Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#1 Příspěvek od xSorbi »

Zdravím, mám istý problém. V jeden deň mi naskočila Avira, keď som bol na FB. Pozeral som sa na to a skúsil som dať "Remove". Avira začala pracovať, lenže po dokončení mi vyhodilo to isté. Na Google Chrome mi začali vyskakovať všade samé reklami, pop-up, atď... Tak som si stiahol ADBlock, že to je normálna záležitosť, lebo dneska sú všade jednoducho reklamy. Nainštaloval som si ADBlock, išiel na YT a zrazu bum, 12 zablokovaných reklám. Neveril som že čo sa deje, nechápal som. Avira začala zasa vyskakovať, tak ma napadol MBAM (Raz už som tu bol s istým problémom a admin mi poradil že mám použiť na koniec MBAM, lebo som nemohol dostať preč vírus) že ten skúsim. Mám prémium ale mal som ho vypnuté, pretože som mal Aviru a spomalovalo mi to trochu net. Dám si update 2.0xxxxxxx, nechal som ho nainštalovať a zapnul som "Threat Scan". Všetko išlo po masle, ale na registroch mi našlo 8 threatov. Už som si myslel že je koniec ale zašiel som do "Filesystems Objects" alebo čosi také a zrazu plesk... 485 Threatov mi našlo :roll: ... Myslel som si že ma vystre.... Tak som to nechal nech mi to dá do karantény a nabehlo to na "Heuristic Scan". Tam to zamrzlo ale ukazovalo že to scanuje. Nechal som to hodinu bežať a stále na tom istom to stálo. Tak som to nechal bežať cez noc. Ráno sa na to pozerám a nič, stále iba "Heuristic Scan" a nič sa nepohlo iba ukazovalo že scan beží už 12 hod.... Tak som skúsil odinštalovať a nainštalovať. Stiahnul som si mbam-clean.exe na vyčistenie od MBAM. Potom som znova stiahnul, nainštaloval, zadal register key a dal sa mi update. Ten som nechal ísť. Keď bolo updatnuté tak som dal ten "Threat Scan" Všetko zasa ako pred tým. Zasa ten istý počet a zasa mi to seklo na "Heuristic Scan". Už ma to tak naštvalo, že som si otvoril list s tým čo tam je nájdené. No boháča, v registroch, zložky vo Windowse, SYSWOW64, pane bože. Tam som do toho nešiel ale počistil som také, ako bolo vo Program Files (x86), atď... Všetko k čomu som mal prístup. Potom som zapnul CCleaner a cez neho som vyčistil kôš. Zrušil som scan cez CTRL-ALT-Delete a zapnul znova. Ukázalo mi toho omnoho menej 244. Bol som rád, dokým nenaskočil istý "Heuristic Scan". Zasa mi to tam zamrzlo. Prosím Vás, spomaluje mi to PC, nič nemám zapnuté a CPU beží na 50%... :( Mám nový vyskladaný a nechcem ho zasrať :/ Ďakujem vopred za pomoc a pardon za sprosté výrazy, jednoducho mám na to nervy... :?: A neviem prečo, mi nejde ani Google Chrome zapnúť.
PS: Pridal som aj obrázok, ktorý som cvakol, keď som dal prvý krát scan. Ešte dám aj druhý s ukazovateľom výkonu, MBAM výpisom
PPS:A ešte aj RAM je na tom hrozne. Strašne sa to zvýšilo ! :(
PRVÝ SCAN: Obrázek http://postimg.org/image/9ikcf9b4d/
DRUHÝ SCAN: Obrázek http://postimg.org/image/534lcrcs9/
Čo oko nevidí to srdce nebolí.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Vypada to na hezkou sbirku :?:

:arrow: Dejte log z FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100 a mrknem na to
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#3 Příspěvek od xSorbi »

Zdravím :)
Ďakujem, že mi idete s tým pomôcť ! :D
Dal som ten scan a vyhodilo mi dva "Notepady" tak ich sem skopírujem :)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-09-2014 01
Ran by User (administrator) on USER-PC on 25-09-2014 17:00:59
Running from C:\Users\User\Downloads
Loaded Profile: User (Available profiles: User & Pablo)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Windows\SysWOW64\ASGT.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(http://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\vVX3000.exe
(Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
() C:\Program Files (x86)\Gaming Keyboard\OSD.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2460488 2014-09-17] (NVIDIA Corporation)
HKLM\...\Run: [Cm108Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
HKLM\...\Run: [VX3000] => C:\Windows\vVX3000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [VICTORY Gaming Keyboard] => C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [270336 2013-04-09] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [413696 2009-01-05] (Apple Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKU\S-1-5-21-2883089224-953471072-2576935892-1000\...\Run: [Akamai NetSession Interface] => C:\Users\User\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2883089224-953471072-2576935892-1000\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-2883089224-953471072-2576935892-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2883089224-953471072-2576935892-1000\...\Run: [Steam] => D:\Games\Steam\steam.exe [1938112 2014-09-23] (Valve Corporation)
HKU\S-1-5-21-2883089224-953471072-2576935892-1000\...\MountPoints2: {20168c2f-7cf2-11de-a222-806e6f6e6963} - E:\Setup.EXE
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-08-02] (Microsoft Corporation)
Startup: C:\Users\Pablo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: 46.107.14.243:3128
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFEAE984E1728CF01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: HomeTab -> {a19638fe-8536-4bcf-b659-a38ad619be61} -> C:\Program Files\HomeTab\IE\HomeTab.dll No File
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: HomeTab -> {a19638fe-8536-4bcf-b659-a38ad619be61} -> C:\Program Files (x86)\HomeTab\IE\HomeTab.dll No File
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - HomeTab - {a19638fe-8536-4bcf-b659-a38ad619be61} - C:\Program Files\HomeTab\IE\HomeTab.dll No File
Toolbar: HKLM-x32 - HomeTab - {a19638fe-8536-4bcf-b659-a38ad619be61} - C:\Program Files (x86)\HomeTab\IE\HomeTab.dll No File
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://www.asus.com/support/asusTek_sys_ctrl3.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{F71F1AB1-A6DA-4E38-A966-29BD639084CF}: [NameServer] 195.146.132.58 195.146.128.62

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default
FF NewTab: about:home
FF SelectedSearchEngine: Conduit Search
FF Homepage: about:home
FF NetworkProxy: "backup.ftp", "66.85.131.18"
FF NetworkProxy: "backup.ftp_port", 7808
FF NetworkProxy: "backup.socks", "66.85.131.18"
FF NetworkProxy: "backup.socks_port", 7808
FF NetworkProxy: "backup.ssl", "66.85.131.18"
FF NetworkProxy: "backup.ssl_port", 7808
FF NetworkProxy: "ftp", "66.85.131.18"
FF NetworkProxy: "ftp_port", 7808
FF NetworkProxy: "http", "66.85.131.18"
FF NetworkProxy: "http_port", 7808
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "66.85.131.18"
FF NetworkProxy: "socks_port", 7808
FF NetworkProxy: "ssl", "66.85.131.18"
FF NetworkProxy: "ssl_port", 7808
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @Sibelius.com/Scorch Plugin,version=6.2.0.88 -> C:\Program Files (x86)\Sibelius Software\Scorch\npsibelius.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPSibelius.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\PDFNetC.dll (PDFTron Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ScorchAxPlugin.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ScorchPDFWrapper.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: iMacros for Firefox - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-09-15]
FF Extension: HomeTab - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\Extensions\{95fa82a2-5246-43e0-bcee-3801c239c192} [2014-09-17]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]

