kontrola
Napsal: 04 pro 2013 18:45
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-12-2013
Ran by Dajanka (administrator) on DAJANKA-PC on 04-12-2013 18:37:14
Running from C:\Users\Dajanka\Downloads
Microsoft Windows 7 Ultimate Service Pack 3 (X86) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Creative Technology Ltd) C:\Program Files\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(WiseCleaner.com) C:\Program Files\Wise\Wise Care 365\WiseTray.exe
() C:\Program Files\Bloody4\Bloody4\Bloody4.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
(Creative Technology Ltd.) C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [PLFSetL] - C:\Windows\PLFSetL.exe [94208 2008-07-03] (sonix)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6703648 2008-12-11] (Realtek Semiconductor)
HKLM\...\Run: [Sound Blaster Tactic3D Control Panel] - C:\Program Files\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe [2093056 2013-10-09] (Creative Technology Ltd)
HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\ASScrProlog.exe [37232 2013-01-04] ()
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1823656 2013-12-04] (Valve Corporation)
HKCU\...\Run: [AF837732E99D7820D865F6BCB397F894871E385B._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [863184 2013-11-14] (Google Inc.)
HKCU\...\Run: [Bloody2] - C:\Program Files\Bloody4\Bloody4\Bloody4.exe [11895808 2013-08-30] ()
HKCU\...\Run: [Akamai NetSession Interface] - "C:\Users\Dajanka\AppData\Local\Akamai\netsession_win.exe"
HKCU\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [894344 2013-02-05] (Autodesk, Inc.)
HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKCU\...\Policies\Explorer: []
MountPoints2: {1d63fc47-078c-11df-a613-806e6f6e6963} - E:\autorun.exe
MountPoints2: {dbb6ac7e-40ca-11e3-bfe3-8dc6edf74f2f} - E:\setup.exe
MountPoints2: {de951946-6450-11e1-b332-00241d135dda} - K:\LGAutoRun.exe
HKU\Guest\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-12-04] (Valve Corporation)
HKU\Guest\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [ 2013-02-05] (Autodesk, Inc.)
HKU\Guest\...\Run: [AF837732E99D7820D865F6BCB397F894871E385B._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-11-14] (Google Inc.)
HKU\Guest\...\Run: [Bloody2] - C:\Program Files\Bloody4\Bloody4\Bloody4.exe [ 2013-08-30] ()
HKU\Guest\...\RunOnce: [CTPostBootSequencer] - "C:\Users\Dajanka\AppData\Local\Temp\CTPBSeq.exe" /reglaunch /self_destruct
HKU\UpdatusUser\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-12-04] (Valve Corporation)
HKU\UpdatusUser\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [ 2013-02-05] (Autodesk, Inc.)
HKU\UpdatusUser\...\Run: [AF837732E99D7820D865F6BCB397F894871E385B._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-11-14] (Google Inc.)
