:57 - 00014908 _____ () C:\Users\danitooo\Downloads\That Fucking Bitch Part Two - Jessica Jaymes, Jaclyn Taylor & Johnny Sins (720p).torrent 2015-04-30 22:29 - 2015-04-30 22:29 - 00011637 _____ () C:\Users\danitooo\Downloads\Mirrors.2.2010.720p.BRRip.XviD.AC3-ViSiON.torrent 2015-04-30 21:51 - 2015-04-30 21:51 - 02359350 _____ () C:\Users\danitooo\Downloads\de_dustlands0000.bmp 2015-04-30 21:50 - 2015-04-30 21:50 - 02359350 _____ () C:\Users\danitooo\Downloads\de_dustlands0002.bmp 2015-04-30 21:49 - 2015-04-30 21:49 - 02359350 _____ () C:\Users\danitooo\Downloads\de_dustlands0003.bmp 2015-04-30 21:47 - 2015-04-30 21:48 - 02359350 _____ () C:\Users\danitooo\Downloads\de_dustlands0004.bmp 2015-04-30 00:31 - 2015-04-30 00:31 - 00004604 _____ () C:\Users\danitooo\Downloads\MySistersHotFriend - Nicole Aniston.torrent 2015-04-30 00:29 - 2015-04-30 00:29 - 00005550 _____ () C:\Users\danitooo\Downloads\Housewife1On1 - Monique Alexander.torrent 2015-04-29 00:48 - 2015-04-29 00:48 - 00015306 _____ () C:\Users\danitooo\Downloads\Teaching Her How To Cum - Peta Jensen & Johnny Sins (720p).torrent 2015-04-28 23:51 - 2015-04-28 23:51 - 00659277 _____ () C:\Users\danitooo\Downloads\cs-3284-de_prodigy32.zip 2015-04-28 23:12 - 2015-04-28 23:12 - 10454957 _____ () C:\Users\danitooo\Downloads\cs-655-de_fog.rar 2015-04-28 23:12 - 2015-04-28 23:12 - 04858531 _____ () C:\Users\danitooo\Downloads\cs-928-de_sultan.rar 2015-04-28 23:12 - 2015-04-28 23:12 - 01877616 _____ () C:\Users\danitooo\Downloads\cs-1676-de_luxor.rar 2015-04-28 23:11 - 2015-04-28 23:11 - 05472107 _____ () C:\Users\danitooo\Downloads\cs-2541-de_abou.zip 2015-04-28 23:11 - 2015-04-28 23:11 - 02739085 _____ () C:\Users\danitooo\Downloads\cs-1713-de_suntower.rar 2015-04-28 23:11 - 2015-04-28 23:11 - 01867140 _____ () C:\Users\danitooo\Downloads\cs-1797-de_zima.rar 2015-04-28 23:10 - 2015-04-28 23:10 - 03795544 _____ () C:\Users\danitooo\Downloads\cs-2790-de_hell.zip 2015-04-28 23:10 - 2015-04-28 23:10 - 00953946 _____ () C:\Users\danitooo\Downloads\cs-1723-de_vengeance.rar 2015-04-28 23:10 - 2015-04-28 23:10 - 00646009 _____ () C:\Users\danitooo\Downloads\cs-1814-de_train_32.rar 2015-04-28 23:09 - 2015-04-28 23:09 - 08438785 _____ () C:\Users\danitooo\Downloads\cs-3013-de_austria.zip 2015-04-28 12:37 - 2015-04-28 12:37 - 00160384 _____ () C:\Windows\Minidump\042815-53211-01.dmp 2015-04-27 23:47 - 2015-04-27 23:47 - 00014640 _____ () C:\Users\danitooo\Downloads\Marta LaCroft - Sexy Tourist Fucks in the Bathroom SD.torrent 2015-04-27 23:45 - 2015-04-27 23:46 - 00016895 _____ () C:\Users\danitooo\Downloads\Piper Perri - Tiny Teen Fucks Her Massive Man SD.torrent 2015-04-26 23:49 - 2015-04-26 23:49 - 00012113 _____ () C:\Users\danitooo\Downloads\TeensLikeItBig - Kalina Ryu & Morgan Lee (Rub N Tug Trainee) NEW April 25 2015 SD MP4s.torrent 2015-04-26 23:45 - 2015-04-26 23:46 - 00013772 _____ () C:\Users\danitooo\Downloads\Mandingo The King Of Interracial XXX 2015 DVDRip x264.torrent 2015-04-25 02:05 - 2015-04-25 02:05 - 00015963 _____ () C:\Users\danitooo\Downloads\RealWifeStories - Christy Mack.torrent 2015-04-25 02:04 - 2015-04-25 02:04 - 00010902 _____ () C:\Users\danitooo\Downloads\First DP for Christy Mack!.torrent 2015-04-25 01:58 - 2015-04-25 01:58 - 00017348 _____ () C:\Users\danitooo\Downloads\Housewife1on1 - Peta Jensen NEW April 23 2015 SD MP4s.torrent 2015-04-25 01:58 - 2015-04-25 01:58 - 00012913 _____ () C:\Users\danitooo\Downloads\HardX - Isabella De Santos (Hot Anal Latina) NEW April 2015 SD MP4s.torrent 2015-04-24 01:57 - 2015-04-24 01:57 - 00016553 _____ () C:\Users\danitooo\Downloads\Porn Pros Cumshots Only 2.torrent 2015-04-24 01:27 - 2015-04-24 01:28 - 00016638 _____ () C:\Users\danitooo\Downloads\Porn Pros - Sexy Aerobic Workout - August Ames HD.torrent 2015-04-23 12:29 - 2015-04-23 12:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot 2015-04-23 01:36 - 2015-04-23 01:36 - 00013090 _____ () C:\Users\danitooo\Downloads\CuckoldSessions - Madelyn Monroe NEW April 2015 SD MP4s.torrent 2015-04-23 01:35 - 2015-04-23 01:35 - 00010854 _____ () C:\Users\danitooo\Downloads\TeensLikeItBig - Piper Perri (Piper Meets Mr.Creep) NEW April SD MP4s.torrent 2015-04-22 22:34 - 2015-04-22 22:34 - 02158866 _____ () C:\Users\danitooo\Downloads\cs-3267-de_cliffcabin.zip 2015-04-21 15:08 - 2015-04-21 15:08 - 00017598 _____ () C:\Users\danitooo\Downloads\Hardcore Gamer Chick (05.03.2015) 1080p (Jayden Lee & Preston Parker).mp4.torrent 2015-04-20 19:55 - 2015-04-20 19:55 - 00000000 ____D () C:\Program Files\Common Files\Java 2015-04-20 18:53 - 2015-04-20 18:54 - 48041760 _____ (IObit) C:\Users\danitooo\Downloads\advanced-systemcare-setup (1).exe 2015-04-20 18:13 - 2015-04-20 18:13 - 00011029 _____ () C:\Users\danitooo\Downloads\TeensLikeItBig - Ariana Marie (I Think We Should Bang Other People Part One) NEW April 18 2015 SD MP4s.torrent 2015-04-20 18:12 - 2015-04-20 18:12 - 00025106 _____ () C:\Users\danitooo\Downloads\Linda Swet - Hands on Hardcore - Bachelor's Gangbang DP DAP TP TRIPLE PENETRATION.torrent 2015-04-20 18:11 - 2015-04-20 18:11 - 00012060 _____ () C:\Users\danitooo\Downloads\MonstersofCock - Piper Perri (Piper Perri Takes on the McPipe) NEW April 2015 SD MP4s.torrent 2015-04-20 18:11 - 2015-04-20 18:11 - 00011296 _____ () C:\Users\danitooo\Downloads\Julia De Lucia - Spanish Student Down to Fuck SD.torrent 2015-04-20 00:42 - 2015-04-20 00:43 - 00018740 _____ () C:\Users\danitooo\Downloads\MyNaughtyMassage - Nicole Aniston NEW April 10 2015 SD MP4s.torrent 2015-04-19 01:45 - 2015-04-19 01:45 - 75689994 _____ () C:\Users\danitooo\Desktop\ Original.flv 2015-04-19 01:43 - 2015-04-19 01:44 - 79595643 _____ () C:\Users\danitooo\Desktop\AMV Tokyo Ghoul - We Are 2015-04-19 01:42 - 2015-04-19 01:43 - 78377720 _____ () C:\Users\danitooo\Desktop\Tokyo Ghoul AMV - Desire ᴵᴹᴲ Original.flv 2015-04-17 19:36 - 2015-04-17 19:36 - 00000000 ____D () C:\ProgramData\Battle.net 2015-04-17 13:13 - 2015-04-17 13:13 - 00155072 _____ () C:\Windows\Minidump\041715-29468-01.dmp 2015-04-16 13:01 - 2015-04-16 13:01 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-15 23:26 - 2015-04-02 02:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-04-15 23:26 - 2015-03-13 06:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-04-15 23:26 - 2015-03-13 06:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-04-15 23:26 - 2015-03-13 06:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-04-15 23:26 - 2015-03-13 06:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-04-15 23:26 - 2015-03-13 06:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-04-15 23:26 - 2015-03-13 06:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-04-15 23:26 - 2015-03-13 06:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-04-15 23:26 - 2015-03-13 06:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-04-15 23:26 - 2015-03-13 06:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-04-15 23:26 - 2015-03-13 06:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-04-15 23:26 - 2015-03-13 06:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-04-15 23:26 - 2015-03-13 06:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-04-15 23:26 - 2015-03-13 06:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-04-15 23:26 - 2015-03-13 06:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-04-15 23:26 - 2015-03-13 06:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-04-15 23:26 - 2015-03-13 06:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-04-15 23:26 - 2015-03-13 06:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-04-15 23:26 - 2015-03-13 06:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-04-15 23:26 - 2015-03-13 05:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-04-15 23:26 - 2015-03-13 05:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-04-15 23:26 - 2015-03-13 05:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-04-15 23:26 - 2015-03-13 05:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-04-15 23:26 - 2015-03-13 05:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-04-15 23:26 - 2015-03-13 05:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-04-15 23:26 - 2015-03-13 05:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-04-15 23:26 - 2015-03-13 05:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-04-15 23:26 - 2015-03-13 05:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-04-15 23:26 - 2015-03-13 05:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-04-15 23:26 - 2015-03-13 05:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-04-15 23:26 - 2015-03-13 05:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-04-15 23:15 - 2015-03-23 06:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-15 23:15 - 2015-03-23 06:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-15 23:15 - 2015-03-23 06:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-15 23:15 - 2015-03-23 06:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-15 23:15 - 2015-03-23 06:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-15 23:15 - 2015-03-23 06:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-15 23:15 - 2015-03-23 05:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-15 23:15 - 2015-01-28 02:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-04-15 23:14 - 2015-03-23 06:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-15 23:11 - 2015-03-17 08:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-04-15 23:11 - 2015-03-17 08:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-15 23:11 - 2015-03-17 08:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-15 23:11 - 2015-03-17 08:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-15 23:11 - 2015-03-17 07:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-15 23:11 - 2015-03-17 07:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-15 23:11 - 2015-03-17 07:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-15 23:11 - 2015-03-17 07:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-15 23:11 - 2015-03-17 07:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-15 23:11 - 2015-03-04 07:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-15 23:11 - 2015-03-04 07:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-15 23:10 - 2015-03-17 07:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-15 23:10 - 2015-03-17 07:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-15 23:10 - 2015-03-17 07:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-15 23:10 - 2015-03-17 07:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-15 23:10 - 2015-03-17 07:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-15 23:10 - 2015-03-17 07:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-15 23:10 - 2015-03-17 07:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-15 23:10 - 2015-03-17 07:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-15 23:10 - 2015-03-17 07:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-15 23:10 - 2015-03-17 07:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-15 23:10 - 2015-03-17 07:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-15 23:10 - 2015-03-05 07:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-15 23:09 - 2015-03-25 06:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-15 23:09 - 2015-03-25 06:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-15 23:09 - 2015-03-25 06:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-15 23:09 - 2015-02-25 06:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-15 23:03 - 2015-03-10 06:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-15 23:03 - 2015-03-10 06:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-15 01:39 - 2015-05-08 00:30 - 00000771 _____ () C:\Users\danitooo\Desktop\PC.txt 2015-04-13 00:24 - 2015-04-13 00:24 - 06400680 _____ (Electronic Arts ) C:\Users\danitooo\Downloads\setup_nfsw.exe 2015-04-11 18:56 - 2015-05-07 11:25 - 229322499 _____ () C:\Windows\MEMORY.DMP 2015-04-11 18:56 - 2015-04-11 18:56 - 00160384 _____ () C:\Windows\Minidump\041115-41808-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-10 21:33 - 2014-04-07 20:06 - 00000000 ____D () C:\Users\danitooo\AppData\Roaming\Skype 2015-05-10 21:31 - 2014-04-07 21:13 - 00000000 ____D () C:\Users\danitooo\AppData\Roaming\uTorrent 2015-05-10 21:27 - 2014-10-22 23:09 - 00000986 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-05-10 20:52 - 2014-09-20 11:17 - 00000382 _____ () C:\Windows\Tasks\update-sys.job 2015-05-10 20:25 - 2014-09-20 11:17 - 00000382 _____ () C:\Windows\Tasks\update-S-1-5-21-3170674983-682481904-2544561987-1001.job 2015-05-10 19:55 - 2014-08-06 19:41 - 00000000 ____D () C:\Users\danitooo\AppData\Local\Battle.net 2015-05-10 03:44 - 2014-12-09 23:26 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-10 03:43 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\tracing 2015-05-10 02:40 - 2015-01-21 20:43 - 01392384 _____ () C:\Windows\WindowsUpdate.log 2015-05-10 01:43 - 2014-12-09 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-05-10 01:43 - 2014-12-09 23:24 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2015-05-10 01:37 - 2009-07-14 07:34 - 00029200 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-10 01:37 - 2009-07-14 07:34 - 00029200 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-10 01:32 - 2014-10-22 23:09 - 00000982 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-10 01:30 - 2014-06-24 23:32 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2015-05-10 01:30 - 2009-07-14 07:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-10 01:29 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\Vss 2015-05-09 02:09 - 2014-11-09 16:46 - 00000591 _____ () C:\Users\danitooo\Desktop\n.txt 2015-05-08 11:12 - 2014-08-06 19:41 - 00000000 ____D () C:\Program Files\Battle.net 2015-05-07 20:30 - 2014-04-07 20:04 - 00000000 ____D () C:\ProgramData\Skype 2015-05-07 20:29 - 2015-04-08 01:22 - 00000000 ___RD () C:\Program Files\Skype 2015-05-07 11:25 - 2014-08-30 11:15 - 00000000 ____D () C:\Windows\Minidump 2015-05-06 15:07 - 2014-04-07 13:15 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-06 03:21 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-05-06 02:54 - 2014-04-07 13:15 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-05-06 02:54 - 2014-04-07 13:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-05-06 02:53 - 2014-10-22 23:07 - 00000000 ____D () C:\Users\danitooo\AppData\Local\Adobe 2015-04-30 00:08 - 2009-07-14 07:53 - 00032546 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-04-28 12:39 - 2014-05-17 18:16 - 00000000 ____D () C:\ProgramData\ProductData 2015-04-23 12:29 - 2014-09-20 11:17 - 00000412 _____ () C:\Users\danitooo\AppData\Local\UserProducts.xml 2015-04-21 19:39 - 2014-04-07 21:22 - 00000000 ___RD () C:\Users\danitooo\Desktop\New folder 2015-04-21 13:28 - 2014-08-06 19:41 - 00000000 ____D () C:\Users\danitooo\AppData\Roaming\Battle.net 2015-04-20 20:00 - 2015-01-25 15:23 - 00000000 ____D () C:\ProgramData\Oracle 2015-04-20 19:53 - 2014-11-07 01:09 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2015-04-20 19:53 - 2014-04-12 00:28 - 00000000 ____D () C:\Program Files\Java 2015-04-20 19:02 - 2014-08-14 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8 2015-04-19 16:58 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\rescache 2015-04-17 20:19 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-04-17 19:56 - 2014-04-07 23:18 - 00000000 ____D () C:\Program Files\WinRAR 2015-04-17 19:55 - 2014-11-05 16:16 - 00000000 ____D () C:\Program Files\PokerStars.BG 2015-04-17 19:55 - 2014-09-20 11:17 - 00000000 ____D () C:\Program Files\Skillbrains 2015-04-17 19:55 - 2014-08-18 13:33 - 00000000 ____D () C:\Program Files\Webteh 2015-04-17 19:55 - 2014-04-07 23:38 - 00000000 ____D () C:\Program Files\vloader-bg 2015-04-17 19:55 - 2014-04-07 21:09 - 00000000 ____D () C:\Program Files\The KMPlayer 2015-04-17 19:55 - 2009-07-14 07:52 - 00000000 ____D () C:\Program Files\Windows Sidebar 2015-04-17 19:53 - 2014-04-07 20:19 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-04-17 19:51 - 2015-03-18 22:39 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services 2015-04-17 19:51 - 2015-03-18 22:36 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition 2015-04-17 19:51 - 2015-03-18 22:28 - 00000000 ____D () C:\Program Files\Microsoft Office 2015-04-17 19:51 - 2014-04-11 22:23 - 00000000 ____D () C:\Program Files\Microsoft.NET 2015-04-17 19:48 - 2014-06-20 11:28 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2015-04-17 19:48 - 2009-07-14 07:52 - 00000000 ____D () C:\Program Files\Microsoft Games 2015-04-17 19:47 - 2014-08-09 16:26 - 00000000 ____D () C:\Program Files\IObit 2015-04-17 19:46 - 2014-08-17 21:53 - 00000000 ____D () C:\Program Files\GRETECH 2015-04-17 19:45 - 2015-04-08 01:22 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-04-17 19:45 - 2015-01-28 19:37 - 00000000 ____D () C:\Program Files\EaseUS 2015-04-17 19:45 - 2014-10-22 23:08 - 00000000 ____D () C:\Program Files\Google 2015-04-17 19:45 - 2014-06-04 21:34 - 00000000 ____D () C:\Program Files\DAEMON Tools Lite 2015-04-17 19:45 - 2014-04-07 20:56 - 00000000 ____D () C:\Program Files\Common Files\PX Storage Engine 2015-04-17 19:45 - 2009-07-14 05:37 - 00000000 ____D () C:\Program Files\Common Files\Services 2015-04-17 19:45 - 2009-07-14 05:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2015-04-17 19:44 - 2015-03-18 22:39 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2015-04-17 19:44 - 2015-03-09 22:58 - 00000000 ____D () C:\Program Files\Common Files\Gretech Corporation 2015-04-17 19:44 - 2015-01-25 15:14 - 00000000 ____D () C:\Program Files\Common Files\IObit 2015-04-17 19:44 - 2015-01-21 20:02 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2015-04-17 19:44 - 2014-08-06 19:41 - 00000000 ____D () C:\Program Files\Common Files\Blizzard Entertainment 2015-04-17 19:43 - 2014-05-11 18:24 - 00000000 ____D () C:\Program Files\CCleaner 2015-04-17 19:39 - 2015-03-18 22:28 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-04-17 19:39 - 2015-01-21 20:21 - 00000000 ____D () C:\Program Files\Adobe 2015-04-17 19:39 - 2014-04-07 20:21 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-17 19:39 - 2014-04-07 20:19 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-04-17 19:38 - 2015-04-08 01:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-17 19:38 - 2015-03-18 22:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2015-04-17 19:38 - 2015-03-04 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter 2015-04-17 19:38 - 2015-01-21 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2014 (32 Bit) 2015-04-17 19:38 - 2015-01-21 20:40 - 00000000 ____D () C:\ProgramData\Adobe 2015-04-17 19:38 - 2014-11-07 01:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-04-17 19:38 - 2014-11-07 01:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2 2015-04-17 19:38 - 2014-10-28 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 LH 2013 2015-04-17 19:38 - 2014-10-22 23:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-04-17 19:38 - 2014-09-06 04:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RocketDock 2015-04-17 19:38 - 2014-08-18 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player 2015-04-17 19:38 - 2014-08-18 01:09 - 00000000 ____D () C:\ProgramData\GRETECH 2015-04-17 19:38 - 2014-08-17 21:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player 2015-04-17 19:38 - 2014-08-09 16:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3 2015-04-17 19:38 - 2014-08-06 19:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2015-04-17 19:38 - 2014-08-06 19:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2015-04-17 19:38 - 2014-06-20 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2015-04-17 19:38 - 2014-06-19 11:26 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-04-17 19:38 - 2014-06-04 21:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite 2015-04-17 19:38 - 2014-06-02 21:29 - 00000000 ____D () C:\ProgramData\Blizzard 2015-04-17 19:38 - 2014-06-02 20:32 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2015-04-17 19:38 - 2014-05-17 18:12 - 00000000 ____D () C:\ProgramData\IObit 2015-04-17 19:38 - 2014-05-11 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-04-17 19:38 - 2014-05-06 14:46 - 00000000 ____D () C:\ProgramData\f6402c15d6c56be2 2015-04-17 19:38 - 2014-05-06 14:45 - 00000000 ____D () C:\ProgramData\InstallMate 2015-04-17 19:38 - 2014-04-16 03:19 - 00000000 ____D () C:\ProgramData\DFX 2015-04-17 19:38 - 2014-04-09 21:06 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2015-04-17 19:38 - 2014-04-07 23:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-17 19:38 - 2014-04-07 20:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp 2015-04-17 19:38 - 2014-04-07 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2015-04-17 19:38 - 2009-07-14 07:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-04-17 19:38 - 2009-07-14 05:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-04-17 19:38 - 2009-07-14 05:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-04-17 08:14 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\AppCompat 2015-04-17 08:10 - 2014-04-07 20:31 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-04-16 13:01 - 2014-05-07 11:18 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-16 12:58 - 2014-04-08 22:08 - 00000000 ____D () C:\Windows\system32\MRT 2015-04-16 12:47 - 2014-04-07 12:39 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-16 12:46 - 2010-11-21 00:01 - 00765280 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-14 19:34 - 2015-04-02 00:41 - 00000000 ____D () C:\Users\danitooo\AppData\Roaming\.minecraft 2015-04-14 09:37 - 2014-12-09 23:24 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-04-14 09:37 - 2014-12-09 23:24 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-04-14 09:37 - 2014-12-09 23:24 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-04-13 00:12 - 2014-04-17 21:14 - 00000000 ____D () C:\Users\danitooo\AppData\Local\Electronic_Arts_Inc 2015-04-12 23:54 - 2014-12-15 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall ==================== Files in the root of some directories ======= 2014-04-23 00:24 - 2014-06-09 21:13 - 0007597 _____ () C:\Users\danitooo\AppData\Local\resmon.resmoncfg 2014-09-20 11:17 - 2014-09-20 11:17 - 0000003 _____ () C:\Users\danitooo\AppData\Local\updater.log 2014-09-20 11:17 - 2015-04-23 12:29 - 0000412 _____ () C:\Users\danitooo\AppData\Local\UserProducts.xml 2014-12-11 18:20 - 2014-12-11 18:20 - 0000000 _____ () C:\Users\danitooo\AppData\Local\{2F611F14-7E37-4F01-8595-0817CBBBC0DA} 2015-01-22 19:24 - 2015-01-22 19:26 - 0000000 _____ () C:\Users\danitooo\AppData\Local\{9CCF26E7-557A-4E7C-8F41-47AB1935CF2C} 2014-07-11 16:58 - 2014-07-11 16:58 - 0000000 _____ () C:\Users\danitooo\AppData\Local\{E7F716F5-10E0-4185-9FCD-7CA02938F89B} 2014-05-17 18:58 - 2014-05-17 18:58 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2014-05-17 17:54 - 2014-05-17 17:54 - 5073168 _____ (PC Cleaners) C:\ProgramData\pclunst.exe 2014-08-14 18:49 - 2014-08-14 18:49 - 0000000 _____ () C:\ProgramData\spds90.txt Files to move or delete: ==================== C:\ProgramData\pclunst.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-04 19:54 ==================== End Of Log ============================
  10. Здравейте! На скоро прихванах тая гадинка KillAV.dr. Антивирусната я засича и я трие но без успех. Създава копия на C:\Users\Public\ и всички директории във нея. Изтрих цялата Public папка с надеждата че просто няма да има къде да създава файлове но то пак си я създаде и продължи просто да създава: Public.exe Public.rar Public.txt Public.bat и тн. със всички възможни разширения. Mawlarebytes и Avast! го намират и трият но предполагам че въпросните копия не са самия вирус и той се крие някъде другаде.