Chrome:
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Easy Auto Refresh) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2014-09-09]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-09-19]
CHR Extension: (iMacros for Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp [2014-09-16]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2014-09-09]
CHR Extension: (Skype Click to Call) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-05-14]
CHR Extension: (ClipConverter) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\njjjgjlocdhecpgdcfjblcnfebfnmhpp [2014-08-10]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-14]
CHR HKCU\...\Chrome\Extension: [cpoooaodibfldhiobnmnjliddplmekeb] - C:\Users\User\AppData\Local\CRE\cpoooaodibfldhiobnmnjliddplmekeb.crx []
CHR HKLM-x32\...\Chrome\Extension: [cpoooaodibfldhiobnmnjliddplmekeb] - C:\Users\User\AppData\Local\CRE\cpoooaodibfldhiobnmnjliddplmekeb.crx []
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-12] (Avira Operations GmbH & Co. KG)
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed]
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG)
S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-05-21] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-05-21] (BlueStack Systems, Inc.)
S4 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [774928 2014-05-21] (BlueStack Systems, Inc.)
S4 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S4 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-09-17] (NVIDIA Corporation)
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-08-08] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-09-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19439944 2014-09-17] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-06-28] ()
S4 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc [X]
S4 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [123152 2014-05-21] (BlueStack Systems)
S3 CEDRIVER60; C:\Program Files (x86)\Cheat Engine 6.3\dbk64.sys [58368 2014-05-29] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-01] (Disc Soft Ltd)
R2 hmip; C:\Windows\system32\Drivers\hmip64.sys [30056 2013-06-19] (Hide My IP)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-25] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-01] (Duplex Secure Ltd.)
S3 OSFMount; \??\C:\Users\User\Desktop\bin\OSFMount.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 17:00 - 2014-09-25 17:01 - 00024743 _____ () C:\Users\User\Downloads\FRST.txt
2014-09-25 17:00 - 2014-09-25 17:01 - 00000000 ____D () C:\FRST
2014-09-25 16:58 - 2014-09-25 16:58 - 02108928 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-09-25 16:52 - 2014-09-25 16:53 - 00000168 _____ () C:\Windows\setupact.log
2014-09-25 16:52 - 2014-09-25 16:52 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 20:20 - 2014-09-24 20:20 - 00000000 ____D () C:\Users\User\Downloads\Trenčianské Zázraky na cestách
2014-09-24 13:53 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 13:53 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-23 13:01 - 2014-09-23 13:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-23 13:01 - 2014-09-23 13:01 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-21 21:10 - 2014-09-21 21:10 - 03157504 _____ () C:\Users\User\Downloads\Zajímavé nápady.pps
2014-09-20 22:34 - 2014-09-20 22:34 - 00257065 _____ () C:\Users\User\Downloads\Když se parkour nepovede!.mp4
2014-09-20 12:01 - 2014-09-25 16:55 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-20 12:01 - 2014-09-20 12:01 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-20 12:01 - 2014-09-20 12:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-20 12:00 - 2014-09-20 12:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-20 12:00 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-20 12:00 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-20 12:00 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-20 11:55 - 2014-09-20 11:56 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-20 11:55 - 2014-09-20 11:55 - 00321848 _____ (Malwarebytes Corporation) C:\Users\User\Downloads\mbam-clean-2.1.1.1001.exe
2014-09-20 10:02 - 2014-09-20 10:02 - 00000000 ____D () C:\Windows\Sun
2014-09-20 10:02 - 2014-09-20 10:02 - 00000000 ____D () C:\Users\User\AppData\Roaming\Oracle
2014-09-20 10:02 - 2014-09-20 10:02 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-20 10:01 - 2014-09-20 10:01 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-20 10:01 - 2014-09-20 10:01 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-20 10:01 - 2014-09-20 10:01 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-20 10:01 - 2014-09-20 10:01 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-20 10:01 - 2014-09-20 10:01 - 00000000 ____D () C:\ProgramData\Sun
2014-09-20 10:01 - 2014-09-20 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-20 10:01 - 2014-09-20 10:01 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-20 09:59 - 2014-09-20 09:59 - 00918440 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u67.exe
2014-09-19 23:47 - 2014-09-19 23:48 - 16566692 _____ () C:\Users\User\Downloads\Kidnappers Kit 2.0.rar
2014-09-19 23:46 - 2014-09-19 23:46 - 28544258 _____ () C:\Users\User\Downloads\Mila_DOA5_v2.1.rar
2014-09-19 23:46 - 2014-09-19 23:46 - 03839530 _____ () C:\Users\User\Downloads\chickenssstoys.rar
2014-09-19 23:42 - 2014-09-19 23:43 - 11932699 _____ () C:\Users\User\Downloads\femshep_n_v1.0.rar
2014-09-19 23:40 - 2014-09-19 23:40 - 09600900 _____ () C:\Users\User\Downloads\RE6_Sherry_Lewd_3.7z
2014-09-19 22:35 - 2014-09-19 22:35 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-09-19 22:35 - 2014-09-13 22:13 - 00613696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-09-19 22:34 - 2014-09-25 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-19 22:34 - 2014-09-14 01:48 - 00073872 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-09-19 22:34 - 2014-09-14 01:48 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-09-19 22:34 - 2014-09-13 23:53 - 06890696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-09-19 22:34 - 2014-09-13 23:53 - 03529872 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-09-19 22:34 - 2014-09-13 23:53 - 02557640 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-09-19 22:34 - 2014-09-13 23:53 - 00934216 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-09-19 22:34 - 2014-09-13 23:53 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-09-19 22:34 - 2014-09-13 23:53 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-09-19 22:34 - 2014-09-11 17:37 - 03961833 _____ () C:\Windows\system32\nvcoproc.bin
2014-09-19 22:31 - 2014-09-17 06:51 - 01538880 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-09-19 22:31 - 2014-09-17 06:51 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-09-19 22:31 - 2014-09-17 06:51 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 31887680 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 24552592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 20922512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 20589536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 19954520 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 18106152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 17259664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 16875856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 14026304 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 13939272 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 13157696 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-09-19 22:31 - 2014-09-14 01:48 - 11392576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 11330776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 04287296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 04008592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 03223120 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 02838424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 01876296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434411.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 01539272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434411.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00984424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00957584 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00925896 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00919240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00894096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00867528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00501064 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00417096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00393024 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00352016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00348304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00303600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00174856 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00156840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-09-19 22:31 - 2014-09-14 01:48 - 00026956 _____ () C:\Windows\system32\nvinfo.pb
2014-09-19 21:52 - 2014-09-04 21:14 - 00038048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-09-19 21:52 - 2014-09-04 21:14 - 00032416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-09-19 12:28 - 2014-09-24 20:36 - 00000000 ____D () C:\Users\User\Desktop\hovadiny
2014-09-18 23:16 - 2014-09-18 23:16 - 02698722 _____ () C:\Users\User\Downloads\Paysafecard-Moneymaker.rar
2014-09-18 23:15 - 2014-09-18 23:15 - 00000129 _____ () C:\Users\User\Downloads\PaySafeCard-zadarmo.txt
2014-09-18 22:57 - 2014-09-25 16:57 - 00004476 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11.job
2014-09-18 22:57 - 2014-09-25 16:57 - 00003794 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4.job
2014-09-18 22:57 - 2014-09-25 16:57 - 00003450 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-6.job
2014-09-18 22:57 - 2014-09-25 16:57 - 00003114 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7.job
2014-09-18 22:57 - 2014-09-19 12:21 - 00000882 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-09-18 22:57 - 2014-09-19 12:21 - 00000878 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-09-18 22:57 - 2014-09-18 22:57 - 00007506 _____ () C:\Windows\System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11
2014-09-18 22:57 - 2014-09-18 22:57 - 00006824 _____ () C:\Windows\System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4
2014-09-18 22:57 - 2014-09-18 22:57 - 00006144 _____ () C:\Windows\System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7
2014-09-18 22:57 - 2014-09-18 22:57 - 00003892 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-09-18 22:57 - 2014-09-18 22:57 - 00003638 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-09-18 22:55 - 2014-09-18 22:55 - 00560939 _____ () C:\Users\User\Downloads\Paysafecard Code Generator 2014.rar
2014-09-18 20:51 - 2014-09-18 20:51 - 01450962 _____ () C:\Users\User\Downloads\metro_for_steam___3_8___beta_9_by_boneyardbrew-d4u3kjv.zip
2014-09-18 20:50 - 2014-09-18 20:50 - 00046578 _____ () C:\Users\User\Downloads\Metro.for.Steam.Settings.zip
2014-09-18 15:16 - 2014-09-18 15:16 - 00001174 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-09-18 15:16 - 2014-09-18 15:16 - 00000000 ____D () C:\Users\User\AppData\Roaming\TeamViewer
2014-09-18 15:16 - 2014-09-18 15:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-09-18 15:15 - 2014-09-18 15:15 - 06630552 _____ (TeamViewer GmbH) C:\Users\User\Downloads\TeamViewer_Setup_cs.exe
2014-09-18 12:48 - 2014-09-18 12:48 - 00000000 ____D () C:\Users\User\Downloads\Skype WebCam hacker 2014 new v3
2014-09-18 12:42 - 2014-09-18 12:43 - 00000000 ____D () C:\Users\User\AppData\Roaming\Activeris
2014-09-17 13:58 - 2014-09-17 13:58 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-09-17 13:58 - 2014-09-17 13:58 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch
2014-09-17 13:58 - 2014-09-17 13:58 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-09-17 13:58 - 2014-09-11 09:14 - 00034368 _____ () C:\Windows\Launcher.exe
2014-09-17 12:50 - 2014-09-17 12:56 - 84431777 _____ () C:\Users\User\Downloads\Antonov An-225 Mriya by Discovery Channel.mp4
2014-09-16 20:09 - 2014-09-16 20:09 - 03497898 _____ () C:\Users\User\Downloads\Worst Movie Death Scene Ever!.mp4
2014-09-16 18:04 - 2014-09-16 18:04 - 00001704 _____ () C:\Users\User\Downloads\YouLikeHits AllInOne Bots - RushingWind - CPAE.zip
2014-09-16 17:34 - 2014-09-22 19:16 - 00000000 ____D () C:\xampp
2014-09-16 17:34 - 2014-09-16 17:34 - 00015983 _____ () C:\Users\User\Downloads\ylh (1).rar
2014-09-16 16:48 - 2014-09-16 16:48 - 00423980 _____ () C:\Users\User\Downloads\prd.wav
2014-09-16 16:33 - 2014-09-16 16:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-15 23:46 - 2014-09-15 23:46 - 00015983 _____ () C:\Users\User\Downloads\ylh.rar
2014-09-15 23:43 - 2014-09-16 00:19 - 00000000 ____D () C:\Program Files (x86)\YLH.bot
2014-09-15 23:43 - 2014-09-15 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YLH.bot
2014-09-15 23:43 - 2010-02-16 09:21 - 01744896 _____ (Chilkat Software, Inc.) C:\Windows\SysWOW64\ChilkatHttp.dll
2014-09-15 23:43 - 2004-03-09 15:45 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2014-09-15 23:43 - 2004-03-09 00:00 - 00124688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWINSCK.OCX
2014-09-15 23:18 - 2014-09-15 23:18 - 00000000 ____D () C:\Users\User\Documents\iMacros
2014-09-15 23:13 - 2014-09-16 11:31 - 00000099 _____ () C:\Windows\ylh-open.bat
2014-09-15 22:50 - 2014-09-15 23:13 - 00000002 _____ () C:\Windows\ylh-actions.txt
2014-09-15 22:47 - 2014-09-15 22:47 - 07723200 _____ () C:\Users\User\Downloads\You-like-hits-bot-free.zip
2014-09-14 23:51 - 2014-09-14 23:51 - 00000000 ____D () C:\Users\User\Downloads\idle_master-master
2014-09-14 23:34 - 2014-09-14 23:34 - 02421892 _____ () C:\Users\User\Downloads\Funny Thai Commercial (Hatari) With Subtitles!!!.mp4
2014-09-14 14:29 - 2014-09-14 14:29 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-13 19:44 - 2014-09-13 19:45 - 10672356 _____ () C:\Users\User\Downloads\The station - Feeling Filthy (full).mp4