HKU\UpdatusUser\...\Run: [Bloody2] - C:\Program Files\Bloody4\Bloody4\Bloody4.exe [ 2013-08-30] ()
HKU\UpdatusUser\...\RunOnce: [CTPostBootSequencer] - "C:\Users\Dajanka\AppData\Local\Temp\CTPBSeq.exe" /reglaunch /self_destruct
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=UP97&ocid=UP97DHP
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6C11DE8E95E0CA01
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/UP97_FRPage
URLSearchHook: HKCU - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 241D135DDA}
SearchScopes: HKLM - {0E4501DC-D5CF-4123-B3F4-5E454AEEE1C2} URL = ${SEARCH_URL}{searchTerms}
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 241D135DDA}
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - 1C3C632B3DB84D8286B148621A2F2BC3 URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {0E4501DC-D5CF-4123-B3F4-5E454AEEE1C2} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://mixidj.delta-search.com/?q={sear ... 7&tsp=4999
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {8236D4C1-9A00-45E3-B25B-27D13D3B20D8} URL = http://searchab.com/?aff=7&uid=d7eab270 ... earchTerms}
SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://www.bigseekpro.com/search/browse ... earchTerms}
SearchScopes: HKCU - {CBE84712-40E5-44C8-8E92-E8F8FBB10EB9} URL = http://mp3tubetoolbar.com/?tmp=toolbar_ ... d8baecee31
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb188/?se ... rfOaT&i=26
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 241D135DDA}
SearchScopes: HKCU - {F2AE882A-D5B4-4EEE-ADF6-A50BA6A9189E} URL = http://search.conduit.com/ResultsExt.as ... =CT3220468
BHO: No Name - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - No File
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Toolbar: HKLM - No Name - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - No File
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR Extension: () - C:\Users\Dajanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.19
CHR Extension: (iVidi Chrome Toolbar) - C:\Users\Dajanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef\1.0_0
CHR Extension: (MixiDj Chrome Toolbar) - C:\Users\Dajanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0
CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\Dajanka\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Dajanka\AppData\Local\GamePlayLabs Plugin\gplplugin.crx
========================== Services (Whitelisted) =================
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2013-11-01] (Creative Labs)
S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1064312 2013-09-12] (Flexera Software LLC)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 mitsijm2014; C:\Program Files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe [723744 2013-01-25] (Autodesk, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files\Wise\Wise Care 365\BootTime.exe [580232 2013-04-25] (WiseCleaner.com)
==================== Drivers (Whitelisted) ====================
R3 athur; C:\Windows\System32\DRIVERS\athur.sys [1500160 2010-01-05] (Atheros Communications, Inc.)
S3 gdrv; C:\Windows\gdrv.sys [16608 2013-01-16] (Windows (R) 2000 DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
S3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2010-01-23] (Padus, Inc.)
S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1761280 2009-09-10] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-10-29] (Duplex Secure Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project)
S3 VASDeviceDrm; C:\Windows\System32\drivers\vasdDev.sys [1451312 2012-03-19] (ShiningMorning Inc.)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.)
S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.)
R3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [17920 2009-07-31] (Creative Technology Ltd.)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [x]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-04 18:37 - 2013-12-04 18:37 - 00013514 _____ C:\Users\Dajanka\Downloads\FRST.txt