  11. Сигурен съм, че системата ми е заразена с тези и други вирусчета и това се случи след, като изтеглих това. За сега нищо не се е случило, но искам да се отърва от тях преди да се случи. Не разполагам с компакт диск за моята операционна система. Ето и файловете, които пожелахте. FRST.txt и Addition.txt
  12. Здравейте.Надявам се някой да помогне за следното. При стартиране на Уиндоуса се забавя много връзката с интернет(активиране на иконката с монитора на тулбара). Бях с браузър Chrome,когато се появи това.След което се появи друг проблем.При стартиране на произволен сайт се появяваха много реклами(изкачащи в същата страница и отварящи се нови страници).Най-лесното за мен решение беше да изтрия Chrome и инсталирах Mozilla.Проблемът с рекламите изчезна,но бавната връзка при стартирането си остана и при този браузър.Прави ми впечатление и това,че при отваряне на страница с разни снимки,преди да се заредят,виждам бели прозорчета с хиксчето в горния ъгъл-това при Chrome го нямаше.Каво мислите за това? Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015 Ran by Admin (administrator) on ADMIN-PC on 03-02-2015 15:34:25 Running from D:\Downloads Loaded Profiles: Admin (Available profiles: Admin) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe () C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files (x86)\Vtune\TBPANEL.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe () C:\Program Files (x86)\Roxio Creator NXT\Roxio Burn\RoxioBurnLauncher.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [shadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2460488 2014-09-17] (NVIDIA Corporation) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-03-17] (Apple Inc.) HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-04-04] (Adobe Systems Incorporated) HKU\S-1-5-21-2122364038-41154087-1698926458-1000\...\Run: [TBPanel] => C:\Program Files (x86)\Vtune\TBPanel.exe [2248704 2011-08-02] () HKU\S-1-5-21-2122364038-41154087-1698926458-1000\...\MountPoints2: {0eede1f3-49d2-11e1-bd08-f46d04dd4de0} - G:\setup.exe HKU\S-1-5-21-2122364038-41154087-1698926458-1000\...\MountPoints2: {1dcf16fe-a399-11e4-a5d9-f46d04dd4de0} - F:\setup.exe HKU\S-1-5-21-2122364038-41154087-1698926458-1000\...\MountPoints2: {49fdbb18-1857-11e1-81f0-f46d04dd4de0} - F:\setup.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/?fr=fp-yie11 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.yahoo.com/?fr=fp-yie11 HKU\S-1-5-21-2122364038-41154087-1698926458-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2122364038-41154087-1698926458-1000 -> {A2B1F8D8-D31B-4BF5-8B06-6117C3E997CF} URL = https://delicious.com/search?p={searchTerms} SearchScopes: HKU\S-1-5-21-2122364038-41154087-1698926458-1000 -> {A2F03616-3CC6-479C-947D-56D368A2AC64} URL = https://www.flickr.com/search/?q={searchTerms} SearchScopes: HKU\S-1-5-21-2122364038-41154087-1698926458-1000 -> {A715C782-AB21-47F2-A97C-1B458A9E4953} URL = https://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11 BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-2122364038-41154087-1698926458-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Hosts: 127.0.0.1 activate.adobe.com Tcpip\Parameters: [DhcpNameServer] 46.40.72.18 46.40.72.17 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4zmyxi5d.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\911bg.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\diribg.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pe-bg.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\portalbgdict.xml FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected] FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected] [2015-01-17] FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected] FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected] [2015-01-17] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2015-01-17] CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2015-01-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] () R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] () R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-12-03] (Freemake) [File not signed] R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-12-03] (Ellora Assets Corp.) [File not signed] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-09-17] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-09-17] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19439944 2014-09-17] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2012-01-28] () R2 RoxioBurnLauncher; C:\Program Files (x86)\Roxio Creator NXT\Roxio Burn\RoxioBurnLauncher.exe [535184 2012-07-05] () S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation) S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 Cardex; C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [15648 2007-03-16] (Windows ® Server 2003 DDK provider) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) S3 NMgamingmsFltr; C:\Windows\System32\drivers\NMgamingms.sys [11264 2009-07-24] (Primax Ltd) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-09-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation) R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation) R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation) R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation) S3 TBPanel; No ImagePath S3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare) S1 jfdlhuqz; \??\C:\Windows\system32\drivers\jfdlhuqz.sys [X] S3 NPF; system32\drivers\NPF.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-03 15:33 - 2015-02-03 15:34 - 00000000 ____D () C:\FRST 2015-02-03 14:02 - 2015-02-03 14:02 - 00003352 ____N () C:\bootsqm.dat 2015-01-31 19:27 - 2015-01-31 19:27 - 00000813 _____ () C:\Users\Admin\Desktop\µTorrent.lnk 2015-01-31 19:27 - 2015-01-31 19:27 - 00000793 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2015-01-31 19:26 - 2015-01-31 19:26 - 00000000 ____D () C:\ProgramData\APN 2015-01-31 17:56 - 2015-01-31 17:56 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2015-01-31 17:49 - 2015-01-31 17:56 - 00000000 ____D () C:\ProgramData\HitmanPro 2015-01-31 17:36 - 2015-02-03 14:06 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-31 17:36 - 2015-01-31 17:36 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-01-31 17:36 - 2015-01-31 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-01-31 17:36 - 2015-01-31 17:36 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-01-31 17:36 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-31 17:36 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-31 17:36 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-27 12:47 - 2015-01-27 12:47 - 00000000 ____D () C:\Users\Admin\AppData\Local\Macromedia 2015-01-27 12:44 - 2015-02-03 13:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-27 12:44 - 2015-01-27 12:45 - 00000000 ____D () C:\Users\Admin\AppData\Local\Mozilla 2015-01-27 12:44 - 2015-01-27 12:44 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-01-27 12:44 - 2015-01-27 12:44 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-01-27 12:44 - 2015-01-27 12:44 - 00000000 ____D () C:\ProgramData\Mozilla 2015-01-27 12:44 - 2015-01-27 12:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 10:47 - 2014-12-13 07:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-01-27 10:47 - 2014-12-13 05:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-01-27 10:43 - 2015-01-27 10:43 - 00000000 __SHD () C:\Users\Admin\AppData\Local\EmieBrowserModeList 2015-01-27 02:40 - 2014-11-27 03:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-01-27 02:40 - 2014-11-27 03:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-01-27 02:40 - 2014-11-22 05:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-01-27 02:40 - 2014-11-22 05:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-01-27 02:40 - 2014-11-22 05:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-01-27 02:40 - 2014-11-22 04:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-01-27 02:40 - 2014-11-22 04:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-01-27 02:40 - 2014-11-22 04:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-01-27 02:40 - 2014-11-22 04:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-01-27 02:40 - 2014-11-22 04:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-01-27 02:40 - 2014-11-22 04:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-01-27 02:40 - 2014-11-22 04:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-01-27 02:40 - 2014-11-22 04:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-01-27 02:40 - 2014-11-22 04:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-01-27 02:40 - 2014-11-22 04:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-01-27 02:40 - 2014-11-22 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-01-27 02:40 - 2014-11-22 04:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-01-27 02:40 - 2014-11-22 04:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-01-27 02:40 - 2014-11-22 04:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-01-27 02:40 - 2014-11-22 04:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-01-27 02:40 - 2014-11-22 04:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-01-27 02:40 - 2014-11-22 04:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-01-27 02:40 - 2014-11-22 04:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-01-27 02:40 - 2014-11-22 04:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-01-27 02:40 - 2014-11-22 04:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-01-27 02:40 - 2014-11-22 04:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-01-27 02:40 - 2014-11-22 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-01-27 02:40 - 2014-11-22 04:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-01-27 02:40 - 2014-11-22 04:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-01-27 02:40 - 2014-11-22 03:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-01-27 02:40 - 2014-11-22 03:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-01-27 02:40 - 2014-11-22 03:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-01-27 02:40 - 2014-11-22 03:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-01-27 02:40 - 2014-11-22 03:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-01-27 02:40 - 2014-11-22 03:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-01-27 02:40 - 2014-11-22 03:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-01-27 02:40 - 2014-11-22 03:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-01-27 02:40 - 2014-11-22 03:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-01-27 02:40 - 2014-11-22 03:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-01-27 02:40 - 2014-11-22 03:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-01-27 02:40 - 2014-11-22 03:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-01-27 02:40 - 2014-11-22 03:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-01-27 02:40 - 2014-11-22 03:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-01-27 02:40 - 2014-11-22 03:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-01-27 02:40 - 2014-11-22 03:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-01-27 02:40 - 2014-11-22 03:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-01-27 02:40 - 2014-11-22 03:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-01-27 02:40 - 2014-11-22 03:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-01-27 02:40 - 2014-11-22 03:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-01-27 02:40 - 2014-11-22 03:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-01-27 02:40 - 2014-11-22 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-01-27 02:40 - 2014-11-22 03:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-01-27 02:40 - 2014-11-22 02:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-01-27 02:40 - 2014-11-22 02:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-01-27 02:00 - 2015-02-01 10:07 - 00002726 _____ () C:\Windows\PFRO.log 2015-01-27 01:26 - 2015-02-03 14:03 - 00002744 _____ () C:\Windows\setupact.log 2015-01-27 01:26 - 2015-01-27 01:26 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-25 14:16 - 2015-01-25 14:16 - 00001193 _____ () C:\Windows\system32\1 hands FIPA SOCCER COACH ATHLETE embarrassing moments boner funny erectile dysfunction viagra sexual impotence photo picture cure remedy symptoms bulge men guy man top best hilarious medical procedur.lnk 2015-01-25 13:10 - 2015-01-25 14:10 - 04070576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-01-21 11:05 - 2014-10-18 04:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-01-21 11:05 - 2014-10-18 03:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2015-01-21 11:05 - 2014-07-07 04:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-01-21 11:05 - 2014-07-07 04:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-01-21 11:05 - 2014-07-07 04:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-01-21 11:05 - 2014-07-07 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-01-21 11:05 - 2014-07-07 03:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2015-01-21 11:05 - 2014-07-07 03:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2015-01-21 11:05 - 2014-07-07 03:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2015-01-21 11:05 - 2014-07-07 03:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2015-01-21 10:56 - 2014-12-19 05:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-21 10:56 - 2014-12-19 03:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-21 10:56 - 2014-12-12 07:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-21 10:56 - 2014-12-12 07:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-21 10:56 - 2014-12-12 07:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-21 10:56 - 2014-12-12 07:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-21 10:56 - 2014-12-12 07:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-21 10:56 - 2014-12-12 07:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-21 10:56 - 2014-12-12 07:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-21 10:56 - 2014-12-11 19:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-21 10:56 - 2014-12-06 06:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-21 10:56 - 2014-12-06 05:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-21 10:56 - 2014-12-06 05:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-21 10:56 - 2014-11-11 05:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-01-21 10:56 - 2014-11-11 05:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-01-21 10:56 - 2014-11-11 05:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2015-01-21 10:56 - 2014-11-11 04:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-01-21 10:56 - 2014-11-11 04:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-01-21 10:56 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2015-01-21 10:56 - 2014-11-11 03:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-01-21 10:56 - 2014-11-08 05:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-01-21 10:56 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2015-01-21 10:56 - 2014-10-30 04:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2015-01-21 10:56 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2015-01-21 10:56 - 2014-10-03 04:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2015-01-21 10:56 - 2014-10-03 04:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2015-01-21 10:56 - 2014-10-03 04:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2015-01-21 10:56 - 2014-10-03 04:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2015-01-21 10:56 - 2014-10-03 04:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2015-01-21 10:56 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2015-01-21 10:56 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2015-01-21 10:56 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2015-01-21 10:56 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2015-01-21 10:56 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2015-01-17 17:51 - 2015-01-17 17:51 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Opera Software 2015-01-17 17:51 - 2015-01-17 17:51 - 00000000 ____D () C:\Users\Admin\AppData\Local\Opera Software 2015-01-17 17:50 - 2015-01-17 17:52 - 00001332 _____ () C:\Users\Public\Desktop\Freemake Video Downloader.lnk 2015-01-17 17:50 - 2015-01-17 17:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake 2015-01-17 17:50 - 2015-01-17 17:50 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2015-01-17 17:49 - 2015-01-17 17:50 - 00000000 ____D () C:\Program Files (x86)\Freemake ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-03 15:10 - 2013-09-04 19:48 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-02-03 14:57 - 2011-11-21 21:49 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-03 14:29 - 2011-11-21 21:35 - 01498658 _____ () C:\Windows\WindowsUpdate.log 2015-02-03 14:17 - 2011-11-21 15:43 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{77122C95-C486-48DE-8C13-2BB165780A7B} 2015-02-03 14:12 - 2009-07-14 06:45 - 00015008 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-03 14:12 - 2009-07-14 06:45 - 00015008 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-03 14:03 - 2011-11-21 21:49 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-03 14:03 - 2011-11-21 15:43 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-03 14:03 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-03 13:15 - 2013-09-04 19:48 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-03 13:15 - 2013-09-04 19:48 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-03 13:15 - 2013-09-04 19:48 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-02-03 13:14 - 2014-09-25 22:45 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe 2015-02-03 10:33 - 2012-02-20 20:58 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\uTorrent 2015-02-03 01:54 - 2014-10-20 21:46 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc 2015-02-02 23:54 - 2014-03-05 23:02 - 00000000 ____D () C:\ProgramData\SmartSound Software Inc 2015-01-31 17:36 - 2013-01-22 20:54 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-31 17:19 - 2012-09-16 20:48 - 00000000 ____D () C:\Program Files (x86)\Applian Technologies 2015-01-29 21:12 - 2011-12-10 22:10 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype 2015-01-27 19:17 - 2009-07-14 07:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-27 13:56 - 2014-07-15 22:10 - 00000000 ____D () C:\Windows\rescache 2015-01-27 12:44 - 2014-04-27 15:47 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Mozilla 2015-01-27 11:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2015-01-27 02:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-01-27 02:09 - 2011-11-21 21:49 - 00000000 ____D () C:\Users\Admin\AppData\Local\Google 2015-01-27 02:09 - 2011-11-21 21:49 - 00000000 ____D () C:\Program Files (x86)\Google 2015-01-26 23:20 - 2012-01-28 20:27 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite 2015-01-24 17:41 - 2011-11-26 20:57 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-01-21 11:09 - 2011-12-30 14:07 - 00766336 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-01-21 11:04 - 2013-07-20 23:53 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-17 17:53 - 2011-11-24 00:11 - 00001413 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-01-17 17:52 - 2014-03-31 00:44 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-01-17 17:50 - 2013-02-04 14:15 - 00000000 ____D () C:\ProgramData\Freemake 2015-01-08 09:55 - 2011-11-21 18:17 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2012-05-04 09:04 - 2012-05-04 09:04 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll 2014-09-22 11:05 - 2014-11-02 14:49 - 0000000 _____ () C:\Users\Admin\AppData\Roaming\Radio Sounds 2012-02-06 02:33 - 2012-06-29 00:10 - 0007601 _____ () C:\Users\Admin\AppData\Local\Resmon.ResmonCfg 2014-03-08 21:42 - 2014-03-08 21:44 - 0299308 _____ () C:\Users\Admin\AppData\Local\rx_image32.Cache 2014-10-20 20:39 - 2014-10-20 20:39 - 0000848 ___SH () C:\ProgramData\KGyGaAvL.sys 2012-06-04 14:37 - 2012-06-04 14:37 - 0034308 _____ () C:\ProgramData\mazuki.dll 2014-09-22 10:12 - 2014-09-22 10:49 - 0000000 ____H () C:\ProgramData\PKP_DLbx.DAT 2014-09-22 11:05 - 2014-11-02 14:49 - 0000000 ____H () C:\ProgramData\PKP_DLes.DAT 2014-09-22 11:05 - 2014-11-02 14:49 - 0000000 ____H () C:\ProgramData\PKP_DLet.DAT 2014-09-22 11:05 - 2014-11-02 14:49 - 0000000 ____H () C:\ProgramData\PKP_DLev.DAT 2014-11-02 14:49 - 2014-11-02 14:49 - 0000000 _____ () C:\ProgramData\Plug-In Settings 2014-11-02 14:49 - 2014-11-02 14:49 - 0000000 _____ () C:\ProgramData\Quartz Composer 2012-07-30 22:10 - 2012-07-30 22:10 - 0002462 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag Files to move or delete: ==================== C:\ProgramData\mazuki.dll Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\HitmanPro.exe C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\Admin\AppData\Local\Temp\sqlite3.dll C:\Users\Admin\AppData\Local\Temp\utt3377.tmp.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-03 15:21 ==================== End Of Log ============================ Addition.txt
  13. Здравейте,от няколко дни имам следният проблем - 1-2 пъти на ден или след рестарт на компа браузърите ми нямат достъп до интернет(обикновенно си ползвам Chrome но опитах и с Mozilla и IE но едно и също)...На скайп си имам връзка,сканирах с антивирусната(BitDefender Internet Security) но без резултат,последва сканиране с Malwarebytes Anti-Malware 2.0.2 и пак нищо..Имам едно инструментче - Dr.Web Cureit като го пуснах сканира и откри ето това : Уж го излекува но на другия ден пак същия номер,последваха пак горните действия и Dr.Web отново откри същото нещо и уж го излекува...На 3-тия ден се събудих пак без нет но този път и скайпа не ми се включи докато не рестартирах компа..В момента след същите действия се оправи но не знам докога...Прилагам лога от FRST....Addition.txt при мен не ми излезна на декстопа FRST.txt
  14. Здравейте, опитвам се да помогна на близък със старичък лаптоп. Работи и зарежда много бавно, уиндоуса е XP service pack 2, неуспешно пробвах да ъпдейтна до 3 - даде неуспешен опит или от сорта. Сканирах с AVG и откри няколко заплахи, системния дял е силно фрагментиран,но вградената програма не успява да дефрагментира напълно и остава към 80% фраг. Сигурно има и вирус някакъв, защото в Chrome имаше няколко adware разширения. Ако е възможно да не се преинсталира ще е добре. Който може , моля да ме упъти как да процедирам по-нататък,благодаря! Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015 01 Ran by Owner (administrator) on ANONYMOUS on 19-04-2015 23:28:28 Running from C:\Documents and Settings\Owner\My Documents\Downloads Loaded Profiles: Owner (Available profiles: Owner) Platform: Microsoft Windows XP Professional Service Pack 2 (X86) OS Language: English (United States) Internet Explorer Version 7 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe () C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe () C:\Program Files\DefaultTab\DefaultTabSearch.exe () C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe (Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Microsoft Corporation) C:\Program Files\UPHClean\uphclean.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\loggingserver.exe () C:\Program Files\VIVACOM 3G USB MODEM\ModemListener.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe () C:\Program Files\AVG Web TuneUp\vprot.exe (Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\rapimgr.exe () C:\WINDOWS\Datecs\Flex2K.exe (AVG Secure Search) C:\Program Files\AVG Web TuneUp\avgcefrend.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\Run: [ModemListener] => C:\Program Files\VIVACOM 3G USB MODEM\ModemListener.exe [98304 2010-01-27] () HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2013\avgui.exe [4411952 2014-11-04] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [vProt] => C:\Program Files\AVG Web TuneUp\vprot.exe [3033112 2015-03-05] () Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\dimsntfy: C:\WINDOWS\System32\dimsntfy.dll [2008-04-14] (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll [2006-03-24] (Intel Corporation) Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll [2004-08-04] (Microsoft Corporation) Winlogon\Notify\WgaLogon: C:\WINDOWS\system32\WgaLogon.dll [2009-03-24] (Microsoft Corporation) Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll [2004-08-04] (Microsoft Corporation) HKLM\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 HKLM\...\Policies\Explorer: [ForceClassicControlPanel] 1 HKLM\...\Policies\Explorer: [NoSharedDocuments] 1 HKLM\...\Policies\Explorer: [MaxRecentDocs] 18 HKLM\...\Policies\Explorer: [NoSMConfigurePrograms] 1 HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 1 HKLM\...\Policies\Explorer: [MemCheckBoxInRunDlg] 1 HKU\S-1-5-19\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-20\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-21-1177238915-790525478-1801674531-1003\...\Run: [H/PC Connection Agent] => C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation) HKU\S-1-5-21-1177238915-790525478-1801674531-1003\...\Run: [Google Update] => C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [116648 2012-07-15] (Google Inc.) HKU\S-1-5-21-1177238915-790525478-1801674531-1003\...\MountPoints2: {2de15e94-d92b-11e3-832e-0019d2711d96} - F:\AutoRun.exe HKU\S-1-5-21-1177238915-790525478-1801674531-1003\...\MountPoints2: {749cc242-444b-11e0-bfc5-0019d2711d96} - F:\Install.exe HKU\S-1-5-18\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-18\...\RunOnce: [tscuninstall] => C:\WINDOWS\system32\tscupgrd.exe [44544 2004-08-04] (Microsoft Corporation) HKU\S-1-5-18\...\RunOnce: [showDeskFix] => regsvr32 /s /n /i:u shell32 HKU\S-1-5-18\...