2014-09-12 23:03 - 2014-09-12 23:17 - 82970512 _____ () C:\Users\User\Documents\lol.mp4
2014-09-12 23:02 - 2014-09-12 23:02 - 00069955 _____ () C:\Users\User\Documents\prvy officialny test 1080 uhd.mp4
2014-09-12 21:42 - 2014-09-12 21:54 - 00003232 _____ () C:\Users\User\Downloads\Air Horn Sound Effect.mp3.sfk
2014-09-12 21:21 - 2014-09-12 23:19 - 00105024 _____ () C:\Users\User\Documents\lol.veg
2014-09-12 21:21 - 2014-09-12 23:11 - 00105024 _____ () C:\Users\User\Documents\lol.veg.bak
2014-09-12 21:05 - 2014-09-12 21:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\Sony Creative Software Inc
2014-09-12 20:43 - 2014-09-12 20:44 - 04470739 _____ () C:\Users\User\Downloads\Lens Flare Sun Green Screen ANIMATION FREE FOOTAGE HD.mp4
2014-09-12 20:37 - 2014-09-12 20:38 - 12958295 _____ () C:\Users\User\Downloads\[FREE SOURCE] Montage Parody Pack (Pt. 1).mp4
2014-09-12 20:37 - 2014-09-12 20:37 - 01736171 _____ () C:\Users\User\Downloads\we like to party rainbow frog.mp4
2014-09-11 22:01 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 22:01 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 22:01 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 22:01 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 22:01 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 22:01 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 22:01 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 22:01 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 22:01 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 22:01 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 22:01 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 22:01 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 22:01 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 22:01 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 22:01 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 22:01 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 22:01 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 22:01 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 22:01 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 22:01 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 22:01 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 22:01 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 22:01 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 22:01 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 22:01 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 22:01 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 22:01 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 22:01 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 22:01 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 22:01 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 22:01 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 22:01 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 22:01 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 22:01 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 22:01 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 22:01 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 22:01 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 22:01 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 22:01 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 22:01 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 22:01 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 22:01 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 22:01 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 22:01 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 22:01 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 22:01 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 22:01 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 22:01 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 22:01 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 22:01 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 22:01 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 22:01 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 22:01 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 22:01 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 22:01 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 22:01 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 21:59 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 21:59 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 16:49 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-11 16:49 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-11 16:49 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-11 16:49 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 16:49 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-11 16:49 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-11 16:49 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-11 16:49 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-11 16:49 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-11 16:49 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-11 16:49 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-10 22:14 - 2014-09-10 22:14 - 00067118 _____ () C:\Users\User\Downloads\long range sniper rifle.lxf
2014-09-07 22:21 - 2014-09-07 22:21 - 01456859 _____ () C:\Users\User\Downloads\Snoop Dogg -Drop It Like It's Hot- Dance Greenscreen HD Footage With -Smoke Weed Everyday- Sound.mp4
2014-09-07 22:05 - 2014-09-09 14:47 - 32336141 _____ () C:\Users\User\Documents\Untitled.mp4
2014-09-07 21:32 - 2014-09-12 22:59 - 00000000 ____D () C:\Users\User\Documents\OFX Presets
2014-09-07 21:26 - 2014-09-07 21:26 - 00000000 ____D () C:\Program Files\Sony
2014-09-07 21:12 - 2014-09-07 21:12 - 00000000 ____D () C:\Users\User\Downloads\Sony.Vegas.Pro.12.0.build.367.x64.Incl.keygen-P2P
2014-09-07 21:09 - 2014-09-07 21:15 - 00002628 _____ () C:\Users\User\Documents\Register Vegas Pro12.htm
2014-09-06 23:19 - 2014-09-06 23:19 - 02508988 _____ () C:\Users\User\Downloads\white screen intervention mw2.mp4
2014-09-06 21:00 - 2014-09-06 21:01 - 24386033 _____ () C:\Users\User\Downloads\Doller Rain on green screen - free green screen.mp4
2014-09-06 20:41 - 2014-09-06 20:41 - 00086406 _____ () C:\Users\User\Downloads\38ceaa2e17aadb8bb325ad0e4928bd6e.jpeg
2014-09-05 21:57 - 2014-09-05 21:57 - 00000000 ____D () C:\Users\User\AppData\Local\CrashRpt
2014-09-05 21:53 - 2014-09-05 21:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BeamNG
2014-09-05 20:13 - 2014-09-05 20:13 - 03418325 _____ () C:\Users\User\Downloads\The Ukrainian Talents - Man gets hit with Bow and Arrow.mp4
2014-09-05 19:28 - 2014-09-05 19:29 - 06270219 _____ () C:\Users\User\Downloads\Ordinary Russian TV show - Fight.mp4
2014-09-05 14:12 - 2014-09-05 14:12 - 01360647 _____ () C:\Users\User\Downloads\Fuck her right in the pussy! (Green Screen).mp4
2014-09-05 14:08 - 2014-09-05 14:08 - 01896929 _____ () C:\Users\User\Downloads\MOM GET THE CAMERA!.mp4
2014-09-05 14:03 - 2014-09-05 14:03 - 00640336 _____ () C:\Users\User\Downloads\GTA5 -wasted- green screen effect + sound.mp4
2014-09-04 22:40 - 2014-09-04 22:41 - 09397714 _____ () C:\Users\User\Downloads\Big Explosion 001 - green screen effects.mp4
2014-09-04 22:39 - 2014-09-04 22:40 - 10073198 _____ () C:\Users\User\Downloads\Green Screen Machine Gun and Grenade HD - Footage PixelBoom.mp4
2014-09-04 22:38 - 2014-09-04 22:38 - 03093809 _____ () C:\Users\User\Downloads\M249 SAW - Shoot & Reload - GreenScreen Pro's HD.mp4
2014-09-04 22:35 - 2014-09-04 22:35 - 01230149 _____ () C:\Users\User\Downloads\Chroma Bullet Pass (Downloadable video).mp4
2014-09-04 22:18 - 2014-09-04 22:21 - 103952408 _____ () C:\Users\User\Downloads\A NEW DANK.mp4
2014-09-04 22:18 - 2014-09-04 22:19 - 15259567 _____ () C:\Users\User\Downloads\Doritos Kid Gets Quickscoped.mp4
2014-09-02 14:52 - 2014-09-02 14:52 - 00000000 ____D () C:\Users\Pablo\Desktop\foto
2014-08-29 15:31 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-29 15:31 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-29 15:31 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 17:01 - 2014-09-25 17:00 - 00024743 _____ () C:\Users\User\Downloads\FRST.txt
2014-09-25 17:01 - 2014-09-25 17:00 - 00000000 ____D () C:\FRST
2014-09-25 17:00 - 2013-10-30 19:46 - 01893123 _____ () C:\Windows\WindowsUpdate.log
2014-09-25 16:58 - 2014-09-25 16:58 - 02108928 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-09-25 16:57 - 2014-09-18 22:57 - 00004476 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11.job
2014-09-25 16:57 - 2014-09-18 22:57 - 00003794 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4.job
2014-09-25 16:57 - 2014-09-18 22:57 - 00003450 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-6.job
2014-09-25 16:57 - 2014-09-18 22:57 - 00003114 _____ () C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7.job
2014-09-25 16:57 - 2009-07-14 06:45 - 00020880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-25 16:57 - 2009-07-14 06:45 - 00020880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-25 16:55 - 2014-09-20 12:01 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 16:55 - 2013-12-25 13:10 - 00000000 ____D () C:\Users\User\AppData\Local\LogMeIn Hamachi
2014-09-25 16:55 - 2013-08-05 10:27 - 00000432 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-09-25 16:53 - 2014-09-25 16:52 - 00000168 _____ () C:\Windows\setupact.log
2014-09-25 16:53 - 2013-12-17 23:49 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-25 16:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-25 16:52 - 2014-09-25 16:52 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-25 16:52 - 2014-09-19 22:34 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-24 23:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK
2014-09-24 23:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sk-SK
2014-09-24 22:54 - 2013-08-01 20:02 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2014-09-24 22:34 - 2014-06-04 18:25 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-24 22:26 - 2013-12-17 23:49 - 00000932 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-24 21:16 - 2013-08-13 23:17 - 00000000 ____D () C:\Users\User\AppData\Local\Paint.NET
2014-09-24 20:36 - 2014-09-19 12:28 - 00000000 ____D () C:\Users\User\Desktop\hovadiny
2014-09-24 20:20 - 2014-09-24 20:20 - 00000000 ____D () C:\Users\User\Downloads\Trenčianské Zázraky na cestách
2014-09-24 20:20 - 2014-02-04 22:42 - 00035840 ___SH () C:\Users\User\Thumbs.db
2014-09-24 17:10 - 2014-08-21 22:54 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-09-24 17:10 - 2014-01-07 14:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Winamp
2014-09-24 17:10 - 2013-08-14 01:45 - 00000000 ____D () C:\Users\User\AppData\Roaming\Media Player Classic
2014-09-24 17:10 - 2013-08-01 22:15 - 00000000 ____D () C:\Users\User\AppData\Roaming\Sony
2014-09-24 17:10 - 2013-08-01 22:06 - 00000000 ____D () C:\Users\User\AppData\Roaming\uTorrent
2014-09-24 17:10 - 2013-08-01 21:14 - 00000000 ____D () C:\Users\User\AppData\Roaming\DAEMON Tools Lite
2014-09-24 14:34 - 2014-06-04 18:25 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-24 14:34 - 2014-06-04 18:25 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-24 14:34 - 2014-06-04 18:25 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-24 13:47 - 2014-08-10 09:35 - 00000000 ____D () C:\Users\User\AppData\Local\TSVNCache
2014-09-23 18:02 - 2014-06-27 11:52 - 00000792 _____ () C:\Windows\Cm108.ini.imi
2014-09-23 13:47 - 2013-08-13 23:19 - 00001188 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
2014-09-23 13:47 - 2013-08-13 23:18 - 00000000 ____D () C:\Program Files\Paint.NET
2014-09-23 13:01 - 2014-09-23 13:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-23 13:01 - 2014-09-23 13:01 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-22 19:16 - 2014-09-16 17:34 - 00000000 ____D () C:\xampp
2014-09-21 21:10 - 2014-09-21 21:10 - 03157504 _____ () C:\Users\User\Downloads\Zajímavé nápady.pps
2014-09-20 22:34 - 2014-09-20 22:34 - 00257065 _____ () C:\Users\User\Downloads\Když se parkour nepovede!.mp4
2014-09-20 12:01 - 2014-09-20 12:01 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-20 12:01 - 2014-09-20 12:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-20 12:01 - 2014-09-20 12:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-20 12:00 - 2013-09-02 10:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-20 11:56 - 2014-09-20 11:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-20 11:55 - 2014-09-20 11:55 - 00321848 _____ (Malwarebytes Corporation) C:\Users\User\Downloads\mbam-clean-2.1.1.1001.exe
2014-09-20 10:02 - 2014-09-20 10:02 - 00000000 ____D () C:\Windows\Sun
2014-09-20 10:02 - 2014-09-20 10:02 - 00000000 ____D () C:\Users\User\AppData\Roaming\Oracle
2014-09-20 10:02 - 2014-09-20 10:02 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-20 10:01 - 2014-09-20 10:01 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-20 10:01 - 2014-09-20 10:01 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-20 10:01 - 2014-09-20 10:01 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-20 10:01 - 2014-09-20 10:01 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-20 10:01 - 2014-09-20 10:01 - 00000000 ____D () C:\ProgramData\Sun
2014-09-20 10:01 - 2014-09-20 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-20 10:01 - 2014-09-20 10:01 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-20 09:59 - 2014-09-20 09:59 - 00918440 _____ (Oracle Corporation) C:\Users\User\Downloads\chromeinstall-7u67.exe
2014-09-19 23:48 - 2014-09-19 23:47 - 16566692 _____ () C:\Users\User\Downloads\Kidnappers Kit 2.0.rar
2014-09-19 23:46 - 2014-09-19 23:46 - 28544258 _____ () C:\Users\User\Downloads\Mila_DOA5_v2.1.rar
2014-09-19 23:46 - 2014-09-19 23:46 - 03839530 _____ () C:\Users\User\Downloads\chickenssstoys.rar
2014-09-19 23:43 - 2014-09-19 23:42 - 11932699 _____ () C:\Users\User\Downloads\femshep_n_v1.0.rar
2014-09-19 23:40 - 2014-09-19 23:40 - 09600900 _____ () C:\Users\User\Downloads\RE6_Sherry_Lewd_3.7z