2013-12-04 18:37 - 2013-12-04 18:37 - 00000000 ____D C:\FRST
2013-12-04 18:36 - 2013-12-04 18:36 - 01092737 _____ (Farbar) C:\Users\Dajanka\Downloads\FRST.exe
2013-12-04 18:20 - 2013-12-04 18:20 - 00622553 _____ (code generator) C:\Users\Dajanka\Downloads\Steam Wallet Hack code generator 2013.exe
2013-12-01 12:44 - 2013-12-04 17:53 - 00000000 ____D C:\Users\Dajanka\Documents\Euro Truck Simulator 2
2013-12-01 12:38 - 2013-12-01 12:38 - 00000216 _____ C:\Users\Dajanka\Desktop\Euro Truck Simulator 2.url
2013-12-01 10:14 - 2013-12-01 10:14 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Chromium
2013-12-01 10:13 - 2013-12-04 18:22 - 00000000 ____D C:\Program Files\Rockstar Games
2013-12-01 10:13 - 2013-12-01 10:14 - 00000000 ____D C:\Users\Dajanka\Documents\Rockstar Games
2013-12-01 10:13 - 2013-12-01 10:13 - 00000000 ____D C:\ProgramData\Rockstar Games
2013-11-29 06:48 - 2013-12-04 18:06 - 00347534 _____ C:\Windows\WindowsUpdate.log
2013-11-29 06:47 - 2013-12-04 13:45 - 00000504 _____ C:\Windows\setupact.log
2013-11-29 06:47 - 2013-12-03 16:16 - 00001704 _____ C:\Windows\PFRO.log
2013-11-29 06:47 - 2013-11-29 06:47 - 04012552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00192128 _____ C:\Users\Dajanka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00000000 _____ C:\Windows\setuperr.log
2013-11-28 19:13 - 2013-11-28 19:26 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Oxy
2013-11-27 21:56 - 2013-11-27 21:56 - 00000114 _____ C:\Users\Dajanka\Desktop\plot.log
2013-11-25 20:10 - 2013-12-03 21:05 - 00000617 _____ C:\Users\Dajanka\Documents\plot.log
2013-11-25 19:13 - 2013-11-25 19:13 - 00000072 _____ C:\Users\Dajanka\Desktop\Inventor.txt
2013-11-25 16:01 - 2013-11-25 16:01 - 00000212 _____ C:\Users\Dajanka\Desktop\Counter-Strike.url
2013-11-24 14:11 - 2013-12-03 21:05 - 00050978 _____ C:\Users\Dajanka\Desktop\STC zadanie.dwg
2013-11-24 14:11 - 2013-12-03 20:52 - 00061546 _____ C:\Users\Dajanka\Desktop\STC zadanie.bak
2013-11-24 13:59 - 2013-11-24 13:59 - 00000203 _____ C:\Users\Dajanka\Documents\debug.log
2013-11-23 21:54 - 2013-11-23 21:54 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Autodesk,_Inc
2013-11-23 21:41 - 2013-11-23 21:41 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Granta Design
2013-11-23 20:01 - 2013-11-23 20:01 - 00001243 _____ C:\Users\Public\Desktop\Autodesk Vault Basic 2014.lnk
2013-11-23 19:23 - 2013-11-23 21:41 - 00000000 ____D C:\Users\Dajanka\Documents\Inventor
2013-11-23 19:18 - 2013-11-23 19:18 - 00002245 _____ C:\Users\Public\Desktop\Autodesk Inventor Professional 2014.lnk
2013-11-23 18:59 - 2013-11-23 18:59 - 00002149 _____ C:\Users\Public\Desktop\Autodesk Design Review 2013.lnk
2013-11-23 18:56 - 2013-11-23 18:56 - 00002135 _____ C:\Users\Public\Desktop\DWG TrueView 2014.lnk
2013-11-22 20:45 - 2013-11-23 20:06 - 00002039 _____ C:\Users\Public\Desktop\Autodesk ReCap.lnk
2013-11-22 20:32 - 2013-11-22 20:32 - 00002098 _____ C:\Users\Public\Desktop\AutoCAD 2014 – Čeština (Czech).lnk
2013-11-22 20:25 - 2013-11-23 20:00 - 00000000 ____D C:\Users\Public\Documents\Autodesk
2013-11-22 19:40 - 2013-11-23 20:06 - 00000000 ____D C:\Program Files\Autodesk
2013-11-22 19:38 - 2013-11-23 19:29 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-11-22 13:12 - 2013-11-22 20:43 - 00000000 ___RD C:\Users\Dajanka\Desktop\BUGGY
2013-11-21 18:11 - 2013-11-22 14:40 - 00000000 ____D C:\Autodesk
2013-11-20 18:08 - 2013-11-20 18:08 - 00001120 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-11-17 19:50 - 2013-11-17 19:50 - 00000000 ____D C:\Users\Dajanka\AppData\Local\bitComposer
2013-11-13 20:55 - 2013-11-13 20:55 - 00000000 ____D C:\Users\Dajanka\AppData\Local\SKIDROW
2013-11-11 21:16 - 2013-11-11 21:16 - 00000002 _____ C:\Users\Public\Documents\Web.txt
2013-11-04 16:15 - 2013-11-04 16:15 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Geckofx
==================== One Month Modified Files and Folders =======
2013-12-04 18:37 - 2013-12-04 18:37 - 00013514 _____ C:\Users\Dajanka\Downloads\FRST.txt