\RunOnce: [iE7-11] => rundll32 advpack.dll,LaunchINFSection NR_IE7en.inf,AfterUserStart Lsa: [Notification Packages] scecli Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2009-07-25] ShortcutTarget: FlexType 2K.lnk -> C:\WINDOWS\Datecs\Flex2K.exe () BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyServer: [s-1-5-21-1177238915-790525478-1801674531-1003] => proxy.rail-infra.bg:8080 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-1177238915-790525478-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={94177F37-429B-4853-BF38-4BE6ED031249}&mid=f65d66cc442a47d3a1d6d1509495f465-6a124ef6434ed2b791f1e22b1ffccd75865e0243&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-2111:47:47&v=4.1.0.411&pid=wtu&sg=&sap=hp SearchScopes: HKLM -> DefaultScope {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm007YYbg&ptnrS=HJxdm007YYbg&si=CPXxnbGZqbICFQhO3god8xEAwg&ptb=A5F26670-EA33-4EF5-82A4-636720B30B2C&ind=2012090915&n=77ee1223&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm007YYbg&ptnrS=HJxdm007YYbg&si=CPXxnbGZqbICFQhO3god8xEAwg&ptb=A5F26670-EA33-4EF5-82A4-636720B30B2C&ind=2012090915&n=77ee1223&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={94177F37-429B-4853-BF38-4BE6ED031249}&mid=f65d66cc442a47d3a1d6d1509495f465-6a124ef6434ed2b791f1e22b1ffccd75865e0243&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-2111:47:47&v=4.1.0.411&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> {08695E7C-3FF8-408F-89E5-CDCE161D6692} URL = http://www.google.com/search?hl=en&q={searchTerms}&rlz=1I7GGLL_zh-CNBG374 SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=120008&tt=300513_ctrl&babsrc=SP_ss_din2g&mntrId=64AB0015B7091564 SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={94177F37-429B-4853-BF38-4BE6ED031249}&mid=f65d66cc442a47d3a1d6d1509495f465-6a124ef6434ed2b791f1e22b1ffccd75865e0243&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-2111:47:47&v=4.1.0.411&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm007YYbg&ptnrS=HJxdm007YYbg&si=CPXxnbGZqbICFQhO3god8xEAwg&ptb=A5F26670-EA33-4EF5-82A4-636720B30B2C&ind=2012090915&n=77ee1223&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQJ9ioJlW&i=26 BHO: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll [2009-03-02] (BitComet) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-04] (Oracle Corporation) BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.1.0.411\AVG Web TuneUp.dll [2015-03-05] (AVG) BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-04] (Oracle Corporation) Toolbar: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-1177238915-790525478-1801674531-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.3.0\ViProtocol.dll [2015-02-14] (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 188.126.0.66 188.126.0.2 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default FF DefaultSearchEngine: AVG Secure Search FF SelectedSearchEngine: AVG Secure Search FF Homepage: https://mysearch.avg.com?cid={94177F37-429B-4853-BF38-4BE6ED031249}&mid=f65d66cc442a47d3a1d6d1509495f465-6a124ef6434ed2b791f1e22b1ffccd75865e0243&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-2111:47:47&v=4.1.0.411&pid=wtu&sg=&sap=hp FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.4.0\\npsitesafety.dll No File FF Plugin: @ei.VideoDownloadConverter_4z.com/Plugin -> C:\Program Files\VideoDownloadConverter_4zEI\Installr\2.bin\NP4zEISB.dll No File FF Plugin: @java.com/DTPlugin,version=10.15.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-03-04] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.15.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-03-04] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.69 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-09-10] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.69 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-09-10] (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-14] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-14] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1177238915-790525478-1801674531-1003: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-14] (Google Inc.) FF Plugin HKU\S-1-5-21-1177238915-790525478-1801674531-1003: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-14] (Google Inc.) FF user.js: detected! => C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\user.js [2013-05-31] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\avg-secure-search.xml [2015-03-05] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\babylon.xml [2013-05-31] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\BitGuard.xml [2013-05-31] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\BrowserProtect.xml [2013-05-31] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\delta.xml [2013-05-31] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\my-web-search.xml [2012-09-09] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\MyStart Search.xml [2012-09-09] FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\searchplugins\search-here.xml [2014-05-12] FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-03-05] FF Extension: incredibar.com - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\Extensions\[email protected] [2012-09-09] FF Extension: Default Tab - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2wh4d01t.default\Extensions\[email protected] [2013-11-16] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-25] FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox [2012-09-09] FF HKLM\...\Firefox\Extensions: [{8E9E3331-D360-4f87-8803-52DE43566502}] - C:\Program Files\Web Assistant\Firefox Chrome: ======= CHR HomePage: Default -> hxxp://google.bg/ CHR StartupUrls: Default -> "hxxp://google.bg/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default CHR Extension: (Google Wallet) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20] CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-09-09] CHR HKLM\...\Chrome\Extension: [kdidombaedgpfiiedeimiebkmbilgmlc] - C:\Program Files\DefaultTab\DefaultTab.crx [2013-02-12] CHR HKLM\...\Chrome\Extension: [lkemddiljapcmhicklfpcbpfffahfbja] - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\extensions\WebNavigation.crx [2013-05-31] StartMenuInternet: chrome.exe - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2000-01-01] (LSI Corporation) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4942384 2014-10-17] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.) R2 DefaultTabSearch; C:\Program Files\DefaultTab\DefaultTabSearch.exe [574464 2013-12-20] () [File not signed] R2 DeviceManager; C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe [40960 2009-11-17] () [File not signed] S3 Dot3svc; C:\WINDOWS\System32\dot3svc.dll [132096 2009-04-20] (Microsoft Corporation) [File not signed] S3 EapHost; C:\WINDOWS\System32\eapsvc.dll [33792 2008-04-14] (Microsoft Corporation) [File not signed] S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [67360 2010-01-25] (NOS Microsystems Ltd.) S3 hkmsvc; C:\WINDOWS\System32\kmsvc.dll [61440 2008-04-14] (Microsoft Corporation) [File not signed] R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [170912 2013-03-04] (Oracle Corporation) S3 napagent; C:\WINDOWS\System32\qagentrt.dll [291328 2008-04-14] (Microsoft Corporation) [File not signed] R2 UPHClean; C:\Program Files\UPHClean\uphclean.exe [241725 2005-04-27] (Microsoft Corporation) [File not signed] S2 uploadmgr; C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38912 2004-08-04] (Microsoft Corporation) R2 vToolbarUpdater18.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe [1875480 2015-03-05] (AVG Secure Search) R2 WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [620056 2015-03-05] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [208184 2013-11-25] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [22328 2013-10-23] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [172856 2014-11-04] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [39224 2013-10-23] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [182584 2014-10-17] (AVG Technologies CZ, s.r.o.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2004-08-03] (Microsoft Corporation) S3 DCamUSBSTK03N; C:\WINDOWS\System32\DRIVERS\STK03NW2.sys [108544 2010-01-05] (Syntek Ltd.) S4 exFat; C:\WINDOWS\system32\Drivers\exFat.sys [133632 2009-04-20] (Microsoft Corporation) [File not signed] S3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2009-12-14] () [File not signed] S3 FTDIBUS; C:\WINDOWS\System32\drivers\ftdibus.sys [57800 2009-10-22] (FTDI Ltd.) S3 jrdusbser; C:\WINDOWS\System32\DRIVERS\jrdusbser.sys [105344 2009-11-17] (TCT International Mobile Ltd) R0 MPRIFL; C:\WINDOWS\System32\DRIVERS\MPRIFL.SYS [17264 2007-12-13] (FSPro Labs) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2004-08-03] (Microsoft Corporation) R3 NETw4x32; C:\WINDOWS\System32\DRIVERS\NETw4x32.sys [2530176 2008-03-13] (Intel Corporation) S3 NPF; C:\WINDOWS\System32\drivers\NPF.sys [50704 2012-03-10] (CACE Technologies, Inc.) R0 pnpshark; C:\WINDOWS\System32\DRIVERS\pnpshark.sys [119552 2003-10-02] ( ) [File not signed] R2 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [163644 2007-04-16] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed] R0 st3shark; C:\WINDOWS\System32\DRIVERS\st3shark.sys [5504 2003-09-27] ( ) [File not signed] R0 TVALZ; C:\WINDOWS\System32\DRIVERS\TVALZ.SYS [16768 2005-12-26] (TOSHIBA Corporation) [File not signed] S2 5689; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\5689.sys [X] U4 Avgfwdx; system32\DRIVERS\avgfwdx.sys [X] S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96256 2004-08-04] (Microsoft Corporation) U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-19 23:27 - 2015-04-19 23:28 - 00000000 ____D () C:\FRST ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-19 23:30 - 2012-05-13 23:20 - 00000392 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{1CE6E4C0-8FD3-4F7B-B78F-E79A4CA6BEBA}.job 2015-04-19 23:30 - 2009-07-25 21:01 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Temp 2015-04-19 23:23 - 2012-09-15 11:56 - 00000978 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-790525478-1801674531-1003UA.job 2015-04-19 23:23 - 2010-04-05 21:12 - 00000986 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-19 23:11 - 2013-11-14 19:33 - 00001590 _____ () C:\WINDOWS\setupact.log 2015-04-19 23:00 - 2013-06-17 12:49 - 00000300 _____ () C:\WINDOWS\Tasks\AdobeFlashPlayerUpdate.job 2015-04-19 22:45 - 2014-11-26 15:37 - 00044858 _____ () C:\Documents and Settings\Owner\debug.log 2015-04-19 22:45 - 2009-07-25 20:58 - 01931547 _____ () C:\WINDOWS\WindowsUpdate.log 2015-04-19 22:44 - 2013-05-31 23:41 - 00000324 _____ () C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job 2015-04-19 22:44 - 2010-04-05 21:12 - 00000982 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-19 22:44 - 2009-07-25 15:50 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2015-04-19 22:44 - 2009-07-25 15:50 - 00000052 _____ () C:\WINDOWS\wiaservc.log 2015-04-19 22:43 - 2013-06-17 12:49 - 00000300 _____ () C:\WINDOWS\Tasks\AdobeFlashPlayerUpdate 2.job 2015-04-19 22:43 - 2009-07-25 21:01 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-04-19 22:42 - 2009-07-25 21:01 - 00032140 _____ () C:\WINDOWS\SchedLgU.Txt 2015-04-19 22:41 - 2009-07-25 21:01 - 00000178 __SHC () C:\Documents and Settings\Owner\ntuser.ini 2015-04-19 22:34 - 2012-05-13 15:24 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-04-19 22:17 - 2013-09-10 00:21 - 00000292 _____ () C:\WINDOWS\Tasks\CPU Grid Computing.job 2015-04-19 20:39 - 2013-12-04 20:10 - 00002282 _____ () C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk 2015-04-19 18:55 - 2013-08-17 10:19 - 00890267 ____C () C:\WINDOWS\setupapi.log 2015-04-19 18:43 - 2013-11-20 22:12 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData 2015-04-19 17:27 - 2012-09-09 22:14 - 00000000 ____D () C:\Program Files\Web Assistant 2015-04-19 16:50 - 2013-06-17 12:49 - 00000000 ____D () C:\Documents and Settings\Owner\Application Data\File Scout 2015-04-19 16:23 - 2012-09-15 11:56 - 00000926 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-790525478-1801674531-1003Core.job 2015-04-19 15:51 - 2014-01-13 23:57 - 00000000 ____D () C:\WINDOWS\system32\CatRoot_bak 2015-04-19 15:51 - 2013-11-21 00:19 - 00586716 ____C () C:\WINDOWS\svcpack.log 2015-04-19 14:51 - 2014-11-21 12:46 - 00000000 ____D () C:\Program Files\AVG Web TuneUp 2015-04-19 14:31 - 2008-04-14 15:00 - 00002228 _____ () C:\WINDOWS\system32\wpa.dbl 2015-04-05 23:29 - 2009-07-25 15:47 - 00529570 _____ () C:\WINDOWS\system32\PerfStringBackup.INI ==================== Files in the root of some directories ======= 2009-11-17 21:00 - 2009-11-17 21:00 - 0002528 ____C () C:\Documents and Settings\Owner\Application Data\$_hpcst$.hpc 2012-09-24 18:17 - 2012-10-04 23:13 - 0000184 ____C () C:\Documents and Settings\Owner\Application Data\default.rss 2009-07-26 01:14 - 2014-05-12 20:59 - 0179712 ____C () C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Files to move or delete: ==================== C:\Documents and Settings\Custom Settings\Apply Theme.vbs C:\Documents and Settings\Custom Settings\Auto Config.bat C:\Documents and Settings\Custom Settings\IE Favorite Links.bat C:\Documents and Settings\Custom Settings\IExpress Shortcut Creator.vbs C:\Documents and Settings\Custom Settings\System Settings.bat C:\Documents and Settings\Custom Settings\System Settings.reg C:\Documents and Settings\Custom Settings\TaskBarCmd v1.1.exe C:\Documents and Settings\Custom Settings\User Settings.bat C:\Documents and Settings\Custom Settings\User Settings.reg C:\Documents and Settings\Custom Settings\WMP Shortcut Creator.vbs Some content of TEMP: ==================== C:\Documents and Settings\Owner\Local Settings\Temp\uninst1.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ Addition.txt
  15. Здравейте, В последните 2 дни компютъра ми се забави значително, и когато се опитах да отворя Task Manager, той се появява за секунда и после изчезва. Постепенно разбрах, че вече не мога да стартирам и други програми: Internet Explorer, WinRar, CrapCleaner. Пробвах да сканирам за вируси с антивирусната (Comodo), но тя не откри нищо. Предположих, че става дума за Malware и свалих Malwarebytes, той ужким откри някакви съмнителни обекти, които изчисти, но нищо не се промени. След 2 дни напразни опити, реших да преинсталирам с нов Windows 7, но дори с него проблема с TaskManager-a остава, а за капак, прясно инсталираната Opera не се стартира изобщо. Май се оказва, че вие сте ми последна инстанция, така че ви моля за помощ. Имам флашка с Windows 7, от която инсталирах настоящия. Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-04-2015 01 Ran by Adrian (administrator) on ADRIAN-PC on 01-05-2015 23:48:02 Running from C:\Users\Adrian\Downloads Loaded Profiles: Adrian & UpdatusUser & (Available profiles: Adrian & UpdatusUser) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Comodo) C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe () C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor) HKLM\...\Run: [intelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel® Corporation) HKLM\...\Run: [synTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2712360 2011-03-21] (Synaptics Incorporated) HKLM\...\Run: [updatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2015-05-01] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2015-05-01] (Lenovo(beijing) Limited) HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2015-05-01] (Lenovo) HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1426136 2015-04-01] (COMODO) HKLM-x32\...\Run: [iAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation) HKLM-x32\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe HKLM-x32\...\Run: [updatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-09-17] (Comodo Security Solutions, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3279574703-4203599334-783653948-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1371456 2015-05-01] (Lavasoft) HKU\S-1-5-21-3279574703-4203599334-783653948-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1371456 2015-05-01] (Lavasoft) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [226920 2011-05-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [193128 2011-05-10] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-05-01] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-05-01] ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-3279574703-4203599334-783653948-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3279574703-4203599334-783653948-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp HKU\S-1-5-21-3279574703-4203599334-783653948-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3279574703-4203599334-783653948-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-3279574703-4203599334-783653948-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-3279574703-4203599334-783653948-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation) Winsock: Catalog9 01 C:\Windows\SysWOW64\LavasoftTcpService.dll [326288 2015-05-01] (Lavasoft Limited) Winsock: Catalog9 02 C:\Windows\SysWOW64\LavasoftTcpService.dll [326288 2015-05-01] (Lavasoft Limited) Winsock: Catalog9 03 C:\Windows\SysWOW64\LavasoftTcpService.dll [326288 2015-05-01] (Lavasoft Limited) Winsock: Catalog9 04 C:\Windows\SysWOW64\LavasoftTcpService.dll [326288 2015-05-01] (Lavasoft Limited) Winsock: Catalog9 16 C:\Windows\SysWOW64\LavasoftTcpService.dll [326288 2015-05-01] (Lavasoft Limited) Winsock: Catalog9-x64 01 C:\Windows\system32\LavasoftTcpService64.dll [373864 2015-05-01] (Lavasoft Limited) Winsock: Catalog9-x64 02 C:\Windows\system32\LavasoftTcpService64.dll [373864 2015-05-01] (Lavasoft Limited) Winsock: Catalog9-x64 03 C:\Windows\system32\LavasoftTcpService64.dll [373864 2015-05-01] (Lavasoft Limited) Winsock: Catalog9-x64 04 C:\Windows\system32\LavasoftTcpService64.dll [373864 2015-05-01] (Lavasoft Limited) Winsock: Catalog9-x64 16 C:\Windows\system32\LavasoftTcpService64.dll [373864 2015-05-01] (Lavasoft Limited) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{A94441A0-EBA3-48BF-A097-38BAE3E00A0E}: [NameServer] 156.154.70.25,156.154.71.25 Tcpip\..\Interfaces\{D7D41A67-8685-4627-8865-F8982B35AD53}: [NameServer] 156.154.70.25,156.154.71.25 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\vom36hqi.default FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\911bg.xml [2015-04-16] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\diribg.xml [2015-04-16] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pe-bg.xml [2015-04-16] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-04-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [970016 2011-05-12] (Broadcom Corporation.) R2 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [2306248 2015-05-01] (Comodo) R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70864 2014-09-17] (Comodo Security Solutions, Inc.) R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5540424 2015-04-01] (COMODO) R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265816 2015-04-01] (COMODO) R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-09-17] (Comodo Security Solutions, Inc.) R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe [833888 2015-04-27] (Lavasoft Limited) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-05-01] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () R2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [17768 2015-05-01] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-13] (Broadcom Corporation.) R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2014-06-26] (Windows ® Win 7 DDK provider) [File not signed] R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20696 2015-04-01] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [797280 2015-04-01] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45880 2015-04-01] (COMODO) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [104608 2015-04-01] (COMODO) R3 JmUsbCcgp; C:\Windows\System32\DRIVERS\jmccgp.sys [17880 2010-07-21] (JMicron Technology Corp.) R3 JmUsbVideo; C:\Windows\System32\Drivers\jmcam.sys [57816 2010-08-27] (JMicron Technology Corp.) R3 JmUsbVideo2; C:\Windows\System32\Drivers\jmcam_lo.sys [32088 2010-08-27] (JMicron Technology Corp.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-05-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-01] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-05-01] (Malwarebytes Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-02 04:45 - 2015-05-01 17:50 - 00000000 ____D () C:\Windows\Panther 2015-05-01 23:48 - 2015-05-01 23:48 - 00014226 _____ () C:\Users\Adrian\Downloads\FRST.txt 2015-05-01 23:47 - 2015-05-01 23:48 - 00000000 ____D () C:\FRST 2015-05-01 23:46 - 2015-05-01 23:46 - 02101248 _____ (Farbar) C:\Users\Adrian\Downloads\FRST64.exe 2015-05-01 23:46 - 2015-05-01 23:46 - 00002330 _____ () C:\Windows\system32\Drivers\fvstore.dat 2015-05-01 23:04 - 2015-05-01 23:35 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-01 23:04 - 2015-05-01 23:04 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-05-01 23:04 - 2015-05-01 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-05-01 23:04 - 2015-05-01 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-05-01 23:04 - 2015-05-01 23:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-05-01 23:04 - 2015-05-01 23:04 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-05-01 23:04 - 2015-05-01 23:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-05-01 22:49 - 2015-05-01 22:49 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-05-01 22:49 - 2015-05-01 22:49 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-05-01 22:49 - 2015-05-01 22:49 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Mozilla 2015-05-01 22:49 - 2015-05-01 22:49 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Mozilla 2015-05-01 22:49 - 2015-05-01 22:49 - 00000000 ____D () C:\ProgramData\Mozilla 2015-05-01 22:49 - 2015-05-01 22:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-05-01 22:49 - 2015-05-01 22:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-05-01 22:20 - 2015-05-01 22:32 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-05-01 22:20 - 2015-05-01 22:20 - 00003824 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1430508049 2015-05-01 22:20 - 2015-05-01 22:20 - 00001135 _____ () C:\Users\Public\Desktop\Opera.lnk 2015-05-01 22:20 - 2015-05-01 22:20 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-05-01 22:20 - 2015-05-01 22:20 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Opera Software 2015-05-01 22:20 - 2015-05-01 22:20 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Opera Software 2015-05-01 22:18 - 2015-05-01 22:18 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Lavasoft 2015-05-01 22:18 - 2015-05-01 22:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2015-05-01 22:18 - 2015-05-01 22:18 - 00000000 ____D () C:\Program Files (x86)\Lavasoft 2015-05-01 22:18 - 2015-04-27 21:39 - 00373864 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService64.dll 2015-05-01 22:18 - 2015-04-27 21:39 - 00326288 _____ (Lavasoft Limited) C:\Windows\SysWOW64\LavasoftTcpService.dll 2015-05-01 22:17 - 2015-05-01 22:17 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Lavasoft 2015-05-01 22:17 - 2015-05-01 22:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc 2015-05-01 22:17 - 2015-05-01 22:17 - 00000000 ____D () C:\ProgramData\Lavasoft 2015-05-01 22:17 - 2015-05-01 22:17 - 00000000 ____D () C:\Program Files (x86)\IZArc 2015-05-01 22:15 - 2015-05-01 22:15 - 00000000 ____D () C:\Users\Adrian\AppData\Local\CrashRpt 2015-05-01 22:08 - 2015-05-01 22:08 - 00000833 _____ () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2015-05-01 22:07 - 2015-05-01 22:09 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\uTorrent 2015-05-01 22:04 - 2015-05-01 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2015-05-01 22:04 - 2015-05-01 22:04 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2015-05-01 21:48 - 2015-05-01 23:47 - 00711393 _____ () C:\Windows\system32\Drivers\sfi.dat 2015-05-01 21:48 - 2015-05-01 23:08 - 00027400 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll 2015-05-01 21:48 - 2015-05-01 23:08 - 00024328 _____ (COMODO CA Limited) C:\Windows\SysWOW64\certsentry.dll 2015-05-01 21:48 - 2015-05-01 23:08 - 00024296 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.exe 2015-05-01 21:48 - 2015-05-01 23:08 - 00001928 _____ () C:\Windows\System32\Tasks\COMODO CertSentry Updater 2015-05-01 21:48 - 2015-05-01 21:48 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO 2015-05-01 21:48 - 2015-05-01 21:48 - 00000000 ____D () C:\Program Files (x86)\Comodo 2015-05-01 21:47 - 2015-05-01 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo 2015-05-01 21:47 - 2015-05-01 21:47 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Comodo 2015-05-01 21:47 - 2015-05-01 21:47 - 00000000 ____D () C:\ProgramData\Shared Space 2015-05-01 21:47 - 2015-05-01 21:47 - 00000000 ____D () C:\Program Files\COMODO 2015-05-01 21:44 - 2015-05-01 21:48 - 00000000 ____D () C:\ProgramData\Comodo 2015-05-01 21:36 - 2014-05-14 19:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-05-01 21:36 - 2014-05-14 19:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-05-01 21:36 - 2014-05-14 19:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-05-01 21:36 - 2014-05-14 19:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-05-01 21:35 - 2014-05-14 19:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-05-01 21:35 - 2014-05-14 19:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-05-01 21:35 - 2014-05-14 19:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-05-01 21:35 - 2014-05-14 19:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-05-01 21:35 - 2014-05-14 19:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-05-01 21:35 - 2014-05-14 19:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-05-01 21:35 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-05-01 21:35 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-05-01 21:35 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-05-01 21:35 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-05-01 21:23 - 2015-05-01 21:22 - 00279968 _____ (Lenovo) C:\Windows\system32\LenovoSdk.OKTDLL.dll 2015-05-01 21:20 - 2015-05-01 21:20 - 00000000 ____D () C:\Program Files\DIFX 2015-05-01 21:20 - 2015-05-01 21:19 - 00039008 _____ (Lenovo.) C:\Windows\system32\Drivers\LhdX64.sys 2015-05-01 21:20 - 2015-05-01 21:19 - 00019872 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoSDKEmSubSystem.dll 2015-05-01 21:19 - 2015-05-01 21:23 - 00000000 ____D () C:\Program Files (x86)\Lenovo 2015-05-01 21:19 - 2015-05-01 21:22 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Downloaded Installations 2015-05-01 21:18 - 2015-05-01 21:24 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2015-05-01 21:18 - 2015-05-01 21:21 - 00002086 _____ () C:\Users\Adrian\Desktop\OneKey Recovery.lnk 2015-05-01 21:18 - 2015-05-01 21:18 - 00002104 _____ () C:\Users\UpdatusUser\Desktop\OneKey Recovery.lnk 2015-05-01 21:18 - 2015-05-01 21:18 - 00002104 _____ () C:\Users\Default\Desktop\OneKey Recovery.lnk 2015-05-01 21:18 - 2015-05-01 21:18 - 00002104 _____ () C:\Users\Default User\Desktop\OneKey Recovery.lnk 2015-05-01 21:18 - 2015-05-01 21:18 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2015-05-01 21:18 - 2015-05-01 21:18 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2015-05-01 21:18 - 2015-05-01 21:18 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2015-05-01 21:18 - 2015-05-01 21:18 - 00000000 ____D () C:\ProgramData\OneKey Recovery 2015-05-01 21:16 - 2015-05-01 21:16 - 00000000 ____D () C:\ProgramData\Temp 2015-05-01 21:13 - 2015-05-01 21:13 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2015-05-01 21:13 - 2015-05-01 21:13 - 00000000 ____D () C:\Program Files\Synaptics 2015-05-01 21:13 - 2011-03-21 08:42 - 01413168 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2015-05-01 21:13 - 2011-03-21 08:40 - 00276264 _____ (Synaptics Incorporated) C:\Windows\system32\SynCtrl.dll 2015-05-01 21:13 - 2011-03-21 08:40 - 00225576 