2014-09-19 22:35 - 2014-09-19 22:35 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-09-19 22:35 - 2013-07-31 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-09-19 22:35 - 2013-07-31 21:42 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-09-19 22:34 - 2013-07-31 21:42 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-09-19 22:34 - 2013-07-31 21:41 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-09-19 22:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2014-09-19 12:21 - 2014-09-18 22:57 - 00000882 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-09-19 12:21 - 2014-09-18 22:57 - 00000878 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-09-19 12:21 - 2009-07-14 06:45 - 05058576 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-18 23:20 - 2014-08-21 22:19 - 00000000 ____D () C:\ProgramData\Freemake
2014-09-18 23:16 - 2014-09-18 23:16 - 02698722 _____ () C:\Users\User\Downloads\Paysafecard-Moneymaker.rar
2014-09-18 23:15 - 2014-09-18 23:15 - 00000129 _____ () C:\Users\User\Downloads\PaySafeCard-zadarmo.txt
2014-09-18 22:57 - 2014-09-18 22:57 - 00007506 _____ () C:\Windows\System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11
2014-09-18 22:57 - 2014-09-18 22:57 - 00006824 _____ () C:\Windows\System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4
2014-09-18 22:57 - 2014-09-18 22:57 - 00006144 _____ () C:\Windows\System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7
2014-09-18 22:57 - 2014-09-18 22:57 - 00003892 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-09-18 22:57 - 2014-09-18 22:57 - 00003638 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-09-18 22:55 - 2014-09-18 22:55 - 00560939 _____ () C:\Users\User\Downloads\Paysafecard Code Generator 2014.rar
2014-09-18 20:52 - 2013-07-31 21:06 - 00123408 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-18 20:51 - 2014-09-18 20:51 - 01450962 _____ () C:\Users\User\Downloads\metro_for_steam___3_8___beta_9_by_boneyardbrew-d4u3kjv.zip
2014-09-18 20:50 - 2014-09-18 20:50 - 00046578 _____ () C:\Users\User\Downloads\Metro.for.Steam.Settings.zip
2014-09-18 15:16 - 2014-09-18 15:16 - 00001174 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-09-18 15:16 - 2014-09-18 15:16 - 00000000 ____D () C:\Users\User\AppData\Roaming\TeamViewer
2014-09-18 15:16 - 2014-09-18 15:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-09-18 15:15 - 2014-09-18 15:15 - 06630552 _____ (TeamViewer GmbH) C:\Users\User\Downloads\TeamViewer_Setup_cs.exe
2014-09-18 12:48 - 2014-09-18 12:48 - 00000000 ____D () C:\Users\User\Downloads\Skype WebCam hacker 2014 new v3
2014-09-18 12:43 - 2014-09-18 12:42 - 00000000 ____D () C:\Users\User\AppData\Roaming\Activeris
2014-09-17 13:58 - 2014-09-17 13:58 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-09-17 13:58 - 2014-09-17 13:58 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch
2014-09-17 13:58 - 2014-09-17 13:58 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-09-17 12:56 - 2014-09-17 12:50 - 84431777 _____ () C:\Users\User\Downloads\Antonov An-225 Mriya by Discovery Channel.mp4
2014-09-17 09:03 - 2013-08-01 23:00 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-09-17 06:51 - 2014-09-19 22:31 - 01538880 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-09-17 06:51 - 2014-09-19 22:31 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-09-17 06:51 - 2014-09-19 22:31 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-09-17 04:13 - 2014-06-09 12:19 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-09-17 04:13 - 2013-10-30 10:08 - 02193560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-09-17 04:12 - 2014-06-09 12:19 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-09-17 04:12 - 2013-10-30 10:08 - 02799784 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-09-16 20:09 - 2014-09-16 20:09 - 03497898 _____ () C:\Users\User\Downloads\Worst Movie Death Scene Ever!.mp4
2014-09-16 18:04 - 2014-09-16 18:04 - 00001704 _____ () C:\Users\User\Downloads\YouLikeHits AllInOne Bots - RushingWind - CPAE.zip
2014-09-16 17:34 - 2014-09-16 17:34 - 00015983 _____ () C:\Users\User\Downloads\ylh (1).rar
2014-09-16 16:48 - 2014-09-16 16:48 - 00423980 _____ () C:\Users\User\Downloads\prd.wav
2014-09-16 16:33 - 2014-09-16 16:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-16 16:33 - 2013-08-01 20:02 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-09-16 16:33 - 2013-08-01 20:02 - 00000000 ____D () C:\ProgramData\Skype
2014-09-16 11:31 - 2014-09-15 23:13 - 00000099 _____ () C:\Windows\ylh-open.bat
2014-09-16 00:19 - 2014-09-15 23:43 - 00000000 ____D () C:\Program Files (x86)\YLH.bot
2014-09-15 23:46 - 2014-09-15 23:46 - 00015983 _____ () C:\Users\User\Downloads\ylh.rar
2014-09-15 23:43 - 2014-09-15 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YLH.bot
2014-09-15 23:18 - 2014-09-15 23:18 - 00000000 ____D () C:\Users\User\Documents\iMacros
2014-09-15 23:13 - 2014-09-15 22:50 - 00000002 _____ () C:\Windows\ylh-actions.txt
2014-09-15 22:47 - 2014-09-15 22:47 - 07723200 _____ () C:\Users\User\Downloads\You-like-hits-bot-free.zip
2014-09-15 11:14 - 2014-08-17 20:11 - 00000000 ____D () C:\Users\Pablo\AppData\Local\TSVNCache
2014-09-15 10:48 - 2013-12-07 12:00 - 00000000 ____D () C:\Users\Pablo\AppData\Local\LogMeIn Hamachi
2014-09-15 09:31 - 2013-09-23 19:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-15 09:06 - 2013-07-31 21:49 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-14 23:51 - 2014-09-14 23:51 - 00000000 ____D () C:\Users\User\Downloads\idle_master-master
2014-09-14 23:34 - 2014-09-14 23:34 - 02421892 _____ () C:\Users\User\Downloads\Funny Thai Commercial (Hatari) With Subtitles!!!.mp4
2014-09-14 14:29 - 2014-09-14 14:29 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-14 14:29 - 2013-11-24 22:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-14 13:02 - 2009-07-14 07:08 - 00032550 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-14 01:48 - 2014-09-19 22:34 - 00073872 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-09-14 01:48 - 2014-09-19 22:34 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 31887680 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 24552592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 20922512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 20589536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 19954520 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 18106152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 17259664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 16875856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 14026304 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 13939272 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 13157696 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-09-14 01:48 - 2014-09-19 22:31 - 11392576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 11330776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 04287296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 04008592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 03223120 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 02838424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 01876296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434411.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 01539272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434411.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00984424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00957584 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00925896 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00919240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00894096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00867528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00501064 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00417096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00393024 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00352016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00348304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00303600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00174856 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00156840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-09-14 01:48 - 2014-09-19 22:31 - 00026956 _____ () C:\Windows\system32\nvinfo.pb
2014-09-13 23:53 - 2014-09-19 22:34 - 06890696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-09-13 23:53 - 2014-09-19 22:34 - 03529872 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-09-13 23:53 - 2014-09-19 22:34 - 02557640 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-09-13 23:53 - 2014-09-19 22:34 - 00934216 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-09-13 23:53 - 2014-09-19 22:34 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-09-13 23:53 - 2014-09-19 22:34 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-09-13 22:13 - 2014-09-19 22:35 - 00613696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-09-13 19:45 - 2014-09-13 19:44 - 10672356 _____ () C:\Users\User\Downloads\The station - Feeling Filthy (full).mp4
2014-09-12 23:19 - 2014-09-12 21:21 - 00105024 _____ () C:\Users\User\Documents\lol.veg
2014-09-12 23:17 - 2014-09-12 23:03 - 82970512 _____ () C:\Users\User\Documents\lol.mp4
2014-09-12 23:11 - 2014-09-12 21:21 - 00105024 _____ () C:\Users\User\Documents\lol.veg.bak
2014-09-12 23:02 - 2014-09-12 23:02 - 00069955 _____ () C:\Users\User\Documents\prvy officialny test 1080 uhd.mp4
2014-09-12 22:59 - 2014-09-07 21:32 - 00000000 ____D () C:\Users\User\Documents\OFX Presets
2014-09-12 21:54 - 2014-09-12 21:42 - 00003232 _____ () C:\Users\User\Downloads\Air Horn Sound Effect.mp3.sfk
2014-09-12 21:05 - 2014-09-12 21:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\Sony Creative Software Inc
2014-09-12 20:44 - 2014-09-12 20:43 - 04470739 _____ () C:\Users\User\Downloads\Lens Flare Sun Green Screen ANIMATION FREE FOOTAGE HD.mp4
2014-09-12 20:38 - 2014-09-12 20:37 - 12958295 _____ () C:\Users\User\Downloads\[FREE SOURCE] Montage Parody Pack (Pt. 1).mp4
2014-09-12 20:37 - 2014-09-12 20:37 - 01736171 _____ () C:\Users\User\Downloads\we like to party rainbow frog.mp4
2014-09-12 15:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-11 22:00 - 2013-07-31 21:48 - 00770424 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 22:00 - 2009-07-14 07:13 - 00770424 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-11 21:59 - 2014-05-01 00:26 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-11 17:37 - 2014-09-19 22:34 - 03961833 _____ () C:\Windows\system32\nvcoproc.bin
2014-09-11 09:14 - 2014-09-17 13:58 - 00034368 _____ () C:\Windows\Launcher.exe
2014-09-10 22:14 - 2014-09-10 22:14 - 00067118 _____ () C:\Users\User\Downloads\long range sniper rifle.lxf
2014-09-10 00:11 - 2014-09-24 13:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-09 23:47 - 2014-09-24 13:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-09 14:47 - 2014-09-07 22:05 - 32336141 _____ () C:\Users\User\Documents\Untitled.mp4
2014-09-09 13:00 - 2013-10-05 00:36 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-09 13:00 - 2013-08-01 20:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-09 13:00 - 2013-08-01 20:08 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-07 22:21 - 2014-09-07 22:21 - 01456859 _____ () C:\Users\User\Downloads\Snoop Dogg -Drop It Like It's Hot- Dance Greenscreen HD Footage With -Smoke Weed Everyday- Sound.mp4
2014-09-07 21:26 - 2014-09-07 21:26 - 00000000 ____D () C:\Program Files\Sony
2014-09-07 21:26 - 2013-08-01 22:11 - 00000000 ____D () C:\ProgramData\Sony
2014-09-07 21:26 - 2013-08-01 22:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-09-07 21:15 - 2014-09-07 21:09 - 00002628 _____ () C:\Users\User\Documents\Register Vegas Pro12.htm
2014-09-07 21:12 - 2014-09-07 21:12 - 00000000 ____D () C:\Users\User\Downloads\Sony.Vegas.Pro.12.0.build.367.x64.Incl.keygen-P2P
2014-09-06 23:19 - 2014-09-06 23:19 - 02508988 _____ () C:\Users\User\Downloads\white screen intervention mw2.mp4
2014-09-06 21:01 - 2014-09-06 21:00 - 24386033 _____ () C:\Users\User\Downloads\Doller Rain on green screen - free green screen.mp4
2014-09-06 20:41 - 2014-09-06 20:41 - 00086406 _____ () C:\Users\User\Downloads\38ceaa2e17aadb8bb325ad0e4928bd6e.jpeg
2014-09-05 21:57 - 2014-09-05 21:57 - 00000000 ____D () C:\Users\User\AppData\Local\CrashRpt
2014-09-05 21:56 - 2013-08-15 23:42 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-09-05 21:53 - 2014-09-05 21:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BeamNG
2014-09-05 20:13 - 2014-09-05 20:13 - 03418325 _____ () C:\Users\User\Downloads\The Ukrainian Talents - Man gets hit with Bow and Arrow.mp4
2014-09-05 19:29 - 2014-09-05 19:28 - 06270219 _____ () C:\Users\User\Downloads\Ordinary Russian TV show - Fight.mp4
2014-09-05 14:12 - 2014-09-05 14:12 - 01360647 _____ () C:\Users\User\Downloads\Fuck her right in the pussy! (Green Screen).mp4
2014-09-05 14:08 - 2014-09-05 14:08 - 01896929 _____ () C:\Users\User\Downloads\MOM GET THE CAMERA!.mp4
2014-09-05 14:03 - 2014-09-05 14:03 - 00640336 _____ () C:\Users\User\Downloads\GTA5 -wasted- green screen effect + sound.mp4
2014-09-05 04:10 - 2014-09-11 16:49 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-05 04:05 - 2014-09-11 16:49 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-04 22:41 - 2014-09-04 22:40 - 09397714 _____ () C:\Users\User\Downloads\Big Explosion 001 - green screen effects.mp4
2014-09-04 22:40 - 2014-09-04 22:39 - 10073198 _____ () C:\Users\User\Downloads\Green Screen Machine Gun and Grenade HD - Footage PixelBoom.mp4
2014-09-04 22:38 - 2014-09-04 22:38 - 03093809 _____ () C:\Users\User\Downloads\M249 SAW - Shoot & Reload - GreenScreen Pro's HD.mp4
2014-09-04 22:35 - 2014-09-04 22:35 - 01230149 _____ () C:\Users\User\Downloads\Chroma Bullet Pass (Downloadable video).mp4
2014-09-04 22:21 - 2014-09-04 22:18 - 103952408 _____ () C:\Users\User\Downloads\A NEW DANK.mp4
2014-09-04 22:19 - 2014-09-04 22:18 - 15259567 _____ () C:\Users\User\Downloads\Doritos Kid Gets Quickscoped.mp4
2014-09-04 21:14 - 2014-09-19 21:52 - 00038048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-09-04 21:14 - 2014-09-19 21:52 - 00032416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-09-04 21:14 - 2013-08-29 13:13 - 00034976 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2014-09-02 14:52 - 2014-09-02 14:52 - 00000000 ____D () C:\Users\Pablo\Desktop\foto