2013-12-04 18:37 - 2013-12-04 18:37 - 00000000 ____D C:\FRST
2013-12-04 18:36 - 2013-12-04 18:36 - 01092737 _____ (Farbar) C:\Users\Dajanka\Downloads\FRST.exe
2013-12-04 18:22 - 2013-12-01 10:13 - 00000000 ____D C:\Program Files\Rockstar Games
2013-12-04 18:20 - 2013-12-04 18:20 - 00622553 _____ (code generator) C:\Users\Dajanka\Downloads\Steam Wallet Hack code generator 2013.exe
2013-12-04 18:06 - 2013-11-29 06:48 - 00347534 _____ C:\Windows\WindowsUpdate.log
2013-12-04 18:05 - 2013-02-07 16:24 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-04 17:56 - 2012-04-14 18:39 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-04 17:54 - 2013-01-04 15:03 - 00000926 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-04 17:53 - 2013-12-01 12:44 - 00000000 ____D C:\Users\Dajanka\Documents\Euro Truck Simulator 2
2013-12-04 17:37 - 2013-01-24 21:42 - 00000000 ____D C:\Program Files\Steam
2013-12-04 16:42 - 2013-02-14 15:05 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\TS3Client
2013-12-04 16:21 - 2013-01-24 21:42 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-12-04 13:50 - 2009-07-14 05:34 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-04 13:50 - 2009-07-14 05:34 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-04 13:45 - 2013-11-29 06:47 - 00000504 _____ C:\Windows\setupact.log
2013-12-04 13:45 - 2013-09-08 18:20 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Wise Care 365
2013-12-04 13:45 - 2013-05-24 16:25 - 00000402 _____ C:\Windows\Tasks\Wise Care 365.job
2013-12-04 13:45 - 2013-04-07 18:28 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-12-04 13:45 - 2013-01-04 15:03 - 00000922 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-04 13:45 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-04 13:44 - 2010-01-22 20:57 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-03 21:05 - 2013-11-25 20:10 - 00000617 _____ C:\Users\Dajanka\Documents\plot.log
2013-12-03 21:05 - 2013-11-24 14:11 - 00050978 _____ C:\Users\Dajanka\Desktop\STC zadanie.dwg
2013-12-03 20:52 - 2013-11-24 14:11 - 00061546 _____ C:\Users\Dajanka\Desktop\STC zadanie.bak
2013-12-03 18:33 - 2013-09-12 14:02 - 00000000 ____D C:\Users\Dajanka\AppData\Local\cache
2013-12-03 16:16 - 2013-11-29 06:47 - 00001704 _____ C:\Windows\PFRO.log
2013-12-02 20:02 - 2013-10-09 15:53 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-12-01 12:38 - 2013-12-01 12:38 - 00000216 _____ C:\Users\Dajanka\Desktop\Euro Truck Simulator 2.url
2013-12-01 10:14 - 2013-12-01 10:14 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Chromium
2013-12-01 10:14 - 2013-12-01 10:13 - 00000000 ____D C:\Users\Dajanka\Documents\Rockstar Games
2013-12-01 10:13 - 2013-12-01 10:13 - 00000000 ____D C:\ProgramData\Rockstar Games
2013-11-30 17:42 - 2010-01-22 20:43 - 00392604 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-29 17:00 - 2013-05-24 16:25 - 00000382 _____ C:\Windows\Tasks\Wise Turbo Checker.job
2013-11-29 06:47 - 2013-11-29 06:47 - 04012552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00192128 _____ C:\Users\Dajanka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00000000 _____ C:\Windows\setuperr.log
2013-11-29 06:47 - 2009-07-14 05:53 - 00032610 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-28 19:26 - 2013-11-28 19:13 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Oxy
2013-11-27 21:56 - 2013-11-27 21:56 - 00000114 _____ C:\Users\Dajanka\Desktop\plot.log
2013-11-26 19:32 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-25 19:13 - 2013-11-25 19:13 - 00000072 _____ C:\Users\Dajanka\Desktop\Inventor.txt
2013-11-25 16:01 - 2013-11-25 16:01 - 00000212 _____ C:\Users\Dajanka\Desktop\Counter-Strike.url
2013-11-24 18:14 - 2013-02-11 18:05 - 00004106 _____ C:\Users\Dajanka\Desktop\configcs16.cfg
2013-11-24 13:59 - 2013-11-24 13:59 - 00000203 _____ C:\Users\Dajanka\Documents\debug.log
2013-11-24 13:59 - 2013-09-11 13:13 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Autodesk
2013-11-23 21:54 - 2013-11-23 21:54 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Autodesk,_Inc