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2015-05-01 21:13 - 2011-03-21 08:40 - 00222504 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCtrl.dll 2015-05-01 21:13 - 2011-03-21 08:40 - 00173352 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCOM.dll 2015-05-01 21:13 - 2011-03-21 08:40 - 00148264 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo9.dll 2015-05-01 21:13 - 2011-03-21 08:40 - 00107816 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCOM.dll 2015-05-01 21:13 - 2011-03-21 08:40 - 00066856 _____ () C:\Windows\SysWOW64\SynTPEnhPS.dll 2015-05-01 21:13 - 2009-08-07 05:49 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2015-05-01 21:11 - 2015-05-01 21:11 - 00000000 ____D () C:\Windows\SysWOW64\SDA 2015-05-01 21:11 - 2015-05-01 21:11 - 00000000 ____D () C:\Program Files (x86)\JMicron 2015-05-01 21:11 - 2010-12-13 06:31 - 00174168 _____ (JMicron Technology Corporation) C:\Windows\system32\Drivers\jmcr.sys 2015-05-01 21:11 - 2010-07-27 05:08 - 00203352 _____ (JMicron Technology Corporation) C:\Windows\SysWOW64\jmcricon.dll 2015-05-01 21:11 - 2010-07-27 05:08 - 00203352 _____ (JMicron Technology Corporation) C:\Windows\system32\jmcricon.dll 2015-05-01 21:08 - 2010-08-27 17:43 - 00032088 _____ (JMicron Technology Corp.) C:\Windows\system32\Drivers\jmcam_lo.sys 2015-05-01 21:08 - 2010-08-27 16:36 - 00280664 _____ (JMicron Technology Corp.) C:\Windows\system32\jmcam.ax 2015-05-01 21:08 - 2010-08-27 16:36 - 00219736 _____ (JMicron Technology Corp.) C:\Windows\SysWOW64\jmcam.ax 2015-05-01 21:08 - 2010-08-27 14:01 - 00057816 _____ (JMicron Technology Corp.) C:\Windows\system32\Drivers\jmcam.sys 2015-05-01 21:08 - 2010-07-21 10:28 - 00642136 _____ (JMicron Technology Corp.) C:\Windows\system32\jmcamInst.dll 2015-05-01 21:08 - 2010-07-21 10:28 - 00615000 _____ (JMicron Technology Corp.) C:\Windows\system32\jmccgpInst.dll 2015-05-01 21:08 - 2010-07-21 10:28 - 00017880 _____ (JMicron Technology Corp.) C:\Windows\system32\Drivers\jmccgp.sys 2015-05-01 21:08 - 2009-04-23 15:37 - 00272896 _____ ( ) C:\Windows\rsnp2uvc.dll 2015-05-01 21:07 - 2015-05-01 21:07 - 00764126 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-05-01 21:04 - 2015-05-01 21:04 - 00000000 ____D () C:\Users\Adrian\Documents\Bluetooth Exchange Folder 2015-05-01 21:04 - 2015-05-01 21:04 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Broadcom 2015-05-01 21:03 - 2015-05-01 21:03 - 00001283 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyBits Chat.lnk 2015-05-01 21:03 - 2011-05-13 03:01 - 00437288 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys 2015-05-01 21:03 - 2011-05-13 03:01 - 00164392 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys 2015-05-01 21:03 - 2011-05-13 03:01 - 00150568 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys 2015-05-01 21:03 - 2011-05-13 03:01 - 00089640 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwdpan.sys 2015-05-01 21:03 - 2011-05-13 03:01 - 00039976 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys 2015-05-01 21:03 - 2011-05-13 03:01 - 00022056 _____ (Broadcom Corporation.) C:\Windows\system32\btwcoins.dll 2015-05-01 21:03 - 2011-05-13 03:01 - 00021544 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys 2015-05-01 21:02 - 2015-05-01 21:20 - 00000000 ____D () C:\Program Files\Lenovo 2015-05-01 21:01 - 2015-05-01 21:01 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Intel 2015-05-01 21:00 - 2015-05-01 21:20 - 00012658 _____ () C:\Windows\DPINST.LOG 2015-05-01 21:00 - 2015-05-01 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless 2015-05-01 21:00 - 2015-05-01 21:00 - 00000000 ____D () C:\ProgramData\Intel 2015-05-01 21:00 - 2015-05-01 21:00 - 00000000 ____D () C:\Program Files\Intel 2015-05-01 21:00 - 2015-05-01 21:00 - 00000000 ____D () C:\Program Files (x86)\Cisco 2015-05-01 20:52 - 2015-05-01 21:07 - 00000000 ____D () C:\Program Files\Broadcom 2015-05-01 20:51 - 2015-05-01 20:51 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2015-05-01 20:51 - 2015-05-01 20:51 - 00000000 ____D () C:\Windows\system32\SRSLabs 2015-05-01 20:51 - 2015-05-01 20:51 - 00000000 ____D () C:\Program Files\Realtek 2015-05-01 20:51 - 2015-05-01 20:51 - 00000000 ____D () C:\Program Files (x86)\Realtek 2015-05-01 20:51 - 2011-03-29 14:24 - 02819560 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2015-05-01 20:51 - 2011-03-28 11:39 - 02931816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2015-05-01 20:51 - 2011-03-24 11:03 - 00084584 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll 2015-05-01 20:51 - 2011-03-15 10:32 - 00648808 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2015-05-01 20:51 - 2011-03-10 06:32 - 02369640 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2015-05-01 20:51 - 2011-03-02 12:25 - 01242216 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2015-05-01 20:51 - 2011-02-22 10:52 - 02075712 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2015-05-01 20:51 - 2010-11-08 02:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2015-05-01 20:51 - 2010-11-08 02:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2015-05-01 20:51 - 2010-11-08 02:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2015-05-01 20:51 - 2010-11-08 02:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2015-05-01 20:51 - 2010-11-08 02:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2015-05-01 20:51 - 2010-11-08 02:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2015-05-01 20:51 - 2010-11-03 13:31 - 01146984 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2015-05-01 20:51 - 2010-11-03 13:31 - 00332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2015-05-01 20:51 - 2010-11-03 13:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2015-05-01 20:51 - 2010-07-22 11:37 - 00200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2015-05-01 20:51 - 2009-11-17 13:12 - 00108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2015-05-01 20:50 - 2015-05-01 20:51 - 00000000 ___HD () C:\Program Files (x86)\Temp 2015-05-01 20:50 - 2011-02-25 14:37 - 01284712 ____R (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2015-05-01 20:47 - 2015-05-01 21:09 - 00000000 ____D () C:\Windows\SysWOW64\NV 2015-05-01 20:47 - 2015-05-01 21:09 - 00000000 ____D () C:\Windows\system32\NV 2015-05-01 20:46 - 2015-05-01 20:47 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-05-01 20:46 - 2015-05-01 20:46 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini 2015-05-01 20:46 - 2009-07-14 07:54 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-01 20:46 - 2009-07-14 07:49 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-05-01 20:45 - 2015-05-01 20:46 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-05-01 20:45 - 2015-05-01 20:45 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-05-01 20:45 - 2011-05-10 07:00 - 20460648 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 18580072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 15051368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 13071592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-05-01 20:45 - 2011-05-10 07:00 - 13011560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 12840040 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 10059880 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 08105576 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 06597736 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 06029928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 04936808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 03182184 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 02954856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 02871400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 02579560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 02206824 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 01969768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 01625704 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6420140.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 01368680 _____ (NVIDIA Corporation) C:\Windows\system32\nvgenco642050.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00764008 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00645736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00446056 _____ (NVIDIA Corporation) C:\Windows\system32\nvoptimusmft.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00391784 _____ (NVIDIA Corporation) C:\Windows\system32\nvdecodemft.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00380520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoptimusmft.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00320104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00226920 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00193128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00067176 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00057960 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2015-05-01 20:45 - 2011-05-10 07:00 - 00025960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2015-05-01 20:45 - 2011-05-10 07:00 - 00011240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvBridge.kmd 2015-05-01 20:45 - 2011-05-10 07:00 - 00007621 _____ () C:\Windows\system32\nvinfo.pb 2015-05-01 20:44 - 2015-05-01 20:46 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-05-01 20:42 - 2015-05-01 21:21 - 00060368 _____ () C:\Users\Adrian\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-01 20:42 - 2015-05-01 20:42 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Intel Corporation 2015-05-01 20:41 - 2015-05-01 20:41 - 00015812 _____ () C:\Windows\system32\results.xml 2015-05-01 20:40 - 2015-05-01 21:00 - 00000000 ____D () C:\Program Files\Common Files\Intel 2015-05-01 20:40 - 2011-03-30 05:10 - 04370456 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe 2015-05-01 20:40 - 2011-03-30 05:10 - 00509976 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2015-05-01 20:40 - 2011-03-30 05:10 - 00418840 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe 2015-05-01 20:40 - 2011-03-30 05:10 - 00391704 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe 2015-05-01 20:40 - 2011-03-30 05:10 - 00239128 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe 2015-05-01 20:40 - 2011-03-30 05:10 - 00179736 _____ () C:\Windows\system32\difx64.exe 2015-05-01 20:40 - 2011-03-30 05:10 - 00167960 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe 2015-05-01 20:40 - 2011-03-26 04:36 - 00013488 _____ () C:\Windows\system32\iglhxs64.vp 2015-05-01 20:40 - 2011-03-26 04:24 - 00090112 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v2342.dll 2015-05-01 20:40 - 2011-03-26 04:17 - 12262336 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2015-05-01 20:40 - 2011-03-26 04:17 - 07473664 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll 2015-05-01 20:40 - 2011-03-26 04:16 - 00963116 _____ () C:\Windows\SysWOW64\igkrng600.bin 2015-05-01 20:40 - 2011-03-26 04:16 - 00963116 _____ () C:\Windows\system32\igkrng600.bin 2015-05-01 20:40 - 2011-03-26 04:16 - 00216876 _____ () C:\Windows\SysWOW64\igfcg600m.bin 2015-05-01 20:40 - 2011-03-26 04:16 - 00216876 _____ () C:\Windows\system32\igfcg600m.bin 2015-05-01 20:40 - 2011-03-26 04:16 - 00145804 _____ () C:\Windows\SysWOW64\igcompkrng600.bin 2015-05-01 20:40 - 2011-03-26 04:16 - 00145804 _____ () C:\Windows\system32\igcompkrng600.bin 2015-05-01 20:40 - 2011-03-26 04:12 - 05692416 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll 2015-05-01 20:40 - 2011-03-26 04:08 - 00575488 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumdx32.dll 2015-05-01 20:40 - 2011-03-26 04:05 - 07386624 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll 2015-05-01 20:40 - 2011-03-26 04:02 - 06068736 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2015-05-01 20:40 - 2011-03-26 03:54 - 19592704 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2015-05-01 20:40 - 2011-03-26 03:45 - 14294016 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2015-05-01 20:40 - 2011-03-26 03:41 - 00208335 _____ () C:\Windows\system32\Gfxres.th-TH.resources 2015-05-01 20:40 - 2011-03-26 03:41 - 00135119 _____ () C:\Windows\system32\Gfxres.ro-RO.resources 2015-05-01 20:40 - 2011-03-26 03:41 - 00133868 _____ () C:\Windows\system32\Gfxres.tr-TR.resources 2015-05-01 20:40 - 2011-03-26 03:41 - 00132422 _____ () C:\Windows\system32\Gfxres.sv-SE.resources 2015-05-01 20:40 - 2011-03-26 03:41 - 00130414 _____ () C:\Windows\system32\Gfxres.hr-HR.resources 2015-05-01 20:40 - 2011-03-26 03:41 - 00116413 _____ () C:\Windows\system32\Gfxres.zh-TW.resources 2015-05-01 20:40 - 2011-03-26 03:41 - 00115195 _____ () C:\Windows\system32\Gfxres.zh-CN.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00287232 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00287232 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00287232 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00285696 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00285696 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00285184 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00285184 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00283648 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00283136 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00282624 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00282624 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2015-05-01 20:40 - 2011-03-26 03:40 - 00195681 _____ () C:\Windows\system32\Gfxres.el-GR.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00180246 _____ () C:\Windows\system32\Gfxres.ru-RU.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00154366 _____ () C:\Windows\system32\Gfxres.ar-SA.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00151350 _____ () C:\Windows\system32\Gfxres.ja-JP.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00147392 _____ () C:\Windows\system32\Gfxres.he-IL.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00138635 _____ () C:\Windows\system32\Gfxres.it-IT.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00137000 _____ () C:\Windows\system32\Gfxres.ko-KR.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00136226 _____ () C:\Windows\system32\Gfxres.de-DE.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00136172 _____ () C:\Windows\system32\Gfxres.es-ES.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00134081 _____ () C:\Windows\system32\Gfxres.fr-FR.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00133321 _____ () C:\Windows\system32\Gfxres.pt-BR.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00132876 _____ () C:\Windows\system32\Gfxres.nl-NL.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00132861 _____ () C:\Windows\system32\Gfxres.hu-HU.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00132299 _____ () C:\Windows\system32\Gfxres.pt-PT.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00131897 _____ () C:\Windows\system32\Gfxres.cs-CZ.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00131711 _____ () C:\Windows\system32\Gfxres.pl-PL.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00131456 _____ () C:\Windows\system32\Gfxres.fi-FI.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00131290 _____ () C:\Windows\system32\Gfxres.sk-SK.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00127599 _____ () C:\Windows\system32\Gfxres.sl-SI.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00127367 _____ () C:\Windows\system32\Gfxres.nb-NO.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00127109 _____ () C:\Windows\system32\Gfxres.da-DK.resources 2015-05-01 20:40 - 2011-03-26 03:40 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2015-05-01 20:40 - 2011-03-26 03:40 - 00122646 _____ () C:\Windows\system32\Gfxres.en-US.resources 2015-05-01 20:40 - 2011-03-26 03:39 - 00380928 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2015-05-01 20:40 - 2011-03-26 03:39 - 00335872 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll 2015-05-01 20:40 - 2011-03-26 03:39 - 00062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2015-05-01 20:40 - 2011-03-26 03:39 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll 2015-05-01 20:40 - 2011-03-26 03:38 - 09014784 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll 2015-05-01 20:40 - 2011-03-26 03:38 - 00385024 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll 2015-05-01 20:40 - 2011-03-26 03:38 - 00285696 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2015-05-01 20:40 - 2011-03-26 03:38 - 00144896 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2015-05-01 20:40 - 2011-03-26 03:38 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll 2015-05-01 20:40 - 2011-03-26 03:38 - 00109056 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll 2015-05-01 20:40 - 2011-03-26 03:38 - 00004096 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll 2015-05-01 20:40 - 2011-03-26 03:34 - 00024576 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2015-05-01 20:40 - 2011-03-26 03:33 - 00288768 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 01991936 _____ () C:\Windows\system32\iglhxa64.cpa 2015-05-01 20:40 - 2011-03-26 03:28 - 00368640 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00364032 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00142848 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00122368 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00095744 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00086528 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll 2015-05-01 20:40 - 2011-03-26 03:28 - 00060254 _____ () C:\Windows\system32\iglhxg64.vp 2015-05-01 20:40 - 2011-03-26 03:28 - 00060226 _____ () C:\Windows\system32\iglhxc64.vp 2015-05-01 20:40 - 2011-03-26 03:28 - 00060015 _____ () C:\Windows\system32\iglhxo64.vp 2015-05-01 20:40 - 2010-10-15 11:28 - 00317440 _____ (Intel® Corporation) C:\Windows\system32\Drivers\IntcDAud.sys 2015-05-01 20:40 - 2010-10-15 11:27 - 00014848 _____ (Intel® Corporation) C:\Windows\system32\IntcDAuC.dll 2015-05-01 20:38 - 2010-12-21 05:08 - 00008192 ____R () C:\Windows\system32\Drivers\IntelMEFWVer.dll 2015-05-01 20:37 - 2015-05-01 20:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2015-05-01 20:36 - 2015-05-01 21:23 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-05-01 20:36 - 2015-05-01 20:36 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\InstallShield 2015-05-01 20:36 - 2011-01-12 17:51 - 00439320 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys 2015-05-01 20:33 - 2015-05-01 20:40 - 00000000 ____D () C:\Program Files (x86)\Intel 2015-05-01 20:33 - 2010-12-23 06:09 - 00053248 ____R (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2015-05-01 20:32 - 2015-05-01 20:39 - 00000000 ____D () C:\Intel 2015-05-01 17:51 - 2015-05-01 22:14 - 00001633 _____ () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-05-01 17:51 - 2015-05-01 22:14 - 00001611 _____ () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2015-05-01 17:50 - 2015-05-01 21:01 - 00000000 ____D () C:\Users\Adrian 2015-05-01 17:50 - 2015-05-01 17:50 - 00000020 ___SH () C:\Users\Adrian\ntuser.ini 2015-05-01 17:50 - 2015-05-01 17:50 - 00000000 __SHD () C:\Recovery 2015-05-01 17:50 - 2015-05-01 17:50 - 00000000 ____D () C:\Users\Adrian\AppData\Local\VirtualStore 2015-05-01 17:50 - 2009-07-14 07:54 - 00000000 ___RD () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-01 17:50 - 2009-07-14 07:49 - 00000000 ___RD () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-05-01 17:48 - 2015-05-01 23:48 - 00651931 _____ () C:\Windows\WindowsUpdate.log 2015-05-01 17:48 - 2015-05-01 17:48 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2015-05-01 17:48 - 2015-05-01 17:48 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-05-01 17:47 - 2015-05-01 17:47 - 00001355 _____ () C:\Windows\TSSysprep.log 2015-04-01 18:49 - 2015-04-01 18:49 - 00797280 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2015-04-01 18:49 - 2015-04-01 18:49 - 00104608 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys 2015-04-01 18:49 - 2015-04-01 18:49 - 00045880 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys 2015-04-01 18:49 - 2015-04-01 18:49 - 00020696 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys 2015-04-01 18:48 - 2015-04-01 18:48 - 00576848 _____ (COMODO) C:\Windows\system32\guard64.dll 2015-04-01 18:48 - 2015-04-01 18:48 - 00444472 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll 2015-04-01 18:48 - 2015-04-01 18:48 - 00041248 _____ (COMODO) C:\Windows\system32\cmdcsr.dll 2015-04-01 18:47 - 2015-04-01 18:47 - 00358104 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll 2015-04-01 18:46 - 2015-04-01 18:46 - 00045784 _____ (COMODO) C:\Windows\system32\cmdkbd64.dll 2015-04-01 18:45 - 2015-04-01 18:45 - 00288472 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2015-04-01 18:45 - 2015-04-01 18:45 - 00040664 _____ (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-02 04:44 - 2009-07-14 08:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2015-05-02 04:44 - 2009-07-14 08:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2015-05-01 23:34 - 2009-07-14 08:13 - 00778332 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-01 23:27 - 2010-11-21 06:47 - 00016908 _____ () C:\Windows\PFRO.log 2015-05-01 23:27 - 2009-07-14 08:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-01 23:27 - 2009-07-14 07:51 - 00027031 _____ () C:\Windows\setupact.log 2015-05-01 23:26 - 2009-07-14 07:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-01 23:26 - 2009-07-14 07:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-01 23:26 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\Vss 2015-05-01 21:36 - 2009-07-14 06:20 - 00000000 __RHD () C:\Users\Public\Libraries 2015-05-01 21:21 - 2009-07-14 07:45 - 00282960 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-05-01 21:19 - 2010-10-25 19:44 - 00029792 _____ (Lenovo Corporation) C:\Windows\system32\Drivers\AcpiVpc.sys 2015-05-01 21:04 - 2009-07-14 06:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-01 21:03 - 2009-07-14 08:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-05-01 21:01 - 2009-07-14 06:20 - 00000000 __RHD () C:\Users\Default 2015-05-01 20:46 - 2009-07-14 08:32 - 00000000 ____D () C:\Windows\system32\restore 2015-05-01 20:45 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\Help 2015-05-01 17:50 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\system32\Recovery 2015-05-01 17:50 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\rescache 2015-05-01 17:48 - 2009-07-14 07:46 - 00002790 _____ () C:\Windows\DtcInstall.log 2015-05-01 17:48 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\system32\sysprep Some content of TEMP: ==================== C:\Users\Adrian\AppData\Local\Temp\DIFxAPI.dll C:\Users\Adrian\AppData\Local\Temp\InstallGenieo.exe C:\Users\Adrian\AppData\Local\Temp\SpOrder.dll C:\Users\Adrian\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe C:\Users\Adrian\AppData\Local\Temp\_is1342.exe C:\Users\Adrian\AppData\Local\Temp\_is5D4B.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-01 17:45 ==================== End Of Log ============================ Addition.txt