Files to move or delete:
====================
C:\Windows\Tasks\{CB75B44C-E5EF-4879-B208-C57DFAE62709}.job


Some content of TEMP:
====================
C:\Users\Pablo\AppData\Local\Temp\avgnt.exe
C:\Users\User\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-18 10:04

==================== End Of Log ============================
Čo oko nevidí to srdce nebolí.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#4 Příspěvek od xSorbi »

A tu je ďalší ten druhý :/


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-09-2014 01
Ran by User at 2014-09-25 17:01:37
Running from C:\Users\User\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.32126 - BitTorrent Inc.)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
Adobe After Effects CS6 (HKLM-x32\...\{4817D846-700B-474E-A31B-80892B3E92E3}) (Version: 11 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.08) - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc)
Aktualizácie NVIDIA 16.13.42 (Version: 16.13.42 - NVIDIA Corporation) Hidden
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.2.0 - Asmedia Technology)
ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.2.8.1 - ASUSTek COMPUTER INC.)
ASUS GPU Tweak (x32 Version: 2.2.8.1 - ASUSTek COMPUTER INC.) Hidden
Avira (HKLM-x32\...\{70e83cd8-4bd5-4039-ab5a-6b94a8abb641}) (Version: 1.1.21.25162 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.21.25162 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira)
Bad Piggies (HKLM-x32\...\{9B81F450-3C3F-490C-8FA7-239F7960E62D}) (Version: 1.5.0 - Rovio Entertainment Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.5.1 - EA Digital Illusions CE AB)
BitTorrent Sync (HKLM-x32\...\BitTorrent Sync) (Version: 1.3.106 - )
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.8.10.3096 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{0BED0B96-70B8-4893-884B-DC485DC8C1B7}) (Version: 0.8.10.3096 - BlueStack Systems, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.04 - Piriform)
Counter-Strike 1.6 (HKLM-x32\...\{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}) (Version: 1.6 - )
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
CPUID CPU-Z 1.67 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0335 - Disc Soft Ltd)
Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
Dynamic-Photo HDR 5 (HKLM-x32\...\Dynamic-Photo HDR 5_is1) (Version: - Mediachance)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.00 - Ubisoft)
FL Studio 11 (HKLM-x32\...\FL Studio 11) (Version: - Image-Line)
FlowStone FL 3.0 (HKLM-x32\...\FlowStone) (Version: - )
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Gaming Keyboard Driver (HKLM-x32\...\{B3CDED64-7DC2-429D-A325-BBC3CF793AA6}) (Version: 1.0 - Senbiz)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Garry)
GCFScape 1.8.5 (HKLM\...\GCFScape_is1) (Version: - Ryan Gregg)
Goat Simulator (HKLM-x32\...\R29hdFNpbXVsYXRvcg==_is1) (Version: 1 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.120 - Spoločnosť Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto Vice City (HKCU\...\{4B35F00C-E63D-40DC-9839-DF15A33EAC46}) (Version: 1.00.000 - )
GRID (HKLM-x32\...\{5A0B7BA5-4682-4273-81C2-69B17E649103}) (Version: 1.30.0000 - Codemasters)
GTA San Andreas (HKLM-x32\...\{E0303B6A-C675-4102-95DA-C013625BFA99}) (Version: 1.00.00001 - Rockstar Games)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
HomeTab 6.8 (HKLM-x32\...\{adbab591-ef01-43b6-84e0-2173c58c3a52}_is1) (Version: 6.8 - One Floor App) <==== ATTENTION
Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version: - Cheat Engine)
iMacros for Chrome File Access 1.0.0.805 (HKCU\...\{97ABEAC7-C6E1-46F1-957B-F395EA4662B5}_is1) (Version: 1.0.0.805 - Ipswitch, Inc)
Intel(R) Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
LEGO Digital Designer (HKLM-x32\...\New LEGO Digital Designer) (Version: - LEGO A/S)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.236 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.236 - LogMeIn, Inc.) Hidden
LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.7.4 - www.leaguereplays.com)
Mafia II (HKLM-x32\...\Mafia II_is1) (Version: - )
Malwarebytes Anti-Malware verzia 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Max Payne 3 (HKLM-x32\...\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}) (Version: 1.0.0.0 - Rockstar Games)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Corporation (x32 Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{6965A8D2-465D-4F98-9FAA-0E9E2348F329}) (Version: 3.22.270.0 - Microsoft Corporation)
Microsoft Office Access MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2010 (x32 Version: 14.0.4763.1012 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Hungarian) 2010 (x32 Version: 14.0.4763.1012 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Slovak) 2010 (Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Slovak) 2010 (x32 Version: 14.0.4763.1017 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{901B8EBE-9919-4EED-96E9-F318EDA09BF6}) (Version: - )
Minecraft 1.6.2 (HKLM-x32\...\Minecraft 1.6.2) (Version: - )
Mozilla Firefox 31.0 (x86 sk) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 sk)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
MPC-HC 1.7.0.7691 (8d311b0) Beta (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.0.7691 - MPC-HC Team)
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
Need for Speed Most Wanted (HKLM-x32\...\Need for Speed Most Wanted_is1) (Version: - )
NVIDIA 3D Vision radič ovládača 344.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.11 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.2 - NVIDIA Corporation)
NVIDIA GeForce Experience Service (Version: 16.13.42 - NVIDIA Corporation) Hidden
NVIDIA Grafický ovládač 344.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.11 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.162.1274 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 2.0 - NVIDIA Corporation) Hidden
NVIDIA Ovládač 3D Vision 344.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.11 - NVIDIA Corporation)
NVIDIA Ovládač zvuku HD 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX (x32 Version: 9.14.0702 - NVIDIA Corporation) Hidden
NVIDIA ShadowPlay 16.13.42 (Version: 16.13.42 - NVIDIA Corporation) Hidden
NVIDIA Softvér systému s podporou technológie PhysX 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 16.13.42 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.25 (Version: 1.2.25 - NVIDIA Corporation) Hidden
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Opera Stable 18.0.1284.68 (HKLM-x32\...\Opera 18.0.1284.68) (Version: 18.0.1284.68 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 344.11 (Version: 344.11 - NVIDIA Corporation) Hidden
paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
PileFile reminder (HKCU\...\{56837588-F559-40CF-91D9-D439D405FB28}) (Version: - Escolade Solutions LTD) <==== ATTENTION
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QuickTime (HKLM-x32\...\{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}) (Version: 7.60.92.0 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.61.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.)
Rigs of Rods 0.38.67 (HKLM-x32\...\Rigs of Rods 0.38.67) (Version: 0.38.67 - Rigs of Rods Team)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
Roller Coaster Tycoon 3 Platinum - CarlesNeo ! (HKLM-x32\...\Roller Coaster Tycoon 3 Platinum - CarlesNeo !) (Version: - )
SHIELD Streaming (Version: 3.1.200 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.42 - NVIDIA Corporation) Hidden
Sibelius Scorch (Firefox, Opera, Netscape, Chrome only) (HKLM-x32\...\{41626CC0-A854-4402-AD06-D7939515C282}) (Version: 6.2.0 - Sibelius Software, a division of Avid Technology, Inc.)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Sniper Elite 3 (HKLM-x32\...\U25pcGVyRWxpdGUz_is1) (Version: 1 - )
Sony PC Companion 2.10.197 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.197 - Sony)
Source Filmmaker (HKLM-x32\...\Steam App 1840) (Version: - Valve)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Surgeon Simulator 2013 Steam Edition 1.0 (HKLM-x32\...\Surgeon Simulator 2013 Steam Edition 1.0) (Version: 1.0 - Cat-A-Cat)
System Requirements Lab Detection (HKLM-x32\...\{A407FC22-36BF-4C82-A516-59D94BC505A9}) (Version: 1.0.5.0 - Husdawg, LLC)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
Terraria v1.2.0.2 cracked-KEBAB (HKLM-x32\...\{A1264D7F-CEF6-4033-8F9D-3E27392E3627}) (Version: 1.2.0.2 - KEBAB)
Test Drive Unlimited (HKLM-x32\...\{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}) (Version: 0.10.0000 - Atari)
TortoiseSVN 1.8.7.25475 (64 bit) (HKLM\...\{A8573F59-C080-4495-A9A8-EC32D8A4ECFF}) (Version: 1.8.25475 - TortoiseSVN)
TrackMania Nations Forever (HKLM-x32\...\Steam App 11020) (Version: - Nadeo)
Unturned (HKLM-x32\...\Steam App 304930) (Version: - Nelson Sexton)
Uplay (HKLM-x32\...\Uplay) (Version: 4.7 - Ubisoft)
USB PnP Sound Device (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392006300}) (Version: - )
Vegas Pro 12.0 (64-bit) (HKLM\...\{A7500970-FE98-11E1-B560-F04DA23A5C58}) (Version: 12.0.367 - Sony)
Vegas Pro 9.0 (HKLM-x32\...\{DC785DB7-D389-48C3-B146-96FE99BF4E2B}) (Version: 9.0.563 - Sony)
VTFEdit 1.2.5 (HKLM-x32\...\VTFEdit_is1) (Version: - Neil Jedrzejewski & Ryan Gregg)
Warcraft III (HKLM-x32\...\Warcraft III) (Version: - )
Warcraft III: All Products (HKCU\...\Warcraft III) (Version: - )
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
YLH.bot 1.35 (HKLM-x32\...\{8B8BFF36-8E3A-4D2A-B16E-AA20AAFE2BA3}_is1) (Version: - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