2013-11-23 21:41 - 2013-11-23 21:41 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Granta Design
2013-11-23 21:41 - 2013-11-23 19:23 - 00000000 ____D C:\Users\Dajanka\Documents\Inventor
2013-11-23 21:39 - 2013-09-11 13:13 - 00000000 ____D C:\ProgramData\Autodesk
2013-11-23 20:06 - 2013-11-22 20:45 - 00002039 _____ C:\Users\Public\Desktop\Autodesk ReCap.lnk
2013-11-23 20:06 - 2013-11-22 19:40 - 00000000 ____D C:\Program Files\Autodesk
2013-11-23 20:01 - 2013-11-23 20:01 - 00001243 _____ C:\Users\Public\Desktop\Autodesk Vault Basic 2014.lnk
2013-11-23 20:00 - 2013-11-22 20:25 - 00000000 ____D C:\Users\Public\Documents\Autodesk
2013-11-23 19:29 - 2013-11-22 19:38 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-11-23 19:23 - 2013-09-12 13:31 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Autodesk
2013-11-23 19:18 - 2013-11-23 19:18 - 00002245 _____ C:\Users\Public\Desktop\Autodesk Inventor Professional 2014.lnk
2013-11-23 18:59 - 2013-11-23 18:59 - 00002149 _____ C:\Users\Public\Desktop\Autodesk Design Review 2013.lnk
2013-11-23 18:56 - 2013-11-23 18:56 - 00002135 _____ C:\Users\Public\Desktop\DWG TrueView 2014.lnk
2013-11-22 20:43 - 2013-11-22 13:12 - 00000000 ___RD C:\Users\Dajanka\Desktop\BUGGY
2013-11-22 20:32 - 2013-11-22 20:32 - 00002098 _____ C:\Users\Public\Desktop\AutoCAD 2014 – Čeština (Czech).lnk
2013-11-22 14:40 - 2013-11-21 18:11 - 00000000 ____D C:\Autodesk
2013-11-21 19:47 - 2013-02-22 19:45 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\CoreFTP
2013-11-21 19:47 - 2013-01-20 09:40 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\uTorrent
2013-11-21 18:08 - 2010-01-22 20:32 - 00000000 ____D C:\Users\Dajanka
2013-11-20 18:08 - 2013-11-20 18:08 - 00001120 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-11-20 18:08 - 2013-02-14 15:03 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-11-19 11:21 - 2010-01-22 21:17 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-17 19:50 - 2013-11-17 19:50 - 00000000 ____D C:\Users\Dajanka\AppData\Local\bitComposer
2013-11-14 19:55 - 2013-01-04 15:02 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Deployment
2013-11-13 20:55 - 2013-11-13 20:55 - 00000000 ____D C:\Users\Dajanka\AppData\Local\SKIDROW
2013-11-11 21:16 - 2013-11-11 21:16 - 00000002 _____ C:\Users\Public\Documents\Web.txt
2013-11-04 16:15 - 2013-11-04 16:15 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Geckofx
2013-11-04 16:14 - 2010-01-23 18:45 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Downloaded Installations
Some content of TEMP:
====================
C:\Users\Dajanka\AppData\Local\Temp\DownloadManager.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-26 09:30
==================== End Of Log ============================
Ran by Dajanka (administrator) on DAJANKA-PC on 04-12-2013 18:37:14
Running from C:\Users\Dajanka\Downloads
Microsoft Windows 7 Ultimate Service Pack 3 (X86) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Creative Technology Ltd) C:\Program Files\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(WiseCleaner.com) C:\Program Files\Wise\Wise Care 365\WiseTray.exe
() C:\Program Files\Bloody4\Bloody4\Bloody4.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
(Creative Technology Ltd.) C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [PLFSetL] - C:\Windows\PLFSetL.exe [94208 2008-07-03] (sonix)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6703648 2008-12-11] (Realtek Semiconductor)
HKLM\...\Run: [Sound Blaster Tactic3D Control Panel] - C:\Program Files\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe [2093056 2013-10-09] (Creative Technology Ltd)
HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\ASScrProlog.exe [37232 2013-01-04] ()
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1823656 2013-12-04] (Valve Corporation)
HKCU\...\Run: [AF837732E99D7820D865F6BCB397F894871E385B._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [863184 2013-11-14] (Google Inc.)