  16. Това е от предишната ми тема -> https://www.kaldata.com/forums/topic/237666-проблем-с-браузъра-google-chrome/ http://i.imgur.com/7T5zTg0.png **ПС. Деинсталирах google chrome, но при опит на инсталиране отново на този браузър ми изписва, че не може да се свърже с интернет. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01Ran by Dobri (administrator) on DOBRI-PC on 27-01-2015 22:39:24Running from C:\Users\Dobri\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LEST1V6ILoaded Profiles: Dobri & UpdatusUser (Available profiles: Dobri & UpdatusUser)Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)Internet Explorer Version 11Boot Mode: NormalTutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe(Microsoft Corporation) C:\Windows\System32\audiodg.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe(Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe(Spotify Ltd) C:\Users\Dobri\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe(Skillbrains) C:\Program Files\Skillbrains\lightshot\5.2.0.17\Lightshot.exe(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe(Microsoft Corporation) C:\Windows\System32\msiexec.exe(IObit) C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashUtil9d.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)HKU\S-1-5-21-1190607394-2965296010-1725609816-1000\...\Run: [Spotify Web Helper] => C:\Users\Dobri\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-21] (Spotify Ltd)HKU\S-1-5-21-1190607394-2965296010-1725609816-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)HKU\S-1-5-21-1190607394-2965296010-1725609816-1000\...\MountPoints2: {50e52da2-cbc4-11e3-a250-0019662ff8fd} - G:\setup.exeCHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONHKU\S-1-5-21-1190607394-2965296010-1725609816-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehpBHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cabHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txtTcpip\..\Interfaces\{E3CA9F59-1FB1-474A-BD26-DDBD869A14DC}: [NameServer] 195.24.92.1 195.24.92.2 FireFox:========FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)FF Plugin: @microsoft.com/GENUINE -> disabled No FileFF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No FileFF Plugin: @t.garena.com/garenatalk -> D:\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll No FileFF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome:=======CHR StartupUrls: Profile 1 -> "hxxp://google.bg/"CHR Profile: C:\Users\Dobri\AppData\Local\Google\Chrome\User Data\DefaultCHR Extension: (Google Wallet) - C:\Users\Dobri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-27]CHR Profile: C:\Users\Dobri\AppData\Local\Google\Chrome\User Data\Profile 1CHR Extension: (Google Wallet) - C:\Users\Dobri\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-27]CHR Extension: (Adblock Plus) - C:\Users\Dobri\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ookcoahhikhembadmoepbhiepkmbjija [2015-01-27] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2724128 2015-01-16] (IObit)S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1903472 2014-12-18] (Electronic Arts)R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2014-03-12] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-04-24] (Disc Soft Ltd)S3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [18584 2014-04-29] (Echobit, LLC)S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2012-07-31] (Screaming Bee LLC)R4 AVGIDSDriver; system32\DRIVERS\avgidsdriverx.sys [X]R4 AVGIDSHX; system32\DRIVERS\avgidshx.sys [X]R4 AVGIDSShim; system32\DRIVERS\avgidsshimx.sys [X]R4 Avgrkx86; system32\DRIVERS\avgrkx86.sys [X]R4 Avgtdix; system32\DRIVERS\avgtdix.sys [X]S3 GGSAFERDriver; \??\D:\Garena Plus\Room\safedrv.sys [X]S2 NEWDRIVER; \??\C:\Windows\system32\WinVDEdrv6.sys [X]S3 VGPU; System32\drivers\rdvgkmd.sys [X]S3 XDva415; \??\C:\Windows\system32\XDva415.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 22:38 - 2015-01-27 22:39 - 00000000 ____D () C:\FRST2015-01-27 22:29 - 2015-01-27 22:29 - 00000000 __SHD () C:\Users\Dobri\AppData\Local\EmieUserList2015-01-27 22:29 - 2015-01-27 22:29 - 00000000 __SHD () C:\Users\Dobri\AppData\Local\EmieSiteList2015-01-27 22:29 - 2015-01-27 22:29 - 00000000 __SHD () C:\Users\Dobri\AppData\Local\EmieBrowserModeList2015-01-27 22:23 - 2015-01-27 22:23 - 00000840 _____ () C:\Windows\PFRO.log2015-01-27 22:22 - 2015-01-27 22:22 - 00003472 ____N () C:\bootsqm.dat2015-01-27 22:04 - 2015-01-27 22:23 - 00000056 _____ () C:\Windows\setupact.log2015-01-27 22:04 - 2015-01-27 22:04 - 00000000 _____ () C:\Windows\setuperr.log2015-01-27 21:46 - 2015-01-27 21:46 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\TuneUp Software2015-01-27 21:46 - 2015-01-27 21:46 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\AVG20152015-01-27 21:45 - 2015-01-27 22:35 - 00000000 ___HD () C:\$AVG2015-01-27 21:45 - 2015-01-27 22:35 - 00000000 ____D () C:\ProgramData\AVG20152015-01-27 21:44 - 2015-01-27 21:59 - 00000000 ____D () C:\Program Files\AVG2015-01-27 21:42 - 2015-01-27 22:37 - 00000000 ____D () C:\ProgramData\MFAData2015-01-27 21:42 - 2015-01-27 21:48 - 00000000 ____D () C:\Users\Dobri\AppData\Local\Avg20152015-01-27 21:42 - 2015-01-27 21:42 - 00000000 ____D () C:\Users\Dobri\AppData\Local\MFAData2015-01-27 19:34 - 2015-01-27 19:34 - 52899840 _____ () C:\Windows\system32\config\SOFTWARE.iobit2015-01-27 19:34 - 2015-01-27 19:34 - 30720000 _____ () C:\Windows\system32\config\COMPONENTS.iobit2015-01-27 19:34 - 2015-01-27 19:34 - 00180224 _____ () C:\Windows\system32\config\DEFAULT.iobit2015-01-27 19:34 - 2015-01-27 19:34 - 00061440 _____ () C:\Windows\system32\config\SAM.iobit2015-01-27 19:34 - 2015-01-27 19:34 - 00032768 _____ () C:\Windows\system32\config\SECURITY.iobit2015-01-27 19:31 - 2015-01-27 19:31 - 00000000 ____D () C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}2015-01-27 19:31 - 2015-01-27 19:31 - 00000000 ____D () C:\Program Files\Common Files\IObit2015-01-27 19:30 - 2015-01-27 22:35 - 00000000 ____D () C:\Program Files\IObit2015-01-27 19:22 - 2015-01-27 19:22 - 00001091 _____ () C:\Users\Dobri\Desktop\Opera.lnk2015-01-27 13:54 - 2015-01-27 13:54 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\Opera2015-01-27 13:54 - 2015-01-27 13:54 - 00000000 ____D () C:\Users\Dobri\AppData\Local\Opera2015-01-27 13:14 - 2015-01-27 13:25 - 00000000 ____D () C:\Windows\system32\MRT2015-01-27 13:07 - 2014-10-18 03:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll2015-01-27 13:07 - 2014-07-07 03:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll2015-01-27 13:07 - 2014-07-07 03:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe2015-01-27 13:07 - 2014-07-07 03:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe2015-01-27 13:07 - 2014-07-07 03:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll2015-01-27 12:54 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll2015-01-27 12:41 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll2015-01-27 12:41 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe2015-01-27 12:41 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe2015-01-27 12:41 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll2015-01-27 12:41 - 2012-07-26 05:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe2015-01-27 12:41 - 2012-07-26 05:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll2015-01-27 12:41 - 2012-07-26 05:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll2015-01-27 12:41 - 2012-07-26 05:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll2015-01-27 12:41 - 2012-07-26 05:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll2015-01-27 12:41 - 2012-07-26 04:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys2015-01-27 12:41 - 2012-07-26 04:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys2015-01-27 12:41 - 2012-06-02 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf2015-01-27 12:39 - 2015-01-27 12:39 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini2015-01-27 12:39 - 2013-01-31 11:00 - 02557728 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll2015-01-27 12:39 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories2015-01-27 12:39 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance2015-01-27 12:15 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll2015-01-27 12:15 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll2015-01-27 12:15 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll2015-01-27 12:15 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys2015-01-27 12:15 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys2015-01-27 12:15 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys2015-01-27 12:15 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS2015-01-27 12:15 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll2015-01-27 12:15 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll2015-01-27 12:15 - 2010-11-19 22:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe2015-01-27 12:14 - 2014-11-27 03:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll2015-01-27 12:14 - 2014-11-22 04:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll2015-01-27 12:14 - 2014-11-22 04:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb2015-01-27 12:14 - 2014-11-22 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll2015-01-27 12:14 - 2014-11-22 04:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll2015-01-27 12:14 - 2014-11-22 04:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll2015-01-27 12:14 - 2014-11-22 04:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll2015-01-27 12:14 - 2014-11-22 04:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll2015-01-27 12:14 - 2014-11-22 04:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll2015-01-27 12:14 - 2014-11-22 03:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll2015-01-27 12:14 - 2014-11-22 03:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll2015-01-27 12:14 - 2014-11-22 03:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll2015-01-27 12:14 - 2014-11-22 03:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe2015-01-27 12:14 - 2014-11-22 03:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe2015-01-27 12:14 - 2014-11-22 03:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll2015-01-27 12:14 - 2014-11-22 03:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe2015-01-27 12:14 - 2014-11-22 03:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll2015-01-27 12:14 - 2014-11-22 03:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll2015-01-27 12:14 - 2014-11-22 03:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll2015-01-27 12:14 - 2014-11-22 03:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll2015-01-27 12:14 - 2014-11-22 03:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll2015-01-27 12:14 - 2014-11-22 03:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll2015-01-27 12:14 - 2014-11-22 03:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll2015-01-27 12:14 - 2014-11-22 03:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe2015-01-27 12:14 - 2014-11-22 03:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl2015-01-27 12:14 - 2014-11-22 03:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll2015-01-27 12:14 - 2014-11-22 03:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll2015-01-27 12:14 - 2014-11-22 03:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll2015-01-27 12:14 - 2014-11-22 02:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll2015-01-27 12:14 - 2014-11-22 02:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll2015-01-27 12:13 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe2015-01-27 12:13 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys2015-01-27 12:12 - 2014-11-11 04:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll2015-01-27 12:12 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll2015-01-27 12:12 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll2015-01-27 12:12 - 2014-09-19 11:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll2015-01-27 12:12 - 2014-09-19 11:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll2015-01-27 12:12 - 2014-09-19 11:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll2015-01-27 12:12 - 2014-09-19 11:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll2015-01-27 12:12 - 2014-09-19 11:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll2015-01-27 12:12 - 2014-09-19 11:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll2015-01-27 12:12 - 2014-08-29 03:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll2015-01-27 12:11 - 2014-12-12 07:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe2015-01-27 12:11 - 2014-12-12 07:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe2015-01-27 12:11 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll2015-01-27 12:11 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll2015-01-27 12:11 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll2015-01-27 12:11 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll2015-01-27 12:10 - 2014-11-11 04:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll2015-01-27 12:10 - 2014-11-11 03:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys2015-01-27 12:10 - 2014-10-03 03:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll2015-01-27 12:10 - 2014-10-03 03:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll2015-01-27 12:10 - 2014-10-03 03:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll2015-01-27 12:10 - 2014-10-03 03:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll2015-01-27 12:10 - 2014-10-03 03:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll2015-01-27 12:10 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll2015-01-27 12:10 - 2014-08-21 08:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll2015-01-27 12:10 - 2014-08-21 08:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll2015-01-27 12:10 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL2015-01-27 12:10 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll2015-01-27 12:10 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll2015-01-27 12:10 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll2015-01-27 12:10 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe2015-01-27 12:10 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll2015-01-27 12:10 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll2015-01-27 12:10 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll2015-01-27 12:10 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll2015-01-27 12:10 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll2015-01-27 12:10 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys2015-01-27 12:10 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys2015-01-27 12:10 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys2015-01-27 12:10 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll2015-01-27 12:09 - 2014-12-19 04:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll2015-01-27 12:09 - 2014-12-19 03:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys2015-01-27 12:09 - 2014-12-11 19:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe2015-01-27 12:09 - 2014-12-06 05:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll2015-01-27 12:09 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe2015-01-27 12:09 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll2015-01-27 12:09 - 2014-10-18 03:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll2015-01-27 12:09 - 2014-10-10 02:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys2015-01-27 12:09 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll2015-01-27 12:09 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll2015-01-27 12:09 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll2015-01-27 12:09 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll2015-01-27 12:09 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys2015-01-27 12:09 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys2015-01-27 12:09 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll2015-01-27 12:09 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys2015-01-27 12:09 - 2014-05-08 11:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll2015-01-27 12:09 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll2015-01-27 12:09 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe2015-01-27 12:07 - 2014-10-14 03:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys2015-01-27 12:07 - 2014-10-14 03:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll2015-01-27 12:07 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll2015-01-27 12:07 - 2014-10-14 03:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll2015-01-27 12:07 - 2014-10-14 03:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll2015-01-27 12:07 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys2015-01-27 12:07 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll2015-01-27 12:07 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll2015-01-27 12:07 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll2015-01-27 12:07 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe2015-01-27 11:53 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll2015-01-27 11:53 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll2015-01-27 11:53 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll2015-01-27 11:53 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll2015-01-27 11:53 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe2015-01-27 11:44 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll2015-01-27 11:44 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll2015-01-27 11:44 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe2015-01-27 11:44 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll2015-01-27 11:44 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll2015-01-27 11:44 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll2015-01-27 11:44 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll2015-01-27 11:44 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll2015-01-27 11:44 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe2015-01-27 11:18 - 2015-01-27 11:24 - 00000000 ____D () C:\Program Files\VS Revo Group2015-01-27 11:15 - 2015-01-27 11:15 - 00880784 _____ (Google Inc.) C:\Users\Dobri\Downloads\ChromeSetup.exe2015-01-26 23:48 - 2015-01-26 23:48 - 00000028 _____ () C:\Users\Dobri\AppData\Roaming\setting2015-01-26 23:48 - 2015-01-26 23:48 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\browser2015-01-26 23:46 - 2015-01-27 11:11 - 00000009 _____ () C:\Users\Dobri\AppData\Roaming\ok.txt2015-01-26 23:46 - 2015-01-26 23:48 - 31990778 _____ () C:\Users\Dobri\AppData\Roaming\arsiv.exe2015-01-25 15:34 - 2015-01-25 15:34 - 00000000 ____D () C:\Program Files\Common Files\Java2015-01-25 15:34 - 2015-01-25 15:33 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll2015-01-25 15:33 - 2015-01-25 15:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2015-01-25 15:30 - 2015-01-25 15:30 - 00000000 ____D () C:\Windows\Sun2015-01-22 18:59 - 2015-01-22 18:59 - 00001325 _____ () C:\Users\Public\Desktop\League of Legends.lnk2015-01-22 18:59 - 2015-01-22 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends2015-01-22 10:47 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll2015-01-22 10:47 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll2015-01-22 10:47 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll2015-01-11 20:02 - 2015-01-11 20:03 - 00000000 ____D () C:\Program Files\Valve2015-01-09 21:48 - 2015-01-13 11:57 - 00000000 ____D () C:\Windows\Minidump ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 22:40 - 2014-04-23 12:50 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\Skype2015-01-27 22:36 - 2014-08-30 16:20 - 00000000 ____D () C:\Program Files\ESET2015-01-27 22:35 - 2014-04-23 12:35 - 02085539 _____ () C:\Windows\WindowsUpdate.log2015-01-27 22:33 - 2014-08-30 18:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum2015-01-27 22:33 - 2014-08-30 18:46 - 00000000 ____D () C:\Program Files\DAUM2015-01-27 22:30 - 2010-11-20 23:01 - 00782838 _____ () C:\Windows\system32\PerfStringBackup.INI2015-01-27 22:29 - 2014-04-23 12:46 - 00000000 ____D () C:\Program Files\Google2015-01-27 22:27 - 2014-06-15 21:28 - 00000000 ____D () C:\ProgramData\ProductData2015-01-27 22:23 - 2014-04-23 12:46 - 00000982 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job2015-01-27 22:23 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT2015-01-27 22:04 - 2014-05-26 14:49 - 00000000 ____D () C:\ProgramData\AVG2015-01-27 21:59 - 2014-05-26 14:50 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\AVG2015-01-27 21:57 - 2014-05-26 14:50 - 00000000 ____D () C:\Users\Dobri\AppData\Local\AVG2015-01-27 21:51 - 2009-07-14 06:34 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A02015-01-27 21:51 - 2009-07-14 06:34 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A02015-01-27 21:47 - 2014-04-29 14:59 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job2015-01-27 21:08 - 2014-09-01 20:27 - 00000376 _____ () C:\Windows\Tasks\update-S-1-5-21-1190607394-2965296010-1725609816-1000.job2015-01-27 20:00 - 2014-04-27 11:12 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys2015-01-27 19:44 - 2014-04-23 15:21 - 00000000 ____D () C:\Program Files\Opera2015-01-27 19:35 - 2014-08-10 19:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer2015-01-27 19:35 - 2014-04-23 13:05 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\uTorrent2015-01-27 19:31 - 2014-06-15 21:28 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\IObit2015-01-27 19:31 - 2014-06-15 21:28 - 00000000 ____D () C:\ProgramData\IObit2015-01-27 18:22 - 2014-09-01 20:27 - 00000376 _____ () C:\Windows\Tasks\update-sys.job2015-01-27 17:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache2015-01-27 16:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET2015-01-27 13:44 - 2009-07-14 06:33 - 00408752 _____ () C:\Windows\system32\FNTCACHE.DAT2015-01-27 13:42 - 2010-11-21 02:46 - 00000000 ____D () C:\Program Files\Windows Journal2015-01-27 12:39 - 2014-04-23 13:29 - 00000000 ____D () C:\ProgramData\NVIDIA2015-01-27 12:39 - 2014-04-23 13:28 - 00000000 ____D () C:\Program Files\NVIDIA Corporation2015-01-27 11:38 - 2010-11-21 02:46 - 00000000 ____D () C:\Windows\RemotePackages2015-01-26 23:19 - 2014-08-12 21:25 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\Spotify2015-01-26 23:11 - 2014-08-12 21:26 - 00000000 ____D () C:\Users\Dobri\AppData\Local\Spotify2015-01-25 15:33 - 2014-07-01 20:55 - 00000000 ____D () C:\ProgramData\Oracle2015-01-25 15:33 - 2014-07-01 20:55 - 00000000 ____D () C:\Program Files\Java2015-01-24 22:47 - 2014-04-29 14:59 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe2015-01-24 22:47 - 2014-04-29 14:59 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl2015-01-24 14:59 - 2014-04-24 17:47 - 00000000 ____D () C:\ProgramData\Microsoft Help2015-01-21 22:40 - 2014-05-29 10:57 - 00000000 ____D () C:\ProgramData\Origin2015-01-21 22:38 - 2014-05-29 11:46 - 00000000 ____D () C:\Program Files\Origin2015-01-18 19:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\LiveKernelReports2015-01-13 11:57 - 2014-04-24 17:46 - 00000000 ____D () C:\Users\Dobri\AppData\Roaming\DAEMON Tools Lite2015-01-08 09:55 - 2014-04-23 12:40 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe2015-01-08 09:44 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy2015-01-03 23:09 - 2014-05-09 15:29 - 00000000 ____D () C:\output2014-12-31 13:15 - 2014-04-23 12:39 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe2014-12-29 21:00 - 2014-12-12 09:16 - 00000000 ____D () C:\Users\Dobri\Desktop\Da uspeq ==================== Files in the root of some directories ======= 2014-06-19 12:05 - 2014-06-19 12:05 - 6010880 _____ () C:\Program Files\GUTF805.tmp2015-01-26 23:46 - 2015-01-26 23:48 - 31990778 _____ () C:\Users\Dobri\AppData\Roaming\arsiv.exe2015-01-26 23:46 - 2015-01-27 11:11 - 0000009 _____ () C:\Users\Dobri\AppData\Roaming\ok.txt2014-10-05 21:21 - 2014-10-05 21:21 - 0045270 _____ () C:\Users\Dobri\AppData\Roaming\room_v3.dat2015-01-26 23:48 - 2015-01-26 23:48 - 0000028 _____ () C:\Users\Dobri\AppData\Roaming\setting2014-06-19 11:53 - 2014-06-19 11:53 - 0000024 _____ () C:\Users\Dobri\AppData\Roaming\temp.ini2014-04-29 15:21 - 2014-04-29 15:21 - 0000000 ___SH () C:\Users\Dobri\AppData\Local\LumaEmu2014-05-21 22:34 - 2014-05-21 22:34 - 0000003 _____ () C:\Users\Dobri\AppData\Local\updater.log2014-05-21 22:34 - 2014-12-17 17:24 - 0000413 _____ () C:\Users\Dobri\AppData\Local\UserProducts.xml2014-07-03 18:51 - 2014-07-03 18:51 - 0000000 _____ () C:\Users\Dobri\AppData\Local\{0AF476E6-3AFB-46B2-B8E3-2DA250542CBA}2014-11-26 21:43 - 2014-11-26 21:43 - 0000000 _____ () C:\Users\Dobri\AppData\Local\{709A9533-F7F3-42F3-936B-FFB5E01CB415} Some content of TEMP:====================C:\Users\Dobri\AppData\Local\Temp\DseShExt-x86.dllC:\Users\Dobri\AppData\Local\Temp\SDShelEx-win32.dllC:\Users\Dobri\AppData\Local\Temp\TUUUninstallHelper.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signedC:\Windows\system32\winlogon.exe[2015-01-27 12:15] - [2010-11-19 22:17] - 0285696 ____A (Microsoft Corporation) C3EB9EA34EBE459F13F3F890F56CE72A C:\Windows\system32\wininit.exe => File is digitally signedC:\Windows\system32\svchost.exe => File is digitally signedC:\Windows\system32\services.exe => File is digitally signedC:\Windows\system32\User32.dll[2010-11-20 23:29] - [2010-11-19 22:21] - 0812032 ____A (Microsoft Corporation) CF97D64D7EC169C53C93B0A192218B29 C:\Windows\system32\userinit.exe => File is digitally signedC:\Windows\system32\rpcss.dll => File is digitally signedC:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-24 12:41 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-01-2015 01 Ran by Dobri at 2015-01-27 22:41:20 Running from C:\Users\Dobri\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LEST1V6I Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKLM\...\uTorrent) (Version: 2.2.1 - ) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Flash Player ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 9.0.47.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 10.2.0.22 - Adobe Systems, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) FIFA 08 (HKLM\...\{0A2A5039-B37F-489D-B1DC-A5258DF9E697}) (Version: 1.0.1.1 - Electronic Arts) GameRanger (HKU\S-1-5-21-1190607394-2965296010-1725609816-1000\...\GameRanger) (Version: - GameRanger Technologies) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 4.2.6.2 - IObit) Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) K-Lite Codec Pack 10.6.5 Full (HKLM\...\KLiteCodecPack_is1) (Version: 10.6.5 - ) League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (Version: 3.0.1 - Riot Games) Hidden Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve) Lightshot-5.2.0.17 (HKLM\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.0.17 - Skillbrains) Malwarebytes Anti-Malware, версия 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) NVIDIA Graphics Driver 307.83 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.83 - NVIDIA Corporation) NVIDIA PhysX (HKLM\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation) OpenAL (HKLM\...\OpenAL) (Version: - ) Opera Stable 27.0.1689.54 (HKLM\...\Opera 27.0.1689.54) (Version: 27.0.1689.54 - Opera Software ASA) Origin (HKLM\...\Origin) (Version: 9.4.7.2799 - Electronic Arts, Inc.) PhotoScape (HKLM\...\PhotoScape) (Version: - ) Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-1190607394-2965296010-1725609816-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer) VideoCAM GE111 (HKLM\...\InstallShield_{088B7BF8-AC95-4348-B77B-619AEB3A74A5}) (Version: 1.3.7501 - VideoCAM GE111) VideoCAM GE111 (Version: 1.3.7501 - VideoCAM GE111) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc) WinRAR 5.10 Бета 3 (32-битова версия) (HKLM\...\WinRAR archiver) (Version: 5.10.3 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 27-01-2015 22:38:47 Removed AVG PC TuneUp 2015 (en-US) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2015-01-26 23:48 - 00000883 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 tools.google.com 127.0.0.1 clients4.google.com ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {09BF3171-86D0-4B51-BB80-0CABD5EF0676} - System32\Tasks\Opera scheduled Autoupdate 1398259312 => C:\Program Files\Opera\launcher.exe [2015-01-23] (Opera Software) Task: {0ADDA080-F40A-4C0F-B652-8D517A24E726} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-23] (Google Inc.) Task: {1EDD279E-785D-4A02-971D-B829F13ADFC7} - System32\Tasks\Uninstaller_SkipUac_Dobri => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-01-20] (IObit) Task: {2722AF7F-2DBC-4A9C-98E1-DD0E79EB8319} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {284E7847-D5CA-4119-97E4-22555F64124F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {28C90242-422B-4418-85C7-6FC1FA33152D} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {40EF9C84-B016-4A48-8FF3-B062B2A2F088} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated) Task: {53BE904D-36FA-4652-BF3A-19B120907DE2} - System32\Tasks\update-sys => C:\Program Files\Skillbrains\Updater\Updater.exe [2014-03-25] () Task: {58AB02A6-F124-4D0C-9447-594F03DD8684} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1190607394-2965296010-1725609816-1000 => C:\Program Files\RealNetworks\RealDownloader\RealUpgrade.exe Task: {7DA5250E-C5B3-4857-AF21-9CEBC4683D4E} - System32\Tasks\update-S-1-5-21-1190607394-2965296010-1725609816-1000 => C:\Program Files\Skillbrains\Updater\Updater.exe [2014-03-25] () Task: {98837775-13CA-4C12-AAE1-CE87AEB9AD5C} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\WatTask => C:\Windows Activation Technologies\wat.exe [2006-04-21] () Task: {A8F4AC42-9937-492C-93AB-1128ACA19E9D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-23] (Google Inc.) Task: {C71A3BC5-DB17-4BE0-B325-E6244A208F68} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1190607394-2965296010-1725609816-1000 => C:\Program Files\RealNetworks\RealDownloader\RealUpgrade.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\update-S-1-5-21-1190607394-2965296010-1725609816-1000.job => C:\Program Files\Skillbrains\Updater\Updater.exe Task: C:\Windows\Tasks\update-sys.job => C:\Program Files\Skillbrains\Updater\Updater.exe ==================== Loaded Modules (whitelisted) ============= 2015-01-27 12:39 - 2013-01-31 11:00 - 00079648 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2011-03-16 23:11 - 2011-03-16 23:11 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 14:45 - 2010-10-20 14:45 - 08801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-01-27 19:31 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files\IObit\IObit Uninstaller\madExcept_.bpl 2015-01-27 19:31 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files\IObit\IObit Uninstaller\madBasic_.bpl 2015-01-27 19:31 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files\IObit\IObit Uninstaller\madDisAsm_.bpl 2014-05-20 19:33 - 2014-05-20 19:33 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1026.dll 2015-01-27 19:31 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files\IObit\IObit Uninstaller\sqlite3.dll 2015-01-27 19:31 - 2014-10-16 10:26 - 00622880 _____ () C:\Program Files\IObit\IObit Uninstaller\ProductStatistics.dll 2015-01-27 19:31 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files\IObit\IObit Uninstaller\webres.