19-09-2014 10:28:22 Windows Update
19-09-2014 19:53:02 Installed DirectX
20-09-2014 08:00:46 Installed Java 7 Update 67
23-09-2014 11:46:15 paint.net 4.0.3
23-09-2014 15:10:24 Windows Update
24-09-2014 21:05:03 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {04B496C0-2C45-4CE7-9390-0993B2895E7E} - System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4 => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-4.exe <==== ATTENTION
Task: {1A3232A6-CEC4-4F0F-896B-FA3D059C0B26} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: {2FE80006-ACD3-4776-BA36-BBB10BE76788} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: {316D2354-CA4A-460C-971A-938C906DC1E2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated)
Task: {57F2242B-ECA5-400D-8505-D1585B1D526F} - System32\Tasks\RunAsStdUser Task => C:\Users\User\AppData\Local\Oxy\Application\oxy.exe <==== ATTENTION
Task: {61A84F71-386D-4A00-A9C0-817FE355B251} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17] (Google Inc.)
Task: {7100E69E-2665-437D-81B5-59518924D162} - System32\Tasks\PileFile reminder => C:\Users\User\AppData\Local\Temp\Riot Points GeneratorDownload_5427\Riot_Points_Generator_Downloader.exe <==== ATTENTION
Task: {86644365-B5D5-45CE-B717-4894E785E4C2} - System32\Tasks\BaronReplays => D:\Nuda\BaronReplays\BaronReplays.exe
Task: {87E21C42-0ECD-48A5-A8F5-A1E7CB201392} - System32\Tasks\PileFile logon => C:\Users\User\AppData\Local\Temp\Riot Points GeneratorDownload_5427\Riot_Points_Generator_Downloader.exe <==== ATTENTION
Task: {926A03A9-0207-4844-A2F4-5BE0A1B43098} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files (x86)\HomeTab\WSystemProtect.exe <==== ATTENTION
Task: {AFC22590-EF6A-4E09-970D-B1870A4E3588} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17] (Google Inc.)
Task: {BDF53528-4DC2-4E72-A28D-86DAFC54BE23} - System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11 => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-11.exe <==== ATTENTION
Task: {DD8A3276-60AE-4825-8086-2B0A59825B26} - System32\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7 => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-7.exe <==== ATTENTION
Task: {E265F387-CD2D-41D2-9024-FA81DC28519B} - \7abad424-0b2a-452a-a110-32d11125f0b4-6 No Task File <==== ATTENTION
Task: {F620E616-727C-4742-B847-3488C679149F} - System32\Tasks\Browser Updater\Browser Updater => C:\Program Files (x86)\HomeTab\WPackageUpgrade.exe <==== ATTENTION
Task: {FD76AE86-0F68-4612-8B6F-F98F243822FB} - System32\Tasks\SystemSockets\SystemSockets => C:\Program Files (x86)\HomeTab\WBrokerDirect.exe <==== ATTENTION
Task: C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11.job => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4.job => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-6.job => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7.job => C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SidebarExecute.job => C:\Program Files\Windows Sidebar\sidebar.exe
Task: C:\Windows\Tasks\{CB75B44C-E5EF-4879-B208-C57DFAE62709}.job => c:\program files (x86)\mozilla firefox\firefox.exe

==================== Loaded Modules (whitelisted) =============

2014-09-19 22:34 - 2014-09-13 23:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-01-17 11:24 - 2012-01-17 11:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe
2013-08-01 21:03 - 2014-06-28 13:46 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-06 20:37 - 2014-05-06 20:37 - 00076032 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
2014-05-06 20:37 - 2014-05-06 20:37 - 00088832 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll
2010-01-30 02:40 - 2010-01-30 02:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2013-08-02 08:47 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe
2013-12-24 20:43 - 2013-04-09 13:13 - 00270336 _____ () C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
2013-12-24 20:43 - 2013-01-09 12:47 - 00151552 _____ () C:\Program Files (x86)\Gaming Keyboard\OSD.exe
2013-08-02 08:47 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll
2014-05-05 22:21 - 2014-05-05 22:21 - 00065792 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll
2014-05-05 22:20 - 2014-05-05 22:20 - 00071936 _____ () C:\Program Files\TortoiseSVN\bin\libsasl32.dll
2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-08-27 15:00 - 2014-08-27 15:00 - 00139056 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-08-27 15:00 - 2014-08-27 15:00 - 00066864 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-08-12 17:51 - 2014-08-27 15:00 - 00052472 _____ () C:\Users\User\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2013-12-24 20:43 - 2012-11-05 09:09 - 00057344 _____ () C:\Program Files (x86)\Gaming Keyboard\lan.dll
2013-12-24 20:43 - 2012-11-05 09:37 - 00061440 _____ () C:\Program Files (x86)\Gaming Keyboard\hiddriver.dll
2014-09-11 17:30 - 2014-09-04 05:01 - 01098056 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\libglesv2.dll
2014-09-11 17:30 - 2014-09-04 05:01 - 00174408 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\libegl.dll
2014-09-11 17:30 - 2014-09-04 05:01 - 08577864 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll
2014-09-11 17:30 - 2014-09-04 05:01 - 00331592 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll
2014-09-11 17:30 - 2014-09-04 05:01 - 01660232 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:41ADDB8A

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: BstHdAndroidSvc => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: BstHdUpdaterSvc => 2
MSCONFIG\Services: c2cautoupdatesvc => 2
MSCONFIG\Services: c2cpnrsvc => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: OpenVPNService => 3
MSCONFIG\Services: PDF Architect 2 => 3
MSCONFIG\Services: pdfforge CrashHandler => 3
MSCONFIG\Services: Sony PC Companion => 3
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: TurboBoost => 3
MSCONFIG\Services: WMPNetworkSvc => 2
MSCONFIG\startupfolder: C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Oxy.lnk => C:\Windows\pss\Oxy.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Easy-Hide-IP => C:\Program Files\Easy-Hide-IP\easy-hide-ip.exe
MSCONFIG\startupreg: HideMyIP => C:\Program Files (x86)\Hide My IP\HideMyIP.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: VPN Direct => C:\Program Files (x86)\VPN Direct\bin\VPNStarter.exe
MSCONFIG\startupreg: Web_Page_Refresh => "C:\System tools package\One million clicks\Web_Page_Refresh.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2883089224-953471072-2576935892-500 -> Administrator - Disabled - Status: Degraded)
Guest (S-1-5-21-2883089224-953471072-2576935892-501 -> Limited - Disabled - Status: Degraded)
HomeGroupUser$ (S-1-5-21-2883089224-953471072-2576935892-1002 -> Limited - Enabled - Status: OK)
Pablo (S-1-5-21-2883089224-953471072-2576935892-1004 -> Administrator - Enabled - Status: OK) => C:\Users\Pablo
User (S-1-5-21-2883089224-953471072-2576935892-1000 -> Administrator - Enabled - Status: OK) => C:\Users\User

==================== Faulty Device Manager Devices =============

Name: Universal Serial Bus (USB) Controller
Description: Universal Serial Bus (USB) Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
Element sa nepodarilo nájsť. (HRESULT : 0x80070490) (0x80070490)

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.JetPropStore> cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Služba Windows Search nemôže načítať informácie ukladacieho priestoru vlastností.

Context: Windows Application, SystemIndex Catalog


Details:
Databáza indexu obsahu je poškodená. (HRESULT : 0xc0041800) (0xc0041800)

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search sa zastavuje, pretože sa vyskytol problém s indexovaním, The catalog is corrupt.


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhľadávacia služba zistila v indexe {id=4700} súbory s poškodenými údajmi. Služba sa pokúsi o automatické opravenie tohto problému opätovným vytvorením indexu.


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: Služba Windows Search nemôže otvoriť ukladací priestor vlastností Jet.


Details:
0x%08x (0xc0041800 - Databáza indexu obsahu je poškodená. (HRESULT : 0xc0041800))

Error: (09/25/2014 04:55:44 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (2600) Windows: Error -1811 occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008F3.log.


System errors:
=============
Error: (09/25/2014 04:58:03 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (09/25/2014 04:55:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 30000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.

Error: (09/25/2014 04:55:56 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 25.72.70.8192.168.137.0255.255.255.0

Error: (09/25/2014 04:55:48 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Služba Windows Search bola ukončená s chybou služby %%-1073473535.

Error: (09/25/2014 04:55:40 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba LogMeIn Hamachi Tunneling Engine sa pri spustení zablokovala.

Error: (09/25/2014 04:55:19 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (09/24/2014 10:32:30 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (09/24/2014 10:20:23 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (09/24/2014 09:42:41 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (09/24/2014 09:30:34 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:


Microsoft Office Sessions:
=========================
Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description:
Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Context: Windows Application


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Context: Windows Application, SystemIndex Catalog


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/25/2014 04:55:48 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Context: Windows Application, SystemIndex Catalog


Details:
Element sa nepodarilo nájsť. (HRESULT : 0x80070490) (0x80070490)
Search.TripoliIndexer

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Context: Windows Application, SystemIndex Catalog


Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)
Search.JetPropStore

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Context: Windows Application, SystemIndex Catalog


Details:
Databáza indexu obsahu je poškodená. (HRESULT : 0xc0041800) (0xc0041800)

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description:
Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)
The catalog is corrupt

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description:
Details:
Metaúdaje indexu obsahu sa nedajú prečítať. (HRESULT : 0xc0041801) (0xc0041801)
4700

Error: (09/25/2014 04:55:44 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description:
Details:
0x%08x (0xc0041800 - Databáza indexu obsahu je poškodená. (HRESULT : 0xc0041800))

Error: (09/25/2014 04:55:44 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows2600Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008F3.log-1811


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3570K CPU @ 4.00GHz
Percentage of memory in use: 36%
Total physical RAM: 8138.14 MB
Available physical RAM: 5142.82 MB
Total Pagefile: 16274.45 MB
Available Pagefile: 12895.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.18 GB) (Free:354.14 GB) NTFS
Drive d: (Nový zväzok) (Fixed) (Total:1374.73 GB) (Free:624.75 GB) NTFS
Drive e: () (CDROM) (Total:0.14 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 973776DD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=488.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1374.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Čo oko nevidí to srdce nebolí.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#5 Příspěvek od vyosek »

:arrow: Kraaaasna sbirka :arcisit:

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#6 Příspěvek od xSorbi »

Mám sa čím vychvaľovať (myslím tou zbierkou :lol: ) Ale rovno teraz mi není do smiechu :/ Idem ešte ten AdwCleaner čeknúť
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.0 (09.22.2014:1)
OS: Windows 7 Ultimate x64
Ran by User on çt 25. 09. 2014 at 18:20:53,80
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a19638fe-8536-4bcf-b659-a38ad619be61}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{a19638fe-8536-4bcf-b659-a38ad619be61}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\simplytech"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Successfully deleted the following from C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\mrds6njz.default\prefs.js

user_pref("browser.search.selectedEngine", "Conduit Search");
Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\mrds6njz.default\minidumps [6 files]



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\coljhboelhlkbgaaolcngflenaggpeao
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\kmedakdfngfmagjlndeckcbfcmidlbio



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on çt 25. 09. 2014 at 18:23:11,82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Čo oko nevidí to srdce nebolí.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#7 Příspěvek od xSorbi »

:arrow: Ku*** ! Dal som MBAM, že či to už je vyriešené ale zapol sa "Heuristic Scan" (Konečne) a tá sviňa našla 199 THREATOV ! Tu je log z ADWCleaner :cry: #

AdwCleaner v3.310 - Report created 25/09/2014 at 18:27:09
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : User - USER-PC
# Running from : C:\Users\User\Desktop\adwcleaner_3.310.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\WinterSoft
Folder Deleted : C:\Users\User\AppData\Local\emaze
Folder Deleted : C:\Users\User\AppData\Local\globalUpdate
Folder Deleted : C:\Users\User\AppData\Roaming\Activeris

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : PileFile logon
Task Deleted : PileFile reminder
Task Deleted : 7abad424-0b2a-452a-a110-32d11125f0b4-11
Task Deleted : 7abad424-0b2a-452a-a110-32d11125f0b4-4
Task Deleted : 7abad424-0b2a-452a-a110-32d11125f0b4-6
Task Deleted : 7abad424-0b2a-452a-a110-32d11125f0b4-7

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\coljhboelhlkbgaaolcngflenaggpeao
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\kmedakdfngfmagjlndeckcbfcmidlbio
Key Deleted : HKLM\SOFTWARE\Classes\AppID\HomeTab.DLL
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKCU\Software\Escolade
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\HomeTab
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\simplytech
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\simplytech
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\SavePass 1.1
Key Deleted : HKLM\SOFTWARE\VBMZ
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280


-\\ Mozilla Firefox v31.0 (x86 sk)

[ File : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\prefs.js ]


-\\ Google Chrome v37.0.2062.124

[ File : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1895 octets] - [27/08/2013 14:09:36]
AdwCleaner[R1].txt - [9939 octets] - [25/09/2014 18:26:15]
AdwCleaner[S0].txt - [1872 octets] - [27/08/2013 14:09:56]
AdwCleaner[S1].txt - [9687 octets] - [25/09/2014 18:27:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [9747 octets] ##########
Čo oko nevidí to srdce nebolí.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#8 Příspěvek od xSorbi »

:arrow: A ešte jedna vec, keď našlo tých 199 threatov tak sa to zasa zaseklo :/
Sakra neviete čo s tým, mám už fakt na to nervy no ale ešte sa ovládam. Si ani v kľude nemôžem pozreť FB ani nič, zasa mi ukazuje ADBlock že mi bloklo reklamy aj na tejto stránke :/
Čo oko nevidí to srdce nebolí.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#9 Příspěvek od xSorbi »

:arrow: :arrow: :arrow: :arrow: Ach, zasa som použil tu moju metódu ničenia vírusov, a zasa som to tak spravil ako pred tým. Našlo zatiaľ iba 11 threatov ufffffff, ALE zasa sa zastavilo na "Heuristic Scan" keď sa to rozbehlo :(
Čo oko nevidí to srdce nebolí.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#10 Příspěvek od vyosek »

:arrow: Jeste taky s lecenim nekoncime, nespoustejte si testy a kroky dle sebe a jak se vam zachce

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#11 Příspěvek od xSorbi »

Zoek.exe v5.0.0.0 Updated 24-09-2014
Tool run by User on çt 25. 09. 2014 at 22:53:27,44.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\User\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391106} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004\Software\Microsoft\Internet Explorer\Approved Extensions\{61a83e16-7198-49c6-8874-3e4e8faeb4f3} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Approved Extensions\{61a83e16-7198-49c6-8874-3e4e8faeb4f3} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Approved Extensions\{61a83e16-7198-49c6-8874-3e4e8faeb4f3} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Approved Extensions\{61a83e16-7198-49c6-8874-3e4e8faeb4f3} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Internet Explorer\Approved Extensions\{61a83e16-7198-49c6-8874-3e4e8faeb4f3} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311391106} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150} deleted successfully
HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:home");
user_pref("browser.search.useDBForOrder", "false");

Added to C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default

user.js not found
---- Lines searches removed from prefs.js ----
user_pref("HomeTab_8131.global.DisplayRecentSearches", "true");
---- FireFox user.js and prefs.js backups ----

prefs_201425.09._2300_.backup

==== Deleting Files \ Folders ======================

C:\Users\User\.android deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\User\AppData\Local\CrashRpt deleted
C:\Users\User\AppData\LocalLow\SimplyTech deleted
C:\windows\SysNative\tasks\RunAsStdUser Task deleted
C:\Windows\Launcher.exe deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\Syswow64\tmpCA9F.tmp deleted
C:\Windows\Syswow64\tmpCAA0.tmp deleted
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\extensions\{95fa82a2-5246-43e0-bcee-3801c239c192} deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default
- iMacros for Firefox - %ProfilePath%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default
DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
cpoooaodibfldhiobnmnjliddplmekeb - C:\Users\User\AppData\Local\CRE\cpoooaodibfldhiobnmnjliddplmekeb.crx[]
flliilndjeohchalpbbcdekjklbdgfkk - No path found[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14. 07. 2014 18:22]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
cpoooaodibfldhiobnmnjliddplmekeb - C:\Users\User\AppData\Local\CRE\cpoooaodibfldhiobnmnjliddplmekeb.crx[]

Skype Click to Call - Pablo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Auto Refresh Plus - Pablo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilipfekkmncanaajkapbpancpelijih
Easy Auto Refresh - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc
Auto Replay for YouTube™ - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb
Skype Click to Call - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
ClipConverter - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\njjjgjlocdhecpgdcfjblcnfebfnmhpp
Speed Dial for Gmail - User\AppData\Roaming\Opera Software\Opera Stable\Extensions\bpnilbmleimgkpdemlobfaaghhohpfco
SavePass 1.1 - User\AppData\Roaming\Opera Software\Opera Stable\Extensions\ilhhefepljbmehhbmjcflhcchkddfaon
SavePass - User\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhamjeenndcnlegpcihoonbhpjcehglk

==== Chromium Fix ======================

C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\bpnilbmleimgkpdemlobfaaghhohpfco deleted successfully
C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhamjeenndcnlegpcihoonbhpjcehglk deleted successfully
C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\ilhhefepljbmehhbmjcflhcchkddfaon deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Pablo\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Pablo\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{522CE8F8-3EB0-72F1-4930-C9497BD38358} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cpoooaodibfldhiobnmnjliddplmekeb deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\cpoooaodibfldhiobnmnjliddplmekeb deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{adbab591-ef01-43b6-84e0-2173c58c3a52}_is1 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-Hide-IP deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HideMyIP deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VPN Direct deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Web_Page_Refresh deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Pablo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\User\AppData\Local\Mozilla\Firefox\Profiles\mrds6njz.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\User\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Pablo\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=217 folders=56 26230066 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Pablo\AppData\Local\Temp emptied successfully
C:\Users\User\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Reset Hosts File ======================

Hosts File Reset Successfully

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\User\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

==== EOF on çt 25. 09. 2014 at 23:08:38,16 ======================
Čo oko nevidí to srdce nebolí.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#12 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#13 Příspěvek od xSorbi »

Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/25/2014 11:13:47 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Windows\SysWOW64\ASGT.exe (PID: 2044) [WD-HEUR]

1 proccess terminated!

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* Security Center (wscsvc) is not Running.
Startup Type set to: Manual

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 09/25/2014 11:14:48 PM
Execution time: 0 hours(s), 1 minute(s), and 0 seconds(s)
Čo oko nevidí to srdce nebolí.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#14 Příspěvek od vyosek »

Fajn, prozente to ComboFixem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

xSorbi
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2014 21:25

Re: Spomalený PC MBAM sa zastavuje na "HEURISTIC SCAN" !!!

#15 Příspěvek od xSorbi »