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: EvolveClient => "C:\Program Files\Echobit\Evolve\EvolveClient.exe" -autorun MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: Spotify => "C:\Users\Dobri\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Dobri\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: Viber => "C:\Users\Dobri\AppData\Local\Viber\Viber.exe" StartMinimized ========================= Accounts: ========================== Administrator (S-1-5-21-1190607394-2965296010-1725609816-500 - Administrator - Disabled) Dobri (S-1-5-21-1190607394-2965296010-1725609816-1000 - Administrator - Enabled) => C:\Users\Dobri Guest (S-1-5-21-1190607394-2965296010-1725609816-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1190607394-2965296010-1725609816-1002 - Limited - Enabled) UpdatusUser (S-1-5-21-1190607394-2965296010-1725609816-1003 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Faulty Device Manager Devices ============= Name: Standard PS/2 Keyboard Description: Standard PS/2 Keyboard Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard keyboards) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/27/2015 10:24:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2015 10:24:15 PM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost (1964) WebCacheLocal: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Users\Dobri\AppData\Local\Microsoft\Windows\WebCache\V01.log. Error: (01/27/2015 09:57:25 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL. System Error: The system cannot find the file specified. . Error: (01/27/2015 09:44:52 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL. System Error: The system cannot find the file specified. . Error: (01/27/2015 09:43:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL. System Error: The system cannot find the file specified. . Error: (01/27/2015 03:52:39 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: C:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInViews\Microsoft.Office.Tools.v9.0.dll . Error code = 0x80070020 Error: (01/27/2015 01:50:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2015 01:47:36 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Windows license activation failed. Error 0x00000000. Error: (01/27/2015 11:40:47 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2015 11:19:47 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {4461be38-76b8-4954-b327-c66b04e9010f} System errors: ============= Error: (01/27/2015 10:34:55 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:55 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:51 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:51 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:40 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:40 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:36 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:36 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:21 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (01/27/2015 10:34:21 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Microsoft Office Sessions: ========================= Error: (01/27/2015 10:24:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2015 10:24:15 PM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost1964WebCacheLocal: C:\Users\Dobri\AppData\Local\Microsoft\Windows\WebCache\V01.log-1811 (0xfffff8ed) Error: (01/27/2015 09:57:25 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL. System Error: The system cannot find the file specified. Error: (01/27/2015 09:44:52 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL. System Error: The system cannot find the file specified. Error: (01/27/2015 09:43:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary SASKUTIL. System Error: The system cannot find the file specified. Error: (01/27/2015 03:52:39 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: C:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInViews\Microsoft.Office.Tools.v9.0.dll . Error code = 0x80070020 C:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInViews\Microsoft.Office.Tools.v9.0.dll Error: (01/27/2015 01:50:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2015 01:47:36 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: 0x000000000x00000001 Error: (01/27/2015 11:40:47 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/27/2015 11:19:47 AM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Access is denied. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {4461be38-76b8-4954-b327-c66b04e9010f} CodeIntegrity Errors: =================================== Date: 2015-01-27 22:23:53.277 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 22:18:19.643 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 22:12:16.972 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 19:47:03.759 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 19:35:48.112 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 19:22:02.201 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 19:11:44.082 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 17:29:22.054 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 16:17:36.144 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 14:25:49.453 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ Percentage of memory in use: 73% Total physical RAM: 1919.3 MB Available physical RAM: 501.34 MB Total Pagefile: 3838.61 MB Available Pagefile: 2042.04 MB Total Virtual: 2047.88 MB Available Virtual: 1894.27 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:29.2 GB) (Free:4.78 GB) NTFS Drive d: (Локален диск) (Fixed) (Total:104.56 GB) (Free:31.44 GB) NTFS Drive e: () (Fixed) (Total:19.53 GB) (Free:14.57 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 153.4 GB) (Disk ID: A9AAA9AA) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=29.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=104.6 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=19.5 GB) - (Type=07 NTFS) ==================== End Of Log ============================
  17. Здравейте,всеки път когато стартирам своя браузър, а и други програми ми излиза следната грешка. "There was a problem starting C:\Program Files\Settings Manager\systemk\sysapcrt.dll Access is denied." След като потвърдя с ОК,браузърът си стартира нормално,но е досадно всеки път да има ерор. ОС е уиндоус 7.Не съм инсталирал нов софтуер наскоро. Не разполагам с нов диск за операционната си система. Това са логовете, които имам от препоръчаната от Вас програма. Съдържанието на FRST.txt Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by myPC (administrator) on myPC on 27-01-2015 12:18:26 Running from C:\Users\myPC\Desktop Loaded Profiles: myPC (Available profiles: myPC) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 9 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe () D:\garena\Garena Plus\ggdllhost.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\systemku.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe () D:\garena\Garena Plus\GarenaMessenger.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5581888 2014-02-24] (ESET) HKLM-x32\...\Run: [bCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2583040 2009-09-21] (VIA) HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-30] (Piriform Ltd) IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll [664592 2014-05-18] () HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll [490000 2014-05-18] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.softonic.com/INF00176/tb_v1?SearchSource=10&cc=&mi=8073f234000000000000001966fa4207 HKU\S-1-5-21-3522770205-4233124857-3227214610-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp SearchScopes: HKU\S-1-5-21-3522770205-4233124857-3227214610-1000 -> DefaultScope {0FB51F6C-83D2-4836-88DF-8CF4E4DF0CBC} URL = http://search.softonic.com/INF00176/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=8073f234000000000000001966fa4207&r=218 SearchScopes: HKU\S-1-5-21-3522770205-4233124857-3227214610-1000 -> {0FB51F6C-83D2-4836-88DF-8CF4E4DF0CBC} URL = http://search.softonic.com/INF00176/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=8073f234000000000000001966fa4207&r=218 BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 78.159.128.2 78.159.128.3 FireFox: ======== FF ProfilePath: C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470 FF Homepage: hxxp://www.google.bg/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll () FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @t.garena.com/garenatalk -> D:\garena\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> D:\vlc\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> D:\vlc\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\vlc\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\vlc\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF Extension: ABV Notifier - C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\[email protected] [2014-12-15] FF Extension: FlashGot - C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-10] FF Extension: Adblock Plus - C:\Users\myPC\AppData\Roaming\Mozilla\Firefox\Profiles\38gkhptu.default-1418649727470\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-15] FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-08-27] FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird Chrome: ======= CHR Profile: C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Документи) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-16] CHR Extension: (Google Диск) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-16] CHR Extension: (YouTube) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-16] CHR Extension: (Google Търсене) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-16] CHR Extension: (Google Wallet) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-16] CHR Extension: (Gmail) - C:\Users\myPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1343408 2014-02-24] (ESET) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1721800 2014-08-09] (NVIDIA Corporation) R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed] R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed] R2 SystemkService; C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe [3543056 2014-05-18] (Aztec Media Inc) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2012-10-08] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET) R1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg [36240 2014-05-18] (Aztec Media Inc) R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs) S4 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [416768 2009-06-10] (Realtek Semiconductor Corporation ) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2014-06-21] (Duplex Secure Ltd.) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) U3 ahsxfwvb; No ImagePath S3 APackDrv; \??\C:\Windows\SysWOW64\Drivers\APackDrv.sys [X] S3 GGSAFERDriver; \??\D:\garena\Garena Plus\Room\safedrv.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 12:18 - 2015-01-27 12:18 - 00014040 _____ () C:\Users\myPC\Desktop\FRST.txt 2015-01-27 12:16 - 2015-01-27 12:18 - 00000000 ____D () C:\FRST 2015-01-27 12:13 - 2015-01-27 12:14 - 02129920 _____ (Farbar) C:\Users\myPC\Desktop\FRST64.exe 2015-01-27 00:08 - 2015-01-27 00:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-26 16:15 - 2015-01-27 12:05 - 00005264 _____ () C:\Windows\setupact.log 2015-01-26 16:15 - 2015-01-26 16:15 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-22 22:50 - 2015-01-25 23:22 - 00000000 ____D () C:\Users\myPC\Desktop\5 i 6 2015-01-22 22:48 - 2015-01-22 22:48 - 00000000 ____D () C:\Users\myPC\Desktop\posledna lekciq MO 2015-01-22 00:22 - 2015-01-22 00:22 - 00000000 ____D () C:\Users\myPC\Desktop\OTD MARIQ S IMENA 2015-01-20 01:46 - 2015-01-25 03:00 - 00000000 ____D () C:\Users\myPC\Desktop\shit 2015-01-16 00:53 - 2015-01-16 00:54 - 00000000 ____D () C:\Users\myPC\Documents\Fax 2015-01-15 20:57 - 2015-01-22 00:22 - 00000000 ____D () C:\Users\myPC\Desktop\Отд Мария 2015-01-15 20:07 - 2015-01-15 20:09 - 00000187 _____ () C:\Users\myPC\Desktop\МО най-чести теми.txt 2015-01-14 14:42 - 2015-01-14 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet 2015-01-13 00:38 - 2015-01-13 00:38 - 00000028 _____ () C:\Users\myPC\Desktop\mo.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 12:11 - 2014-07-08 22:50 - 00000000 ____D () C:\ProgramData\systemk 2015-01-27 12:11 - 2014-06-21 21:33 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\GarenaPlus 2015-01-27 12:11 - 2014-06-21 21:33 - 00000000 ____D () C:\ProgramData\GarenaMessenger 2015-01-27 12:08 - 2013-02-03 10:06 - 01588818 _____ () C:\Windows\WindowsUpdate.log 2015-01-27 12:05 - 2014-12-20 12:55 - 00003418 _____ () C:\Windows\System32\Tasks\gg_uac_daemon_myPC 2015-01-27 12:05 - 2014-12-16 20:40 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-27 12:05 - 2014-08-27 12:55 - 00000360 _____ () C:\Windows\Tasks\DriverToolkit Autorun.job 2015-01-27 12:05 - 2013-02-03 10:35 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-01-27 12:05 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-27 12:04 - 2013-02-03 10:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 03:51 - 2013-02-03 10:49 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\uTorrent 2015-01-27 03:51 - 2009-07-14 06:45 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-27 03:51 - 2009-07-14 06:45 - 00026144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-27 03:46 - 2014-12-16 20:41 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-01-27 03:46 - 2014-12-16 20:40 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-27 03:41 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-01-27 02:56 - 2013-02-03 11:16 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\vlc 2015-01-27 02:53 - 2013-02-18 15:08 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-27 01:27 - 2014-01-12 12:38 - 00045270 _____ () C:\Users\myPC\AppData\Roaming\room_v3.dat 2015-01-26 23:03 - 2009-07-14 07:13 - 00786598 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-26 22:37 - 2013-11-22 13:39 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer 2015-01-25 22:53 - 2013-02-18 15:08 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-01-25 22:53 - 2013-02-03 10:43 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-01-25 22:53 - 2013-02-03 10:43 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-24 18:45 - 2013-02-03 14:31 - 00000000 ____D () C:\Users\myPC\AppData\Roaming\Skype 2015-01-24 18:01 - 2014-09-19 14:35 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-24 18:01 - 2013-02-03 14:31 - 00000000 ____D () C:\ProgramData\Skype 2015-01-23 22:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2015-01-09 19:01 - 2014-04-14 11:28 - 00000000 ____D () C:\Program Files (x86)\Settings Manager ==================== Files in the root of some directories ======= 2014-01-12 12:38 - 2015-01-27 01:27 - 0045270 _____ () C:\Users\myPC\AppData\Roaming\room_v3.dat 2014-08-27 12:24 - 2014-08-27 12:27 - 0000003 _____ () C:\Users\myPC\AppData\Local\user_data.ini ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe [2014-05-14 19:26] - [2011-01-16 02:01] - 0389632 ____A (Microsoft Corporation) 81257415084B84F3C0D95C381A8D4C8F C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll [2010-11-21 05:24] - [2011-01-16 02:01] - 1008640 ____A (Microsoft Corporation) 0B864E15A0BADFF0E7BB8B59009FDDCF C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-24 19:24 ==================== End Of Log ============================ Прикачвам Addition.txt. Addition.txt
  18. Да не отварям друга тема,защото въпросът ми е почти същият.Досадна и нахална търсачка /omiga-plus/се настани на първа страница.Пуснах програмите които сте постнали тук да сканират,и изчистиха доста досадни проблеми, но търсачката така и си остана макар и не на първа страница. Моля дайте някакъв съвет!
  19. Днес си инсталирах една малка програма но покрай нея се накичиха и доста гадинки.Проверих и почистих със HitmanPro и Mallwarebyts.........но все пак ако може да погледнете.Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2015 01 Ran by Ivaylo Dimov (administrator) on IVAYLODIMOV-PC on 16-01-2015 19:48:30 Running from C:\Users\Ivaylo Dimov\Downloads Loaded Profiles: Ivaylo Dimov (Available profiles: Ivaylo Dimov) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Български (България) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.jcomsoft.com)C:\Windows\SysWOW64\AniGIF.ocx 2015-01-16 17:31 - 2015-01-16 17:31 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Local\CrashRpt 2015-01-16 17:22 - 2015-01-16 17:23 - 23462809 _____ (Igor Pavlov) C:\Users\Ivaylo Dimov\Downloads\WinSetupFromUSB-1-4.exe 2015-01-16 15:57 - 2015-01-16 16:49 - 1880096768 _____ () C:\Users\Ivaylo Dimov\Downloads\Chakra-2014.05-Descartes-x86_64.iso 2015-01-15 08:16 - 2015-01-16 16:51 - 00000000 ____D () C:\Users\Ivaylo Dimov\Downloads\rufus_files 2015-01-15 08:13 - 2015-01-15 08:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer 2015-01-15 08:13 - 2015-01-15 08:13 - 00000000 ____D () C:\Program Files (x86)\ImageWriter 2015-01-08 17:39 - 2015-01-08 17:39 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2015-01-06 15:37 - 2015-01-06 15:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Home Edition 8.1.1 2015-01-06 15:37 - 2015-01-06 15:37 - 00000000 ____D () C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.1.1 2015-01-06 15:37 - 2013-09-30 16:26 - 03050808 _____ () C:\Windows\system32\pwNative.exe 2015-01-06 15:37 - 2013-09-30 16:26 - 00019152 ____N () C:\Windows\system32\pwdrvio.sys 2015-01-06 15:37 - 2013-09-30 16:26 - 00012504 ____N () C:\Windows\system32\pwdspio.sys 2015-01-05 22:19 - 2015-01-05 22:19 - 00000000 ____D () C:\Program Files\Synaptics 2015-01-05 21:59 - 2015-01-05 21:59 - 00000481 _____ () C:\Windows\SynInst.log 2015-01-05 21:05 - 2015-01-05 21:05 - 00000923 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\µTorrent.lnk 2015-01-05 21:05 - 2015-01-05 21:05 - 00000000 ____D () C:\Program Files\uTorrent 2015-01-05 21:04 - 2015-01-05 21:04 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Local\uTorrent 2015-01-05 20:31 - 2015-01-05 20:31 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Local\ShamurShamur 2015-01-05 19:59 - 2015-01-05 19:59 - 00000218 _____ () C:\Users\Ivaylo Dimov\.recently-used.xbel 2015-01-05 19:59 - 2015-01-05 19:59 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Roaming\gtk-2.0 2015-01-05 19:56 - 2015-01-05 19:56 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Roaming\live-usb-install 2015-01-05 19:43 - 2015-01-05 19:43 - 00640424 _____ (Akeo Consulting (http://akeo.ie)) C:\Users\Ivaylo Dimov\Downloads\rufus-1.4.12.exe 2015-01-04 22:21 - 2015-01-04 22:21 - 00001179 _____ () C:\Users\Ivaylo Dimov\Desktop\AIDA64 Extreme.lnk 2015-01-04 22:21 - 2015-01-04 22:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire 2015-01-04 22:14 - 2015-01-04 22:14 - 00000000 ____D () C:\Program Files (x86)\Lavalys 2015-01-03 18:27 - 2015-01-03 18:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan 2015-01-03 11:01 - 2015-01-03 11:06 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-12-30 23:07 - 2015-01-16 17:30 - 00002465 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-12-30 23:07 - 2014-12-30 23:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-30 23:06 - 2015-01-16 19:28 - 00001006 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-30 23:06 - 2015-01-16 19:11 - 00001010 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-30 23:06 - 2014-12-30 23:06 - 00004006 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-12-30 23:06 - 2014-12-30 23:06 - 00003754 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-12-29 13:47 - 2014-12-30 23:07 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Local\Google 2014-12-29 13:47 - 2014-12-30 23:06 - 00000000 ____D () C:\Program Files (x86)\Google 2014-12-29 10:07 - 2015-01-16 19:27 - 00027662 _____ () C:\Windows\PFRO.log 2014-12-26 12:13 - 2015-01-05 22:19 - 00006396 _____ () C:\Windows\DPINST.LOG 2014-12-23 21:29 - 2014-12-23 21:29 - 00000000 ____D () C:\Windows\Samsung 2014-12-23 21:29 - 2014-12-23 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung SCX-4x21 Series 2014-12-23 21:29 - 2014-12-23 21:29 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-12-23 21:29 - 2012-07-25 11:27 - 00497568 _____ () C:\Windows\ssndii.exe 2014-12-23 21:28 - 2009-10-13 10:44 - 00022016 _____ () C:\Windows\system32\sugw2l6.dll 2014-12-23 21:28 - 2009-10-13 10:44 - 00000411 _____ () C:\Windows\system32\sugw2l6.smt 2014-12-23 21:28 - 2009-10-13 10:43 - 00151552 _____ (SS) C:\Windows\system32\sugw2ci.exe 2014-12-23 21:28 - 2009-10-13 10:43 - 00089600 _____ (SS) C:\Windows\system32\sugw2ci.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 01233920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml2.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4r.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00081920 _____ (Samsung Electronics) C:\Windows\SysWOW64\ssdevm.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00074240 _____ (Samsung Electronics) C:\Windows\system32\ssdevm64.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00049152 _____ (Samsung Electronics) C:\Windows\SysWOW64\ssusbpn.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00047104 _____ (Samsung Electronics) C:\Windows\system32\ssusbp64.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4a.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00038160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml2r.dll 2014-12-23 21:28 - 2009-10-13 09:12 - 00021776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml2a.dll 2014-12-23 21:27 - 2014-12-23 21:27 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-12-23 21:27 - 2011-07-08 06:43 - 00011576 ____N (Samsung Electronics) C:\Windows\system32\Drivers\SSPORT.SYS 2014-12-23 10:29 - 2015-01-16 19:28 - 00005165 _____ () C:\Windows\setupact.log 2014-12-23 10:29 - 2014-12-23 10:29 - 00000000 _____ () C:\Windows\setuperr.log 2014-12-18 00:18 - 2015-01-16 17:16 - 00000432 __RSH () C:\ProgramData\ntuser.pol 2014-12-17 21:51 - 2014-12-17 21:51 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Local\Broadcom 2014-12-17 21:50 - 2014-12-17 21:50 - 00000000 ____D () C:\Program Files\WIDCOMM 2014-12-17 21:50 - 2009-07-01 12:46 - 00132648 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys 2014-12-17 21:50 - 2009-07-01 12:46 - 00098344 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys 2014-12-17 21:50 - 2009-07-01 12:46 - 00021160 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys 2014-12-17 21:50 - 2009-04-07 15:33 - 00035104 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys 2014-12-17 21:22 - 2014-12-17 21:32 - 00000000 ____D () C:\Windows\pss 2014-12-17 21:22 - 2014-12-17 21:22 - 00000000 ____D () C:\Users\Ivaylo Dimov\Documents\Bluetooth Exchange Folder ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-16 19:35 - 2009-07-14 06:45 - 00031504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-16 19:35 - 2009-07-14 06:45 - 00031504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-16 19:31 - 2014-12-05 07:00 - 01764126 _____ () C:\Windows\WindowsUpdate.log 2015-01-16 19:28 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-16 19:26 - 2014-12-05 09:47 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Roaming\uTorrent 2015-01-16 19:13 - 2014-12-05 09:49 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-16 17:30 - 2014-12-05 07:23 - 00001621 _____ () C:\Users\Ivaylo Dimov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-01-16 13:25 - 2014-12-15 08:18 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2015-01-16 07:07 - 2014-12-05 11:31 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-01-15 09:31 - 2014-12-12 21:33 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Roaming\Skype 2015-01-13 23:13 - 2014-12-05 09:49 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-01-13 23:13 - 2014-12-05 09:49 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-13 23:13 - 2014-12-05 09:49 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-01-13 21:27 - 2014-12-07 09:42 - 00000000 ____D () C:\Users\Ivaylo Dimov\AppData\Local\Mirillis 2015-01-13 21:27 - 2014-12-05 19:09 - 00000000 ____D () C:\The KMPlayer 2015-01-11 06:24 - 2009-07-14 07:08 - 00032546 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-05 22:19 - 2014-12-05 10:08 - 00000000 ____D () C:\SWSETUP 2015-01-05 19:59 - 2014-12-05 07:22 - 00000000 ____D () C:\Users\Ivaylo Dimov 2015-01-03 18:27 - 2014-12-09 09:31 - 00000045 _____ () C:\Windows\SysWOW64\initdebug.nfo 2015-01-03 17:49 - 2014-12-05 12:00 - 00001768 _____ () C:\Users\Public\Desktop\Defraggler.lnk 2015-01-03 17:33 - 2014-12-09 09:24 - 00000000 ____D () C:\Program Files (x86)\FinalWire 2014-12-30 21:45 - 2014-12-05 09:38 - 00791072 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-12-27 08:57 - 2009-07-14 07:13 - 00781790 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-26 12:11 - 2014-12-05 10:20 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 2014-12-18 00:18 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-12-18 00:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-12-17 22:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2014-12-17 21:50 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories Some content of TEMP: ==================== C:\Users\Ivaylo Dimov\AppData\Local\Temp\cabex.dll C:\Users\Ivaylo Dimov\AppData\Local\Temp\sfamcc00001.dll C:\Users\Ivaylo Dimov\AppData\Local\Temp\sfextra.dll C:\Users\Ivaylo Dimov\AppData\Local\Temp\unelevate.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-16 13:18 ==================== End Of Log ============================
  20. Здравейте, на 2 пъти вече след стартиране на машината браузъра ми (гугъл хром) ми се стартира автоматично и ето къде ме праща: http://gangnamgame.net/'къв гангнам стайл 'кви пет лева... това е от преди минута, вчера същата работа, може да не е зараза ама знам ли. С уин 7 х64бита съм. Аddition: http://dox.bg/files/dw?a=26fe5197f2 FRST: http://dox.bg/files/dw?a=d1689c4e67
  21. Здравейте отново . Имам едно бавно лаптопче , но не знам дали вирус причинява всичко това или просто го пренатоварвам с някои програми . Наскоро му инсталирах някои програми ( AVG 2015 , CryptoPrevent , Malwarebytes Anti-Malware , Unchecky ) възможно ли е от тях да е така бавен . Ако може да направим същите стъпки със сканирането , ще съм ви отново благодарен .