ComboFix 14-09-24.01 - User . 09. 2014 23:22:12.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.8138.5714 [GMT 2:00]
Running from: c:\users\User\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\User\AppData\Local\assembly\tmp
c:\users\User\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
.
.
((((((((((((((((((((((((( Files Created from 2014-08-25 to 2014-09-25 )))))))))))))))))))))))))))))))
.
.
2014-09-25 21:25 . 2014-09-25 21:25 -------- d-----w- c:\users\Pablo\AppData\Local\temp
2014-09-25 21:25 . 2014-09-25 21:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-25 21:02 . 2014-09-25 21:29 -------- d-----w- c:\users\User\AppData\Local\Temp
2014-09-25 21:02 . 2014-09-25 20:53 24064 ----a-w- c:\windows\zoek-delete.exe
2014-09-25 20:53 . 2014-09-25 21:25 -------- d-----w- c:\windows\system32\drivers\etc
2014-09-25 20:51 . 2014-09-25 21:01 -------- d-----w- C:\zoek_backup
2014-09-25 20:35 . 2014-09-25 20:35 12872 ----a-w- c:\windows\system32\bootdelete.exe
2014-09-25 20:13 . 2014-09-25 20:35 -------- d-----w- c:\programdata\HitmanPro
2014-09-25 16:26 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-09-25 15:00 . 2014-09-25 15:01 -------- d-----w- C:\FRST
2014-09-24 11:53 . 2014-09-09 22:11 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-24 11:53 . 2014-09-09 21:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-09-23 15:10 . 2014-09-09 02:05 11578928 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{03FD7595-0C91-49AD-A637-881B59136A58}\mpengine.dll
2014-09-23 11:01 . 2014-09-23 11:01 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-09-20 10:01 . 2014-09-25 21:28 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-20 10:00 . 2014-09-20 10:01 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-09-20 10:00 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-09-20 10:00 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-20 10:00 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-09-20 08:02 . 2014-09-20 08:02 -------- d-----w- c:\users\User\AppData\Roaming\Oracle
2014-09-20 08:02 . 2014-09-20 08:02 -------- d-----w- c:\windows\Sun
2014-09-20 08:02 . 2014-09-20 08:02 -------- d-----w- c:\programdata\Oracle
2014-09-20 08:01 . 2014-09-20 08:01 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-09-20 08:01 . 2014-09-20 08:01 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-09-20 08:01 . 2014-09-20 08:01 -------- d-----w- c:\program files (x86)\Java
2014-09-19 20:35 . 2014-09-19 20:35 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2014-09-19 20:35 . 2014-09-13 20:13 613696 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-09-19 20:34 . 2014-09-25 21:26 -------- d-----w- c:\programdata\NVIDIA
2014-09-19 20:34 . 2014-09-13 21:53 3529872 ----a-w- c:\windows\system32\nvsvc64.dll
2014-09-19 20:34 . 2014-09-13 21:53 934216 ----a-w- c:\windows\system32\nvvsvc.exe
2014-09-19 20:34 . 2014-09-13 21:53 62608 ----a-w- c:\windows\system32\nvshext.dll
2014-09-19 20:34 . 2014-09-13 21:53 2557640 ----a-w- c:\windows\system32\nvsvcr.dll
2014-09-19 20:34 . 2014-09-11 15:37 3961833 ----a-w- c:\windows\system32\nvcoproc.bin
2014-09-19 20:34 . 2014-09-13 21:53 6890696 ----a-w- c:\windows\system32\nvcpl.dll
2014-09-19 20:34 . 2014-09-13 21:53 385168 ----a-w- c:\windows\system32\nvmctray.dll
2014-09-19 20:34 . 2014-09-13 23:48 73872 ----a-w- c:\windows\system32\OpenCL.dll
2014-09-19 20:34 . 2014-09-13 23:48 60560 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-09-19 19:52 . 2014-09-04 19:14 38048 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-09-19 19:52 . 2014-09-04 19:14 32416 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-09-18 13:16 . 2014-09-18 13:16 -------- d-----w- c:\users\User\AppData\Roaming\TeamViewer
2014-09-18 13:16 . 2014-09-18 13:16 -------- d-----w- c:\program files (x86)\TeamViewer
2014-09-16 15:34 . 2014-09-22 17:16 -------- d-----w- C:\xampp
2014-09-16 14:33 . 2014-09-16 14:33 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-09-15 21:43 . 2014-09-15 22:19 -------- d-----w- c:\program files (x86)\YLH.bot
2014-09-15 21:43 . 2010-02-16 07:21 1744896 ----a-w- c:\windows\SysWow64\ChilkatHttp.dll
2014-09-15 21:43 . 2004-03-09 13:45 152848 ----a-w- c:\windows\SysWow64\comdlg32.ocx
2014-09-15 21:43 . 2004-03-08 22:00 124688 ----a-w- c:\windows\SysWow64\MSWINSCK.OCX
2014-09-15 21:13 . 2014-09-16 09:31 99 ----a-w- c:\windows\ylh-open.bat
2014-09-14 12:29 . 2014-07-17 05:42 46704 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2014-09-14 12:29 . 2014-07-17 05:42 822384 ----a-w- c:\program files (x86)\Mozilla Firefox\icuuc52.dll
2014-09-14 12:29 . 2014-07-17 05:42 1022576 ----a-w- c:\program files (x86)\Mozilla Firefox\icuin52.dll
2014-09-14 12:29 . 2014-07-17 05:42 10594416 ----a-w- c:\program files (x86)\Mozilla Firefox\icudt52.dll
2014-09-12 19:05 . 2014-09-12 19:05 -------- d-----w- c:\users\User\AppData\Roaming\Sony Creative Software Inc
2014-09-11 19:59 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2014-09-11 19:59 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2014-09-11 14:49 . 2014-08-01 11:53 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-09-11 14:49 . 2014-08-01 11:35 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-09-11 14:49 . 2014-06-24 03:29 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-09-11 14:49 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-09-11 14:49 . 2014-07-07 02:06 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-09-11 14:49 . 2014-07-07 02:06 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-09-11 14:49 . 2014-07-07 01:40 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-09-11 14:49 . 2014-07-07 01:40 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-09-11 14:49 . 2014-07-07 01:39 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-09-11 14:49 . 2014-09-05 02:10 578048 ----a-w- c:\windows\system32\aepdu.dll
2014-09-11 14:49 . 2014-09-05 02:05 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-09-07 19:26 . 2014-09-07 19:26 -------- d-----w- c:\program files\Sony
2014-08-29 13:31 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-29 13:31 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-08-29 13:31 . 2014-08-23 00:59 3163648 ----a-w- c:\windows\system32\win32k.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-24 12:34 . 2014-06-04 16:25 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-24 12:34 . 2014-06-04 16:25 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-09-17 02:13 . 2014-06-09 10:19 1291280 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2014-09-17 02:13 . 2013-10-30 08:08 2193560 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-09-17 02:12 . 2013-10-30 08:08 2799784 ----a-w- c:\windows\system32\nvspcap64.dll
2014-09-17 02:12 . 2014-06-09 10:19 1715224 ----a-w- c:\windows\system32\nvspbridge64.dll
2014-09-15 07:06 . 2013-07-31 19:49 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-09-04 19:14 . 2013-08-29 11:13 34976 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-08-23 13:26 . 2014-08-23 13:24 2829 ----a-w- c:\windows\War3Unin.pif
2014-08-23 13:26 . 2014-08-23 13:24 139264 ----a-w- c:\windows\War3Unin.exe
2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll
2014-07-24 21:47 . 2014-07-24 21:47 869544 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2014-07-24 18:25 . 2013-08-02 00:14 42040 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2014-07-22 13:14 . 2014-07-22 13:14 137376 ----a-w- c:\windows\system32\vcomp120.dll
2014-07-20 12:07 . 2013-08-02 07:20 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-07-20 12:07 . 2013-08-01 19:03 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-07-16 07:26 . 2013-08-01 19:03 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-07-14 02:02 . 2014-08-13 19:30 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-07-14 01:40 . 2014-08-13 19:30 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-07-09 02:03 . 2014-08-13 19:32 7168 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-07-09 02:03 . 2014-08-13 19:32 7168 ----a-w- c:\windows\system32\KBDTAT.DLL
2014-07-09 02:03 . 2014-08-13 19:32 7168 ----a-w- c:\windows\system32\KBDRU1.DLL
2014-07-09 02:03 . 2014-08-13 19:32 6656 ----a-w- c:\windows\system32\KBDRU.DLL
2014-07-09 02:03 . 2014-08-13 19:32 7168 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-07-09 01:31 . 2014-08-13 19:32 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL
2014-07-09 01:31 . 2014-08-13 19:32 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL
2014-06-30 22:24 . 2014-08-13 22:02 8856 ----a-w- c:\windows\system32\icardres.dll
2014-06-30 22:14 . 2014-08-13 22:02 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-06-28 11:46 . 2013-08-01 19:03 76152 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\User\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Steam"="d:\games\Steam\steam.exe" [2014-09-23 1938112]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-08-12 751184]
"VICTORY Gaming Keyboard"="c:\program files (x86)\Gaming Keyboard\Monitor.exe" [2013-04-09 270336]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2009-01-05 413696]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-08-27 164656]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-09-04 3802448]
.
c:\users\Pablo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Intel(R) Turbo Boost Technology Monitor 2.6.lnk - c:\program files\Intel\TurboBoost\SignalIslandUi.exe [2012-5-30 207400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 CEDRIVER60;CEDRIVER60;c:\program files (x86)\Cheat Engine 6.3\dbk64.sys;c:\program files (x86)\Cheat Engine 6.3\dbk64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 OSFMount;OSFMount;c:\users\User\Desktop\bin\OSFMount.sys;c:\users\User\Desktop\bin\OSFMount.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
R4 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
R4 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
R4 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
R4 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R4 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.6;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 hmip;hmip;c:\windows\system32\Drivers\hmip64.sys;c:\windows\SYSNATIVE\Drivers\hmip64.sys [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys;c:\windows\SYSNATIVE\drivers\CM10864.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-25 15:27 1096520 ----a-w- c:\program files (x86)\Google\Chrome\Application\37.0.2062.124\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-04 12:34]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 21:49]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 21:49]
.
2013-08-24 c:\windows\Tasks\SidebarExecute.job
- c:\program files\Windows Sidebar\sidebar.exe [2013-08-01 13:25]
.
2013-10-10 c:\windows\Tasks\{CB75B44C-E5EF-4879-B208-C57DFAE62709}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2013-11-24 05:42]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"="wscript.exe" [2013-10-12 168960]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-06-12 6548112]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-09-17 2799784]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-09-17 2460488]
"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2012-08-22 12935168]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = about:newtab
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = 127.0.0.1;<local>
uInternet Settings,ProxyServer = 46.107.14.243:3128
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F71F1AB1-A6DA-4E38-A966-29BD639084CF}: NameServer = 195.146.132.58 195.146.128.62
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: network.proxy.ftp - 66.85.131.18
FF - prefs.js: network.proxy.ftp_port - 7808
FF - prefs.js: network.proxy.http - 66.85.131.18
FF - prefs.js: network.proxy.http_port - 7808
FF - prefs.js: network.proxy.socks - 66.85.131.18
FF - prefs.js: network.proxy.socks_port - 7808
FF - prefs.js: network.proxy.ssl - 66.85.131.18
FF - prefs.js: network.proxy.ssl_port - 7808
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2014-09-17 15:58; {95fa82a2-5246-43e0-bcee-3801c239c192}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mrds6njz.default\extensions\{95fa82a2-5246-43e0-bcee-3801c239c192}
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-Nvtmru - c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
AddRemove-BitTorrent Sync - c:\program files (x86)\BitTorrent Sync\BTSync.exe
AddRemove-{70e83cd8-4bd5-4039-ab5a-6b94a8abb641} - c:\programdata\Package Cache\{70e83cd8-4bd5-4039-ab5a-6b94a8abb641}\Avira.OE.Setup.Bundle.exe
AddRemove-{8e70e4e1-06d7-470b-9f74-a51bef21088e} - c:\programdata\Package Cache\{8e70e4e1-06d7-470b-9f74-a51bef21088e}\vcredist_x86.exe
AddRemove-{a1909659-0a08-4554-8af1-2175904903a1} - c:\programdata\Package Cache\{a1909659-0a08-4554-8af1-2175904903a1}\vcredist_x64.exe
AddRemove-{56837588-F559-40CF-91D9-D439D405FB28} - c:\users\User\AppData\Local\Temp\Download_64DA\Riot_Points_Generator_Downloader.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:78,c4,84,78,d7,a1,ce,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f2,60,a3,0b,06,88,43,47,8a,0b,d3,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f2,60,a3,0b,06,88,43,47,8a,0b,d3,\
.
[HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{a19638fe-8536-4bcf-b659-a38ad619be61}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-2883089224-953471072-2576935892-1000)
@Allowed: (Read) (S-1-15-3-4096)
@Allowed: (Read) (RestrictedCode)
"Flags"=dword:00000400
.
[HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:fc,db,ae,22,25,43,32,73,0e,7a,e8,75,99,90,1d,88,61,23,20,94,09,9f,ea,
49,74,67,34,d2,1b,57,35,7a,ea,f6,ec,2e,66,5d,18,57,c8,dd,5e,a8,e9,80,f7,64,\
"??"=hex:e3,2b,bb,43,b3,3a,55,62,d2,aa,d7,9f,0c,6e,7e,1a
.
[HKEY_USERS\S-1-5-21-2883089224-953471072-2576935892-1000\Software\SecuROM\License information*]
"datasecu"=hex:12,04,a6,d2,d1,02,6f,f6,bc,3d,ee,ce,c9,58,5c,ff,08,8a,20,15,fd,
f2,59,6c,22,33,77,06,1c,b2,96,88,34,82,a7,05,e4,0f,19,f7,10,c3,f8,82,d5,ff,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_167_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_167_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Gaming Keyboard\OSD.exe
.
**************************************************************************
.
Completion time: 2014-09-25 23:34:44 - machine was rebooted
ComboFix-quarantined-files.txt 2014-09-25 21:34
.
Pre-Run: 380 796 366 848 bytes free
Post-Run: 380 317 724 672 bytes free
.
- - End Of File - - F0BB72CA65F643C6C2F6D6AB31FD1033
A36C5E4F47E84449FF07ED3517B43A31
Čo oko nevidí to srdce nebolí.

Zamčeno