  22. Здравейте, Честита Нова Година с пожелание за здраве и успехи на всички свързани с този полезен форум! Търся помощ за следния проблем. При отваряне на различни страници, връзките вътре са неактивни а при кликане върху тях в нов прозорец се отварят 2-3 рекламни и потенциално опасни страници. Това се появява нерегулярно в различни браузъри. Опитах редица програми за отстраняване на малуеър - Malwarebytes, Hitman Pro, AdwCleaner, SpyHunter... без успех. Не помогна и System Restore. Не се виждат подозрителни програми, инсталирани наскоро. Доколкото разбирам, не виждам да са настъпили промени и в интернет настройките. Ето и нужната информация: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2015 Ran by Nikola (administrator) on MINI on 02-01-2015 13:03:21 Running from C:\Users\Nikola\Desktop Loaded Profile: Nikola (Available profiles: Nikola) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Palemoon) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Lenovo.) C:\Windows\System32\TPHDEXLG64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE (CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Moonchild Productions) C:\Program Files\Pale Moon\palemoon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\DeviceDisplayObjectProvider.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Mozilla Corporation) C:\Program Files\Pale Moon\plugin-container.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10151968 2010-04-20] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [908320 2010-04-20] (Realtek Semiconductor) HKLM\...\Run: [synTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [TpShocks] => C:\Windows\System32\TpShocks.exe [231328 2010-03-15] (Lenovo.) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [startCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-13] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro) HKLM-x32\...\Run: [uCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-03] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35184 2008-12-03] (Adobe Systems Incorporated) HKU\S-1-5-21-2063281587-2529135136-1089397287-1000\...\Run: [Google Update] => C:\Users\Nikola\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-23] (Google Inc.) HKU\S-1-5-21-2063281587-2529135136-1089397287-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-18\...\RunOnce: [WLStart] => C:\Program Files (x86)\Windows Live\Installer\wlstart.exe [768336 2009-07-26] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) ShellIconOverlayIdentifiers-x32: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\SysWow64\IcnOvrly.dll () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2063281587-2529135136-1089397287-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs HKU\S-1-5-21-2063281587-2529135136-1089397287-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp URLSearchHook: HKU\S-1-5-21-2063281587-2529135136-1089397287-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2063281587-2529135136-1089397287-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2063281587-2529135136-1089397287-1000 -> {1FC3EA2A-5BB8-4BA6-B477-3CAB1D2B6875} URL = http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKU\S-1-5-21-2063281587-2529135136-1089397287-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 104.236.54.174 107.170.245.37 93.123.54.229 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-2063281587-2529135136-1089397287-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Nikola\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-2063281587-2529135136-1089397287-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Nikola\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2010-06-27] Chrome: ======= CHR HomePage: Default -> hxxp://www.searchnu.com/406 CHR StartupUrls: Default -> "hxxp://www.google.bg/" CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Nikola\AppData\Local\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Nikola\AppData\Local\Google\Chrome\Application\39.0.2171.95\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Nikola\AppData\Local\Google\Chrome\Application\39.0.2171.95\gcswf32.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Skype Toolbars) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL No File CHR Plugin: (Java Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Windows LiveВ® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Nikola\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Преводач) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2011-12-07] CHR Extension: (YouTube) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-14] CHR Extension: (Adblock Plus) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-06-25] CHR Extension: (Google Търсене) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-14] CHR Extension: (SiteAdvisor) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2011-10-21] CHR Extension: (Google Wallet) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Readability) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadggleneidfmbhhedlildjnpgcggmch [2011-12-29] CHR Extension: (Gmail) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-14] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-11-20] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-11-20] CHR StartMenuInternet: Google Chrome - C:\Users\Nikola\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 ABBYY.Licensing.FineReader.Professional.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [660768 2007-12-06] (ABBYY (BIT Software)) S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-03-05] (Adobe Systems) [File not signed] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited) S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited) S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [156904 2014-11-13] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited) S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited) R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo) S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2015-01-02] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-02-22] (Anchorfree Inc.) R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [214912 2010-01-27] (Vimicro Corporation) R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo) S1 archlp; SysWOW64\drivers\archlp.sys [X] S1 ArcSec; system32\drivers\ArcSec.sys [X] U3 BcmSqlStartupSvc; No ImagePath S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] U2 IAStorDataMgrSvc; No ImagePath U2 IviRegMgr; No ImagePath S3 Prot6Flt; system32\DRIVERS\Prot6Flt.sys [X] U2 RichVideo; No ImagePath S3 RkHit; \??\C:\windows\system32\drivers\RKHit.sys [X] U3 SQLWriter; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-02 13:03 - 2015-01-02 13:04 - 00020659 _____ () C:\Users\Nikola\Desktop\FRST.txt 2015-01-02 12:55 - 2015-01-02 13:02 - 00000736 _____ () C:\Users\Nikola\Desktop\SystemLook.txt 2015-01-02 12:54 - 2015-01-02 12:54 - 00165376 _____ () C:\Users\Nikola\Desktop\SystemLook_x64.exe 2015-01-02 12:40 - 2015-01-02 12:39 - 02173952 _____ () C:\Users\Nikola\Desktop\adwcleaner_4.106.exe 2015-01-02 12:06 - 2015-01-02 13:03 - 00000000 ____D () C:\FRST 2015-01-02 12:05 - 2015-01-02 12:06 - 02123264 _____ (Farbar) C:\Users\Nikola\Desktop\FRST64.exe 2015-01-02 09:12 - 2015-01-02 09:12 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group 2015-01-02 09:10 - 2015-01-02 12:28 - 00000000 ____D () C:\windows\CC1F6DA021D2425AB1B65B164A598450.TMP 2015-01-01 20:18 - 2015-01-01 20:18 - 00000000 _____ () C:\autoexec.bat 2015-01-01 20:12 - 2015-01-02 09:09 - 00000000 ____D () C:\windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP 2015-01-01 18:46 - 2015-01-01 18:46 - 00048364 _____ () C:\Users\Nikola\Documents\cc_20150101_184554.reg 2015-01-01 18:20 - 2015-01-01 18:52 - 00000000 ____D () C:\Program Files\HitmanPro 2015-01-01 18:20 - 2015-01-01 18:48 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-12-31 21:52 - 2015-01-02 12:45 - 00000000 ____D () C:\AdwCleaner 2014-12-31 21:02 - 2014-12-31 21:28 - 00000000 ____D () C:\ProgramData\IObit 2014-12-31 21:02 - 2014-12-31 21:02 - 00000000 ____D () C:\Users\Nikola\AppData\IObit 2014-12-31 21:01 - 2014-12-31 21:27 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\IObit 2014-12-31 21:01 - 2014-12-31 21:27 - 00000000 ____D () C:\ProgramData\ProductData 2014-12-31 21:01 - 2014-12-31 21:02 - 00000000 ____D () C:\Program Files (x86)\IObit 2014-12-31 16:34 - 2015-01-01 13:01 - 00000000 ____D () C:\Users\Nikola\Desktop\1 2014-12-30 21:09 - 2014-12-30 21:09 - 00000000 __SHD () C:\Users\Nikola\AppData\Local\EmieBrowserModeList 2014-12-24 20:47 - 2014-12-16 18:15 - 00002406 _____ () C:\Users\Nikola\Desktop\subsunacs.net_103958.txt 2014-12-22 17:38 - 2015-01-02 10:00 - 00000000 ____D () C:\вера 2014-12-22 14:41 - 2015-01-02 10:23 - 00000000 ____D () C:\проект казарма 2014-12-21 18:42 - 2014-12-21 18:44 - 01667658 _____ () C:\Users\Nikola\Downloads\B1_2014_11_6103.zip 2014-12-18 12:57 - 2014-12-13 07:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-12-18 12:57 - 2014-12-13 05:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-12-11 07:17 - 2014-12-11 07:17 - 00000000 ____D () C:\windows\system32\appraiser 2014-12-11 06:41 - 2014-10-18 04:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2014-12-11 06:41 - 2014-10-18 03:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll 2014-12-11 06:41 - 2014-07-07 04:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2014-12-11 06:41 - 2014-07-07 04:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe 2014-12-11 06:41 - 2014-07-07 04:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2014-12-11 06:41 - 2014-07-07 04:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll 2014-12-11 06:41 - 2014-07-07 03:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll 2014-12-11 06:41 - 2014-07-07 03:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe 2014-12-11 06:41 - 2014-07-07 03:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe 2014-12-11 06:41 - 2014-07-07 03:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll 2014-12-10 07:01 - 2014-12-04 04:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2014-12-10 07:01 - 2014-12-04 04:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2014-12-10 07:01 - 2014-12-04 04:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2014-12-10 07:01 - 2014-12-04 04:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2014-12-10 07:01 - 2014-12-04 04:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-12-10 07:01 - 2014-12-04 04:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2014-12-10 07:01 - 2014-12-04 04:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-12-10 07:01 - 2014-12-02 01:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe 2014-12-10 07:01 - 2014-11-27 03:43 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-12-10 07:01 - 2014-11-27 03:10 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-12-10 07:01 - 2014-11-22 05:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-12-10 07:01 - 2014-11-22 05:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-12-10 07:01 - 2014-11-22 04:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-12-10 07:01 - 2014-11-22 04:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-12-10 07:01 - 2014-11-22 04:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-12-10 07:01 - 2014-11-22 04:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-12-10 07:01 - 2014-11-22 04:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-12-10 07:01 - 2014-11-22 04:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-12-10 07:01 - 2014-11-22 04:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-12-10 07:01 - 2014-11-22 04:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-12-10 07:01 - 2014-11-22 04:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-12-10 07:01 - 2014-11-22 04:06 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-12-10 07:01 - 2014-11-22 04:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-12-10 07:01 - 2014-11-22 04:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-12-10 07:01 - 2014-11-22 03:59 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-12-10 07:01 - 2014-11-22 03:58 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-12-10 07:01 - 2014-11-22 03:56 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-12-10 07:01 - 2014-11-22 03:54 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-12-10 07:01 - 2014-11-22 03:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-12-10 07:01 - 2014-11-22 03:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-12-10 07:01 - 2014-11-22 03:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-12-10 07:01 - 2014-11-22 03:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-10 07:01 - 2014-11-22 03:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-12-10 07:01 - 2014-11-22 03:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-12-10 07:01 - 2014-11-22 03:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-12-10 07:01 - 2014-11-22 03:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-12-10 07:01 - 2014-11-22 03:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-12-10 07:01 - 2014-11-22 03:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-12-10 07:01 - 2014-11-22 03:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-12-10 07:01 - 2014-11-22 02:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-12-10 07:01 - 2014-11-22 02:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-12-10 07:01 - 2014-11-11 05:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll 2014-12-10 07:01 - 2014-11-11 04:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll 2014-12-10 07:01 - 2014-11-11 03:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys 2014-12-10 07:00 - 2014-11-22 05:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-12-10 07:00 - 2014-11-22 04:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-12-10 07:00 - 2014-11-22 04:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-12-10 07:00 - 2014-11-22 04:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-12-10 07:00 - 2014-11-22 04:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-12-10 07:00 - 2014-11-22 04:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-12-10 07:00 - 2014-11-22 04:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-12-10 07:00 - 2014-11-22 04:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-12-10 07:00 - 2014-11-22 04:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-12-10 07:00 - 2014-11-22 04:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-12-10 07:00 - 2014-11-22 04:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-12-10 07:00 - 2014-11-22 04:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-12-10 07:00 - 2014-11-22 04:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2014-12-10 07:00 - 2014-11-22 03:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-12-10 07:00 - 2014-11-22 03:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-12-10 07:00 - 2014-11-22 03:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-12-10 07:00 - 2014-11-22 03:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-12-10 07:00 - 2014-11-22 03:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-12-10 07:00 - 2014-11-22 03:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-12-10 07:00 - 2014-11-22 03:21 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-12-10 07:00 - 2014-11-22 03:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-12-10 07:00 - 2014-11-08 05:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2014-12-10 07:00 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2014-12-10 07:00 - 2014-10-30 04:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe 2014-12-10 07:00 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe 2014-12-10 07:00 - 2014-10-03 04:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll 2014-12-10 07:00 - 2014-10-03 04:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll 2014-12-10 07:00 - 2014-10-03 04:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll 2014-12-10 07:00 - 2014-10-03 04:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll 2014-12-10 07:00 - 2014-10-03 04:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe 2014-12-10 07:00 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll 2014-12-10 07:00 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-10 07:00 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll 2014-12-10 07:00 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll 2014-12-10 07:00 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe 2014-12-06 18:09 - 2014-12-06 18:09 - 00000479 _____ () C:\Users\Nikola\Desktop\CONTACT - Shortcut.lnk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-02 12:54 - 2009-07-14 06:45 - 00022464 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-02 12:54 - 2009-07-14 06:45 - 00022464 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-02 12:52 - 2010-06-27 00:46 - 01891193 _____ () C:\windows\WindowsUpdate.log 2015-01-02 12:49 - 2010-06-27 01:34 - 07497600 _____ () C:\windows\system32\TPAPSLOG.LOG 2015-01-02 12:46 - 2014-11-13 07:06 - 00002244 _____ () C:\windows\PFRO.log 2015-01-02 12:46 - 2014-10-12 08:01 - 00002072 _____ () C:\windows\setupact.log 2015-01-02 12:46 - 2013-04-14 07:12 - 00000994 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-02 12:46 - 2010-06-27 01:34 - 02330240 _____ () C:\windows\system32\TPHDLOG0.LOG 2015-01-02 12:46 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-01-02 12:42 - 2011-10-18 13:28 - 00001012 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2063281587-2529135136-1089397287-1000UA.job 2015-01-02 12:10 - 2013-04-14 07:12 - 00000998 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-02 12:10 - 2012-07-29 22:38 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2015-01-02 11:28 - 2012-01-18 08:11 - 06962688 ___SH () C:\Users\Nikola\Desktop\Thumbs.db 2015-01-02 09:09 - 2011-10-29 20:08 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\uTorrent 2015-01-02 09:07 - 2011-10-29 20:14 - 00000000 ____D () C:\Movies 2015-01-02 08:22 - 2014-06-30 09:35 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-01 22:06 - 2009-07-14 07:13 - 00782510 _____ () C:\windows\system32\PerfStringBackup.INI 2015-01-01 21:42 - 2011-10-18 13:28 - 00000960 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2063281587-2529135136-1089397287-1000Core.job 2014-12-31 21:30 - 2011-10-17 21:33 - 00000000 ____D () C:\Users\Nikola 2014-12-31 21:29 - 2014-06-30 09:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-12-31 21:28 - 2012-07-29 22:38 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-12-31 21:28 - 2012-01-10 16:36 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Wise Registry Cleaner 2014-12-31 21:28 - 2012-01-10 16:31 - 00000000 ____D () C:\Program Files (x86)\Wise Registry Cleaner 2014-12-31 21:28 - 2011-10-17 21:33 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2014-12-31 21:27 - 2011-10-18 13:16 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Skype 2014-12-31 21:27 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\registration 2014-12-27 16:57 - 2011-10-17 22:04 - 00000000 ____D () C:\Users\Nikola\AppData\Local\Microsoft Games 2014-12-22 21:39 - 2013-02-21 21:49 - 00000448 _____ () C:\windows\Tasks\Wise Registry Cleaner Schedule Task.job 2014-12-18 18:56 - 2014-03-22 18:14 - 00000000 ____D () C:\ETSY 2014-12-13 11:48 - 2014-03-27 08:15 - 00000000 ____D () C:\RAWS 2014-12-12 14:38 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-12-12 11:50 - 2012-07-29 21:56 - 00000000 ____D () C:\Program Files\Pale Moon 2014-12-11 07:17 - 2014-05-07 05:31 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-12-11 07:17 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\PolicyDefinitions 2014-12-11 07:17 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\AppCompat 2014-12-11 07:08 - 2013-07-19 05:26 - 00000000 ____D () C:\windows\system32\MRT 2014-12-11 06:44 - 2011-10-19 08:28 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-12-10 06:37 - 2012-07-29 22:38 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-12-10 06:37 - 2012-07-29 22:38 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-12-10 06:37 - 2011-11-03 21:06 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl Files to move or delete: ==================== C:\Users\Nikola\Photoshop_Portable_13.1.2_x64_Multilingual.exe C:\Users\Nikola\wlsetup-web.exe Some content of TEMP: ==================== C:\Users\Nikola\AppData\Local\Temp\HitmanPro.exe C:\Users\Nikola\AppData\Local\Temp\Quarantine.exe C:\Users\Nikola\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-25 00:22 ==================== End Of Log Благодаря предварително! Addition.txt
  23. Здравейте !Имам въпросче.Хванах вирус и ми изчезна пандата и стената .-ползувам Сигейт.Изчезнаха тотално .Това ми се случва за втори път май.Сканирах от другия компютър с Нод 32 и той откри Nao вирус който пандата не откри - пасивно сканиране на диска .Качих и на тоя компютър Нод 32 но гадината се е завряла някъде и постоянно записва нещо в систем рестора .Вчера изключих систем рестора и на тоя дял. Общо взето машината работи но има един досаден проблем- като стартирам някакъв торент да се сваля и ми блокират всичките браузери .Пробвах всички модзила Ие и гугъл хром - тоя пък въобще запецна . Бях с М торент - преинсталирах - същото махнах го и сега сложих Биткомет - същата работа . Моля някой ако може да даде съвет ако не преинсталирам ама от спортна злоба ми се ще да го хвана.
  24. Лаптопът се ползва от един малък "хакер" и ми се струва, че го е напълнил с какви ли не екстри. Пуснах Malwarebytes и изчисти каквото можа, но досадният istartsyrf си остана, а може би и още неща. Изобщо, ще съм благодарна ако някой помогне да почистя компютъра. FRST.txt Addition.txt
  25. Системата е със: Win 7 Ultimate 64 bit Comodo IS Malwarebytes Anti-Malware Преди 3 дни съм преинсталирал Прозореца , познат ме помоли да му намеря един гаджет за времето HTC HOME Apis свалил съм я от уж официален сайт (http://www.htchome.org/bg/) ,първоначално пуснах инсталацията в изолирана среда,но понеже нещо не се получи я пуснах в реален режим и тогава антивирусната ме затрупа с въпроси за разрешения.Но все пак си зная че COMODO съм го пуснал на най-високо ниво на защита и така или иначе ме пита за всичко,разреших всичко и направо се видях в чудо след инсталацията.От 40-42 процеса се оказаха пуснати над 60 ,а процесора се натовари над 70% .Оказа се че покрай въпросния гаджет са се намъкнали и още 5-6 други паразитни приложения който успях да изчистя с голям зор,имаше доста промени по регистрито и гадния номер че имаше стрингове във всички браузъри да зареждата като първоначална страница някаква си тяхна и дори от опцийте да си върнрш твоята пак не става,но с това се оправих де.За сега си мисля че съм изчистил всички поразий ,но един странен проблем продължава да си съществува. През известно време иконката от Десктопа на антивирусната се озовава в кошчето,прегледах всички инсталационни папки на COMODO ,но не можах да разбера къде е проблема,регистрите уж ги прочистих с Malwarebytes ,но може би там има нещо пропуснато.Възстановил съм си обичайните процеси и нови не виждам стартирани,макар че докато не се изчисти апп дата папката и регисрито някой от паразитните програмки периодично се възтановяваха..... Ако някой има идея да каже,не ми се занимава отново с преинсталация.Имам чист бекъп на друг дял ма харда ако това има значение. Мозилата ми е основен браузър и за това я изчистих и преинсталирах ,в дръгите браузъри нарочно оставих промените за да ви стане ясно за начина как променят коя страница се отваря при стартиране. Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015 Ran by Zlosterr (administrator) on ZLOSTERR-PC on 20-01-2015 11:54:55 Running from C:\Users\Zlosterr\Desktop Loaded Profiles: Zlosterr (Available profiles: Zlosterr) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (PcWinTech.com) C:\Program Files (x86)\CleanMem\Mini_Monitor.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe () C:\Program Files\Core Temp\Core Temp.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1297112 2015-01-17] (COMODO) HKU\S-1-5-21-1665565209-142464742-1340035291-1000\...\MountPoints2: {01c45a40-9fcb-11e4-b928-001bfc380a90} - O:\Autoplay.exe -auto Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-1665565209-142464742-1340035291-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp HKU\S-1-5-21-1665565209-142464742-1340035291-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1665565209-142464742-1340035291-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734&ts=1421605560&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1665565209-142464742-1340035291-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734&ts=1421605560&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1665565209-142464742-1340035291-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734&ts=1421605560&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1665565209-142464742-1340035291-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734&ts=1421605560&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1665565209-142464742-1340035291-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734&ts=1421605560&type=default&q={searchTerms} BHO-x32: No Name -> {11111111-1111-1111-1111-110611571143} -> No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{7B9E528B-084B-4FB0-B3C7-61C4FFC22317}: [NameServer] 178.254.192.5 178.254.192.3 FireFox: ======== FF ProfilePath: C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default FF Homepage: https://www.google.bg/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF user.js: detected! => C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\user.js FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: LavaFox V2 - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: Flashblock - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2015-01-17] FF Extension: Flash and Video Download - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2015-01-18] FF Extension: DownThemAll! AntiContainer - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: CacheDownload - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: cliget - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: YouTube Video and Audio Downloader - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: Ghostery - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: FireGestures - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: Free Memory - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: Private Tab - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: FastestFox - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\[email protected] [2015-01-17] FF Extension: CacheViewer - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}.xpi [2015-01-17] FF Extension: NoScript - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-01-17] FF Extension: Adblock Plus - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-17] FF Extension: DownThemAll! - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-17] FF Extension: Sothink Web Video Downloader for Firefox - C:\Users\Zlosterr\AppData\Roaming\Mozilla\Firefox\Profiles\ahzjpk9q.default\Extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}.xpi [2015-01-17] Chrome: ======= CHR HomePage: Default -> hxxp://www.mystartsearch.com/?type=hp&ts=1421605479&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734 CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hp&ts=1421605479&from=smt&uid=WDCXWD10EZEX-00UD2A0_WD-WMC3F007773477734" CHR DefaultSearchKeyword: Default -> mystartsearch CHR DefaultSuggestURL: Default -> CHR Profile: C:\Users\Zlosterr\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Zlosterr\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-19] CHR Extension: (Google Wallet) - C:\Users\Zlosterr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-17] CHR StartMenuInternet: Google Chrome - Chrome.exe ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70864 2014-07-25] (Comodo Security Solutions, Inc.) R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [7618952 2015-01-17] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265304 2015-01-17] (COMODO) S4 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2370240 2015-01-18] (Comodo Security Solutions, Inc.) S4 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-07-25] (Comodo Security Solutions, Inc.) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-01-19] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2015-01-19] (Malwarebytes Corporation) S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-08-16] (Microsoft Corporation) S2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe /service [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 3xHybr64; C:\Windows\System32\DRIVERS\3xHybr64.sys [3113904 2015-01-17] (ASUSTeK Computer Inc.) R3 c65013264; C:\Windows\System32\drivers\c6501.sys [1095168 2015-01-18] (C-Media Inc) R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2014-06-26] (Windows ® Win 7 DDK provider) [File not signed] R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20184 2014-12-09] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [792648 2014-12-09] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45880 2014-12-09] (COMODO) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-01-19] (DT Soft Ltd) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [104608 2014-12-09] (COMODO) R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [93400 2015-01-19] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-01-19] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-19] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-01-19] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2015-01-18] () S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () R3 ALSysIO; \??\C:\Users\Zlosterr\AppData\Local\Temp\ALSysIO64.sys [X] S3 SPBIUpdd; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys [X] S3 WinRing0_1_2_0; \??\C:\Users\Zlosterr\AppData\Local\Temp\tmpB6FF.tmp [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-20 11:54 - 2015-01-20 11:55 - 00014599 _____ () C:\Users\Zlosterr\Desktop\FRST.txt 2015-01-19 22:00 - 2015-01-19 22:00 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2015-01-19 21:01 - 2015-01-19 21:01 - 00044900 _____ () C:\Users\Zlosterr\Downloads\Shortcut.txt 2015-01-19 20:30 - 2015-01-19 20:30 - 00003055 _____ () C:\Users\Zlosterr\Downloads\Manaka.rar 2015-01-19 20:16 - 2015-01-20 11:55 - 00000000 ____D () C:\FRST 2015-01-19 20:13 - 2015-01-19 20:13 - 02126848 _____ (Farbar) C:\Users\Zlosterr\Desktop\FRST64.exe 2015-01-19 19:08 - 2015-01-19 19:08 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\PDAppFlex 2015-01-19 19:07 - 2015-01-19 19:07 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\NVIDIA 2015-01-19 18:35 - 2015-01-19 18:35 - 00001636 _____ () C:\Users\Zlosterr\Desktop\COMODO IS.lnk 2015-01-19 18:23 - 2015-01-19 18:23 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-01-19 18:22 - 2015-01-19 19:15 - 00000000 ____D () C:\Program Files\Adobe 2015-01-19 18:19 - 2015-01-19 19:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2015-01-19 18:08 - 2015-01-19 18:08 - 00283200 _____ (DT Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2015-01-19 18:07 - 2015-01-19 18:08 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Pro Advanced 2015-01-19 16:34 - 2015-01-19 16:34 - 00022306 _____ () C:\Users\Zlosterr\Downloads\justice.league.throne.of.atlantis(subsunacs.net).rar 2015-01-19 15:32 - 2015-01-19 15:32 - 29727656 _____ (Oracle Corporation) C:\Users\Zlosterr\Downloads\jre-8u25-windows-i586.exe 2015-01-19 15:31 - 2015-01-19 15:32 - 92658088 _____ (Oracle Corporation) C:\Users\Zlosterr\Downloads\jre-8u25-windows-x64.exe 2015-01-19 15:27 - 2015-01-19 15:27 - 00638888 _____ (Oracle Corporation) C:\Users\Zlosterr\Downloads\jxpiinstall.exe 2015-01-19 11:51 - 2015-01-19 12:28 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-19 11:51 - 2015-01-19 11:51 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-19 11:51 - 2015-01-19 11:51 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-19 11:51 - 2015-01-19 11:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-19 11:51 - 2015-01-19 11:51 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-01-19 11:51 - 2015-01-19 11:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-01-19 11:51 - 2015-01-19 11:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-01-19 11:38 - 2015-01-19 11:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-18 22:23 - 2015-01-19 18:11 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\DAEMON Tools Pro 2015-01-18 22:23 - 2015-01-19 18:11 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro 2015-01-18 21:49 - 2015-01-18 21:49 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-01-18 21:49 - 2015-01-18 21:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-18 20:37 - 2015-01-20 11:30 - 00001352 _____ () C:\Windows\Tasks\QPAHNNM.job 2015-01-18 20:36 - 2015-01-20 11:30 - 00001698 _____ () C:\Windows\Tasks\ADCVACOC.job 2015-01-18 20:36 - 2015-01-18 20:36 - 00004736 _____ () C:\Windows\System32\Tasks\ADCVACOC 2015-01-18 20:28 - 2015-01-18 20:28 - 00000000 ____D () C:\ProgramData\Sun 2015-01-18 20:28 - 2015-01-18 20:27 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2015-01-18 20:28 - 2015-01-18 20:27 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2015-01-18 20:26 - 2015-01-18 20:26 - 00000000 ____D () C:\Users\Public\Documents\ShopperPro 2015-01-18 20:24 - 2015-01-18 20:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Home 2015-01-18 18:25 - 2015-01-19 20:14 - 00000000 ____D () C:\Users\Zlosterr\Downloads\New folder 2015-01-18 15:55 - 2015-01-19 13:05 - 00024352 _____ () C:\Windows\PFRO.log 2015-01-18 13:19 - 2015-01-18 13:19 - 00000000 ____D () C:\Program Files (x86)\Comodo 2015-01-18 12:29 - 2015-01-18 18:26 - 00000000 ____D () C:\Users\Zlosterr\Documents\My Games 2015-01-18 12:29 - 2015-01-18 12:29 - 00000000 ____D () C:\Users\Zlosterr\Documents\Ubisoft 2015-01-18 12:29 - 2015-01-18 12:29 - 00000000 ____D () C:\Users\Zlosterr\Documents\samsung 2015-01-18 12:29 - 2015-01-18 12:29 - 00000000 ____D () C:\Users\Zlosterr\Documents\NFS Most Wanted 2015-01-18 12:29 - 2015-01-18 12:29 - 00000000 ____D () C:\Users\Zlosterr\Documents\Empire Earth II 2015-01-18 12:29 - 2015-01-18 12:29 - 00000000 ____D () C:\Users\Zlosterr\Documents\Assassin's Creed III 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Wargaming.net 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Unity 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Theta 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Sierra 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Opera 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\IrfanView 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\IObit 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\ImTOO 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Google 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\cr3 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Comodo 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\calibre 2015-01-18 12:27 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Ashampoo 2015-01-18 12:27 - 2014-01-29 17:00 - 00000624 _____ () C:\Users\Zlosterr\AppData\Roaming\All CPU MeterV3_Settings.ini 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Wondershare 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Unity 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Ubisoft Game Launcher 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Stardock_Corporation 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Sniper3 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Skyrim 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\SKIDROW 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\PlayMovie 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Opera 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\NVIDIA Corporation 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Macromedia 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Blizzard Entertainment 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Black_Tree_Gaming 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Apps\Windows 7 USB DVD Download Tool 2015-01-18 12:25 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Apps\2.0 2015-01-18 12:25 - 2014-11-27 23:35 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\calibre-cache 2015-01-18 12:25 - 2014-09-20 11:45 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\PackageAware 2015-01-18 12:22 - 2015-01-18 12:22 - 00000000 ____D () C:\Users\Zlosterr\Documents\Snagit 2015-01-18 12:21 - 2015-01-18 12:26 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\TechSmith 2015-01-18 12:21 - 2015-01-18 12:21 - 00000000 ____D () C:\ProgramData\TechSmith 2015-01-18 12:21 - 2015-01-18 12:21 - 00000000 ____D () C:\ProgramData\regid.1995-08.com.techsmith 2015-01-18 12:21 - 2015-01-18 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2015-01-18 12:21 - 2015-01-18 12:21 - 00000000 ____D () C:\Program Files (x86)\TechSmith 2015-01-18 12:20 - 2015-01-19 18:54 - 00006038 _____ () C:\Windows\WindowsUpdate.log 2015-01-18 12:20 - 2015-01-19 18:54 - 00000000 ____D () C:\ProgramData\Package Cache 2015-01-18 12:19 - 2015-01-18 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64 2015-01-18 12:19 - 2015-01-18 12:19 - 00000000 ____D () C:\Program Files\MPC-HC 2015-01-18 12:08 - 2015-01-18 12:08 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UnH Solutions 2015-01-18 12:08 - 2015-01-18 12:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnH Solutions 2015-01-18 12:08 - 2015-01-18 12:08 - 00000000 ____D () C:\Program Files (x86)\UnH Solutions 2015-01-18 12:07 - 2015-01-18 12:07 - 00001209 _____ () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk 2015-01-18 12:07 - 2015-01-18 12:07 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\GRETECH 2015-01-18 12:07 - 2015-01-18 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player 2015-01-18 12:07 - 2015-01-18 12:07 - 00000000 ____D () C:\Program Files (x86)\GRETECH 2015-01-18 12:06 - 2015-01-18 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView 2015-01-18 12:06 - 2015-01-18 12:06 - 00000000 ____D () C:\Program Files (x86)\XnView 2015-01-18 12:03 - 2015-01-18 12:03 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2015-01-18 12:03 - 2015-01-18 12:03 - 00000000 ____D () C:\Program Files\Unlocker 2015-01-18 12:02 - 2015-01-18 12:02 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Macromedia 2015-01-18 12:00 - 2015-01-18 12:01 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-01-18 12:00 - 2015-01-18 12:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-18 12:00 - 2015-01-18 12:00 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2015-01-18 12:00 - 2015-01-18 12:00 - 00000000 ____D () C:\Windows\system32\Macromed 2015-01-18 11:58 - 2015-01-18 11:58 - 00000000 __SHD () C:\Users\Zlosterr\AppData\Local\EmieBrowserModeList 2015-01-18 11:54 - 2015-01-18 11:54 - 00000000 ____D () C:\Program Files (x86)\Sothink SWF Decompiler 2015-01-18 11:52 - 2015-01-18 11:52 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TwistedBrush 2015-01-18 11:52 - 2015-01-18 11:52 - 00000000 ____D () C:\Program Files (x86)\Pixarra 2015-01-18 11:49 - 2015-01-18 11:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 2015-01-18 11:44 - 2015-01-18 11:44 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk 2015-01-18 11:44 - 2015-01-18 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2015-01-18 11:42 - 2015-01-20 11:29 - 00002116 _____ () C:\Windows\setupact.log 2015-01-18 11:42 - 2015-01-18 11:42 - 00000000 ____D () C:\ProgramData\FastStone 2015-01-18 11:42 - 2015-01-18 11:42 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-18 11:41 - 2015-01-18 11:41 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\FastStone 2015-01-18 11:41 - 2015-01-18 11:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Capture 2015-01-18 11:38 - 2015-01-19 19:18 - 00000000 ____D () C:\ProgramData\TEMP 2015-01-18 11:38 - 2015-01-18 11:38 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\URSoft 2015-01-18 11:38 - 2015-01-18 11:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 7 2015-01-18 11:38 - 2015-01-18 11:38 - 00000000 ____D () C:\Program Files (x86)\Your Uninstaller! 7 2015-01-18 11:30 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\FastStone 2015-01-18 11:30 - 2015-01-18 11:41 - 00000000 ____D () C:\Program Files (x86)\FastStone Capture 2015-01-18 11:29 - 2015-01-18 11:29 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro Advanced 2015-01-18 11:29 - 2015-01-18 11:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Photo Resizer 2015-01-18 11:29 - 2015-01-18 11:29 - 00000000 ____D () C:\Program Files (x86)\FastStone Photo Resizer 2015-01-18 11:22 - 2015-01-18 11:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-01-18 11:22 - 2015-01-18 11:22 - 00000000 ____D () C:\Program Files\CCleaner 2015-01-18 11:09 - 2015-01-18 12:25 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\ashampoo 2015-01-18 11:09 - 2015-01-18 11:09 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2015-01-18 11:09 - 2015-01-18 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2015-01-18 11:09 - 2015-01-18 11:09 - 00000000 ____D () C:\ProgramData\ashampoo 2015-01-18 11:08 - 2015-01-18 11:08 - 00000000 ____D () C:\Program Files (x86)\Ashampoo 2015-01-18 10:45 - 2015-01-18 10:45 - 00000000 ____D () C:\Windows\pss 2015-01-18 09:53 - 2015-01-18 09:53 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00069448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2015-01-18 09:53 - 2015-01-18 09:53 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2015-01-18 09:52 - 2015-01-18 09:53 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2015-01-18 09:52 - 2015-01-18 09:52 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2015-01-18 09:51 - 2015-01-18 09:54 - 00000000 ____D () C:\Windows\SysWOW64\directx 2015-01-18 09:44 - 2015-01-18 09:44 - 00518656 _____ (C-Media) C:\Windows\system32\Cmeau6501.exe 2015-01-18 09:44 - 2015-01-18 09:44 - 00000134 _____ () C:\Windows\system\Dlap.pfx 2015-01-18 09:44 - 2015-01-18 09:44 - 00000041 _____ () C:\Windows\system\c6501.INI 2015-01-18 09:43 - 2015-01-18 09:43 - 00000009 _____ () C:\pb.txt 2015-01-18 09:43 - 2007-02-09 19:28 - 00000281 _____ () C:\Windows\c6501.ini 2015-01-18 09:43 - 2007-01-16 15:49 - 00065536 _____ () C:\Windows\VMix.dll 2015-01-18 09:40 - 2015-01-18 09:43 - 06090752 _____ (C-Media Corporation) C:\Windows\SysWOW64\c6501.cpl 2015-01-18 09:40 - 2015-01-18 09:43 - 01095168 _____ (C-Media Inc) C:\Windows\system32\Drivers\c6501.sys 2015-01-18 09:40 - 2015-01-18 09:43 - 00712704 _____ (Sensaura Ltd) C:\Windows\system32\c6501a3d.dll 2015-01-18 09:40 - 2015-01-18 09:43 - 00712704 _____ (Sensaura Ltd) C:\Windows\system32\a3d.dll 2015-01-18 09:40 - 2015-01-18 09:43 - 00491008 _____ (C-Media Corporation) C:\Windows\SysWOW64\c6501rm.exe 2015-01-18 09:40 - 2015-01-18 09:43 - 00200704 _____ (C-Media) C:\Windows\SysWOW64\cmpaput.dll 2015-01-18 09:40 - 2015-01-18 09:43 - 00049152 _____ () C:\Windows\SysWOW64\c6501rm.dll 2015-01-18 09:40 - 2015-01-18 09:43 - 00032768 _____ (C-Media Electronics Inc.) C:\Windows\system32\c6501p.dll 2015-01-18 09:40 - 2015-01-18 09:40 - 00015416 _____ () C:\Windows\system32\Drivers\ASACPI.sys 2015-01-18 09:26 - 2015-01-18 09:26 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-18 09:26 - 2015-01-18 09:25 - 00539680 _____ (NVIDIA Corporation) C:\Windows\system32\nvusmb.exe 2015-01-18 09:25 - 2015-01-18 09:26 - 00644712 _____ (NVIDIA Corporation) C:\Windows\system32\NVUNINST.EXE 2015-01-18 09:25 - 2009-07-16 14:55 - 00002674 _____ () C:\Windows\system32\nvsmb.nvu 2015-01-18 09:24 - 2015-01-18 09:24 - 00000000 ____D () C:\NVIDIA 2015-01-18 08:36 - 2015-01-18 08:36 - 00003396 _____ () C:\Windows\System32\Tasks\CleanMem Mini Monitor 2015-01-18 05:30 - 2015-01-18 11:24 - 00000000 ____D () C:\Windows\Panther 2015-01-17 23:37 - 2015-01-18 09:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-01-17 23:36 - 2015-01-17 23:36 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\NVIDIA 2015-01-17 23:20 - 2015-01-20 11:29 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-01-17 23:20 - 2015-01-17 23:21 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-01-17 23:20 - 2015-01-17 23:20 - 00935368 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-01-17 23:20 - 2015-01-17 23:20 - 00609240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-01-17 23:20 - 2014-07-02 20:55 - 06783776 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-01-17 23:20 - 2014-07-02 20:55 - 03522392 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-01-17 23:20 - 2014-07-02 20:55 - 02559960 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-01-17 23:20 - 2014-07-02 20:55 - 00386520 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-01-17 23:20 - 2014-07-02 20:55 - 00062808 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-01-17 23:20 - 2014-07-02 12:14 - 03826628 _____ () C:\Windows\system32\nvcoproc.bin 2015-01-17 23:19 - 2015-01-18 09:26 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-01-17 23:19 - 2015-01-17 23:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-01-17 23:19 - 2015-01-17 23:18 - 00075040 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2015-01-17 23:19 - 2015-01-17 23:18 - 00061912 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2015-01-17 23:11 - 2015-01-17 23:20 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\vlc 2015-01-17 22:52 - 2015-01-19 18:49 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Adobe 2015-01-17 22:48 - 2015-01-17 22:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3 2015-01-17 22:47 - 2015-01-18 20:47 - 00000000 ____D () C:\Program Files (x86)\AIMP3 2015-01-17 22:47 - 2015-01-18 12:27 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\AIMP3 2015-01-17 22:45 - 2015-01-17 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-01-17 22:44 - 2015-01-18 15:55 - 00001002 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-17 22:44 - 2015-01-18 15:55 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-17 22:44 - 2015-01-18 12:33 - 00004010 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-01-17 22:44 - 2015-01-18 12:33 - 00003758 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-01-17 22:44 - 2015-01-18 11:49 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Google 2015-01-17 22:44 - 2015-01-18 11:49 - 00000000 ____D () C:\Program Files (x86)\Google 2015-01-17 22:43 - 2015-01-19 19:00 - 00003834 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1421527426 2015-01-17 22:43 - 2015-01-19 18:51 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-01-17 22:43 - 2015-01-17 22:43 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-01-17 22:43 - 2015-01-17 22:43 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Opera Software 2015-01-17 22:43 - 2015-01-17 22:43 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Opera Software 2015-01-17 22:28 - 2015-01-19 19:02 - 02127298 _____ () C:\Users\Zlosterr\Documents\AutoRuns.arn 2015-01-17 22:28 - 2015-01-17 22:28 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-01-17 22:28 - 2015-01-17 22:28 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2015-01-17 22:28 - 2015-01-17 22:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-01-17 22:28 - 2015-01-17 22:28 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2015-01-17 22:28 - 2015-01-17 22:28 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-01-17 22:28 - 2015-01-17 22:28 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2015-01-17 22:28 - 2015-01-17 22:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-01-17 22:28 - 2015-01-17 22:28 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2015-01-17 22:28 - 2015-01-17 22:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2015-01-17 22:28 - 2015-01-17 22:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-01-17 22:21 - 2015-01-17 22:21 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2015-01-17 22:21 - 2015-01-17 22:21 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2015-01-17 22:21 - 2015-01-17 22:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2015-01-17 22:21 - 2015-01-17 22:21 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2015-01-17 22:21 - 2015-01-17 22:21 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2015-01-17 22:21 - 2015-01-17 22:21 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2015-01-17 22:21 - 2015-01-17 22:21 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2015-01-17 22:21 - 2012-06-02 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2015-01-17 22:14 - 2015-01-18 09:25 - 00000000 ____D () C:\ProgramData\DriverGenius 2015-01-17 22:13 - 2015-01-17 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius 2015-01-17 22:13 - 2015-01-17 22:13 - 00000000 ____D () C:\Program Files (x86)\Driver-Soft 2015-01-17 22:00 - 2015-01-17 22:00 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2015-01-17 22:00 - 2015-01-17 22:00 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2015-01-17 21:54 - 2015-01-17 22:00 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-17 21:53 - 2015-01-17 21:53 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-01-17 21:53 - 2015-01-17 21:53 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-01-17 21:53 - 2015-01-17 21:53 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-01-17 21:53 - 2015-01-17 21:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-01-17 21:53 - 2015-01-17 21:53 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-01-17 21:53 - 2015-01-17 21:53 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-01-17 21:53 - 2015-01-17 21:53 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-01-17 21:53 - 2015-01-17 21:53 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-01-17 21:53 - 2015-01-17 21:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-01-17 21:53 - 2014-11-22 05:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-01-17 21:53 - 2014-11-22 04:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-01-17 21:52 - 2015-01-17 21:52 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 01050112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2015-01-17 21:52 - 2015-01-17 21:52 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-01-17 21:52 - 2015-01-17 21:52 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2015-01-17 21:52 - 2015-01-17 21:52 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-01-17 21:52 - 2015-01-17 21:52 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2015-01-17 21:52 - 2015-01-17 21:52 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-01-17 21:52 - 2015-01-17 21:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 05780480 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-01-17 21:51 - 2015-01-17 21:51 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2015-01-17 21:51 - 2015-01-17 21:51 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2015-01-17 21:51 - 2015-01-17 21:51 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-17 21:51 - 2015-01-17 21:51 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-01-17 21:51 - 2015-01-17 21:51 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-17 21:51 - 2015-01-17 21:51 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-01-17 21:51 - 2015-01-17 21:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-01-17 21:48 - 2015-01-17 21:48 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-01-17 21:48 - 2015-01-17 21:48 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-01-17 21:42 - 2015-01-17 21:42 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-01-17 21:42 - 2015-01-17 21:42 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-01-17 21:38 - 2015-01-18 22:29 - 00166062 _____ () C:\Windows\system32\Drivers\fvstore.dat 2015-01-17 21:38 - 2015-01-18 20:20 - 00000000 ___HD () C:\VTRoot 2015-01-17 21:30 - 2015-01-20 11:49 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2015-01-17 21:30 - 2015-01-18 13:19 - 00048392 _____ (COMODO CA Limited) C:\Windows\SysWOW64\certsentry.dll 2015-01-17 21:30 - 2015-01-17 21:30 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll 2015-01-17 21:30 - 2015-01-17 21:30 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2015-01-17 21:30 - 2015-01-17 21:30 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2015-01-17 21:30 - 2015-01-17 21:30 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO 2015-01-17 21:30 - 2015-01-17 21:30 - 00000000 ____D () C:\ProgramData\Shared Space 2015-01-17 21:29 - 2015-01-18 13:19 - 00057096 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll 2015-01-17 21:29 - 2015-01-18 13:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo 2015-01-17 21:29 - 2015-01-17 21:29 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Comodo 2015-01-17 21:29 - 2015-01-17 21:29 - 00000000 ____D () C:\Program Files\COMODO 2015-01-17 21:28 - 2015-01-17 21:28 - 00000000 ____D () C:\ProgramData\Comodo Downloader 2015-01-17 21:27 - 2015-01-17 21:30 - 00000000 ____D () C:\ProgramData\Comodo 2015-01-17 21:17 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-01-17 21:17 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-01-17 21:17 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-01-17 21:17 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-01-17 21:17 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-01-17 21:17 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-01-17 21:17 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-01-17 21:17 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-01-17 21:17 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-01-17 21:17 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-01-17 21:17 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-01-17 21:17 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-01-17 21:17 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-01-17 21:17 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-01-17 21:02 - 2015-01-17 21:02 - 00003512 _____ () C:\Windows\System32\Tasks\Clean System Memory 2015-01-17 21:02 - 2015-01-17 21:02 - 00000000 ____D () C:\Windows\CleanMem 2015-01-17 21:02 - 2015-01-17 21:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMem 2015-01-17 21:02 - 2015-01-17 21:02 - 00000000 ____D () C:\Program Files (x86)\CleanMem 2015-01-17 21:02 - 2012-09-21 01:27 - 00061440 _____ (PcWinTech.com) C:\Windows\SysWOW64\CleanMem.exe 2015-01-17 21:02 - 2012-06-26 21:40 - 00000187 _____ () C:\Windows\SysWOW64\CleanMem.ini 2015-01-17 21:02 - 2009-02-22 08:53 - 00000565 _____ () C:\Windows\SysWOW64\CleanMem.exe.manifest 2015-01-17 20:59 - 2015-01-17 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-01-17 20:59 - 2015-01-17 20:59 - 00000000 ____D () C:\Program Files\7-Zip 2015-01-17 20:55 - 2015-01-17 20:55 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\WinRAR 2015-01-17 20:53 - 2015-01-17 20:53 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-01-17 20:53 - 2015-01-17 20:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-01-17 20:52 - 2015-01-17 20:56 - 00000000 ____D () C:\Program Files\WinRAR 2015-01-17 20:50 - 2015-01-17 20:50 - 00000816 _____ () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk 2015-01-17 20:49 - 2015-01-19 18:12 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\BitTorrent 2015-01-17 20:47 - 2015-01-18 15:40 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer 2015-01-17 20:47 - 2015-01-17 20:47 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer 2015-01-17 20:45 - 2015-01-17 20:45 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2015-01-17 20:45 - 2015-01-17 20:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2015-01-17 20:44 - 2015-01-17 20:44 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2015-01-17 20:44 - 2015-01-17 20:44 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA 2015-01-17 20:44 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2015-01-17 20:44 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2015-01-17 20:44 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2015-01-17 20:44 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2015-01-17 20:44 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2015-01-17 20:44 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2015-01-17 20:44 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2015-01-17 20:43 - 2015-01-19 19:16 - 00000000 ____D () C:\ProgramData\Adobe 2015-01-17 20:43 - 2015-01-19 18:52 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-17 20:43 - 2015-01-17 20:43 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk 2015-01-17 20:39 - 2014-01-29 16:55 - 00000282 _____ () C:\Users\Zlosterr\AppData\Roaming\GPU MeterV2_Settings.ini 2015-01-17 20:37 - 2015-01-17 20:37 - 00058016 _____ () C:\Users\Zlosterr\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-17 20:37 - 2015-01-17 20:37 - 00000000 ____D () C:\Windows\System32\Tasks\PCMeter 2015-01-17 20:33 - 2015-01-18 08:38 - 00766518 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-01-17 20:26 - 2015-01-17 20:26 - 00002740 _____ () C:\Windows\System32\Tasks\Core Temp Autostart 2015-01-17 20:23 - 2015-01-20 11:30 - 00000000 ____D () C:\Program Files\Core Temp 2015-01-17 20:23 - 2015-01-17 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp 2015-01-17 20:11 - 2015-01-17 20:11 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Mozilla 2015-01-17 20:11 - 2015-01-17 20:11 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\Mozilla 2015-01-17 20:11 - 2015-01-17 20:11 - 00000000 ____D () C:\ProgramData\Mozilla 2015-01-17 20:10 - 2015-01-18 21:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-17 20:05 - 2015-01-17 20:05 - 00057654 _____ () C:\Windows\OEMLogo.bmp 2015-01-17 19:59 - 2015-01-17 19:59 - 00000000 __SHD () C:\Users\Zlosterr\AppData\Local\EmieUserList 2015-01-17 19:59 - 2015-01-17 19:59 - 00000000 __SHD () C:\Users\Zlosterr\AppData\Local\EmieSiteList 2015-01-17 19:47 - 2015-01-18 08:37 - 00000000 ____D () C:\Users\Zlosterr\Desktop\GAMEs 2015-01-17 19:47 - 2014-10-19 13:16 - 00001005 _____ () C:\Users\Zlosterr\Desktop\TESV - Shortcut.lnk 2015-01-17 19:47 - 2014-09-18 17:12 - 00001866 _____ () C:\Users\Zlosterr\Desktop\Divinity.txt 2015-01-17 19:47 - 2014-08-22 15:29 - 00000000 _____ () C:\Users\Zlosterr\Desktop\New Text Document.txt 2015-01-17 19:47 - 2014-08-18 13:18 - 00001281 _____ () C:\Users\Zlosterr\Desktop\Wow - WoLK.lnk 2015-01-17 19:47 - 2014-04-23 18:27 - 00000721 _____ () C:\Users\Zlosterr\Desktop\World of Tanks.lnk 2015-01-17 19:47 - 2014-01-17 16:30 - 00000842 _____ () C:\Users\Zlosterr\Desktop\Flash games.lnk 2015-01-17 19:47 - 2014-01-17 16:29 - 00000644 _____ () C:\Users\Zlosterr\Desktop\Movie.lnk 2015-01-17 19:41 - 2015-01-20 11:30 - 00000000 ____D () C:\Users\Zlosterr 2015-01-17 19:41 - 2015-01-19 19:13 - 00000000 ____D () C:\Users\Zlosterr\AppData\Roaming\Adobe 2015-01-17 19:41 - 2015-01-18 20:24 - 00001639 _____ () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-01-17 19:41 - 2015-01-18 12:26 - 00000000 ____D () C:\Users\Zlosterr\AppData\Local\VirtualStore 2015-01-17 19:41 - 2015-01-17 19:41 - 00000020 ___SH () C:\Users\Zlosterr\ntuser.ini 2015-01-17 19:41 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-01-17 19:41 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Zlosterr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-01-17 19:40 - 2015-01-17 21:54 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-17 19:40 - 2015-01-17 19:40 - 00000000 __SHD () C:\Recovery 2015-01-17 19:34 - 2015-01-17 19:34 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-01-17 19:33 - 2015-01-17 19:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-20 11:36 - 2009-07-14 06:45 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-20 11:36 - 2009-07-14 06:45 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-20 11:34 - 2009-07-14 07:13 - 00782652 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-20 11:29 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-19 22:00 - 2010-11-21 05:23 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winusb.sys 2015-01-19 22:00 - 2009-07-14 02:21 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\WpdMtp.dll 2015-01-19 22:00 - 2009-07-14 02:21 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\WpdMtpUS.dll 2015-01-18 21:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Services 2015-01-18 18:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-01-18 11:51 - 2014-08-13 01:00 - 04575232 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2015-01-18 09:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2015-01-18 05:30 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2015-01-18 05:30 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2015-01-17 23:35 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-01-17 23:34 - 2009-07-14 06:45 - 00267672 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-17 23:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-01-17 23:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2015-01-17 23:18 - 2014-08-19 22:15 - 31512520 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-01-17 23:18 - 2014-08-19 22:15 - 24196896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-01-17 23:18 - 2014-08-19 22:15 - 16122344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-01-17 23:18 - 2014-08-19 22:15 - 13922752 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-01-17 23:18 - 2014-08-19 22:15 - 11283344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 22994208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 17555104 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 15294296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 13835208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 12866008 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-01-17 23:18 - 2014-08-19 22:14 - 11222048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 04247000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 03989960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 03196816 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 01890080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434052.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 01539928 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434052.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 00944928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 00907096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 00903624 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-01-17 23:18 - 2014-08-19 22:14 - 00869152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-01-17 23:18 - 2014-08-19 22:13 - 02814656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-01-17 23:18 - 2009-07-13 23:59 - 18626304 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-01-17 23:18 - 2009-06-10 22:37 - 14498552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-01-17 23:04 - 2010-01-03 11:41 - 03113904 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\Drivers\3xHybr64.sys 2015-01-17 19:51 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore 2015-01-17 19:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2015-01-17 19:35 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-01-17 19:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep 2015-01-17 19:31 - 2010-11-21 09:16 - 00000000 ____D () C:\Windows\CSC ==================== Files in the root of some directories ======= 2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Zlosterr\AppData\Roaming\ADCVACOC 2015-01-18 12:27 - 2014-01-29 17:00 - 0000624 _____ () C:\Users\Zlosterr\AppData\Roaming\All CPU MeterV3_Settings.ini 2015-01-17 20:39 - 2014-01-29 16:55 - 0000282 _____ () C:\Users\Zlosterr\AppData\Roaming\GPU MeterV2_Settings.ini 2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Zlosterr\AppData\Roaming\QPAHNNM Some content of TEMP: ==================== C:\Users\Zlosterr\AppData\Local\Temp\AdobeApplicationManager.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-18 16:43 ==================== End Of Log ============================ Addition.txt
×
×
  • Добави ново...