HKCU\...\Run: [Bloody2] - C:\Program Files\Bloody4\Bloody4\Bloody4.exe [11895808 2013-08-30] ()
HKCU\...\Run: [Akamai NetSession Interface] - "C:\Users\Dajanka\AppData\Local\Akamai\netsession_win.exe"
HKCU\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [894344 2013-02-05] (Autodesk, Inc.)
HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKCU\...\Policies\Explorer: []
MountPoints2: {1d63fc47-078c-11df-a613-806e6f6e6963} - E:\autorun.exe
MountPoints2: {dbb6ac7e-40ca-11e3-bfe3-8dc6edf74f2f} - E:\setup.exe
MountPoints2: {de951946-6450-11e1-b332-00241d135dda} - K:\LGAutoRun.exe
HKU\Guest\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-12-04] (Valve Corporation)
HKU\Guest\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [ 2013-02-05] (Autodesk, Inc.)
HKU\Guest\...\Run: [AF837732E99D7820D865F6BCB397F894871E385B._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-11-14] (Google Inc.)
HKU\Guest\...\Run: [Bloody2] - C:\Program Files\Bloody4\Bloody4\Bloody4.exe [ 2013-08-30] ()
HKU\Guest\...\RunOnce: [CTPostBootSequencer] - "C:\Users\Dajanka\AppData\Local\Temp\CTPBSeq.exe" /reglaunch /self_destruct
HKU\UpdatusUser\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-12-04] (Valve Corporation)
HKU\UpdatusUser\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [ 2013-02-05] (Autodesk, Inc.)
HKU\UpdatusUser\...\Run: [AF837732E99D7820D865F6BCB397F894871E385B._service_run] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-11-14] (Google Inc.)
HKU\UpdatusUser\...\Run: [Bloody2] - C:\Program Files\Bloody4\Bloody4\Bloody4.exe [ 2013-08-30] ()
HKU\UpdatusUser\...\RunOnce: [CTPostBootSequencer] - "C:\Users\Dajanka\AppData\Local\Temp\CTPBSeq.exe" /reglaunch /self_destruct
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=UP97&ocid=UP97DHP
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6C11DE8E95E0CA01
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/UP97_FRPage
URLSearchHook: HKCU - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 241D135DDA}
SearchScopes: HKLM - {0E4501DC-D5CF-4123-B3F4-5E454AEEE1C2} URL = ${SEARCH_URL}{searchTerms}
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 241D135DDA}
SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKCU - 1C3C632B3DB84D8286B148621A2F2BC3 URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {0E4501DC-D5CF-4123-B3F4-5E454AEEE1C2} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://mixidj.delta-search.com/?q={sear ... 7&tsp=4999
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {8236D4C1-9A00-45E3-B25B-27D13D3B20D8} URL = http://searchab.com/?aff=7&uid=d7eab270 ... earchTerms}
SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://www.bigseekpro.com/search/browse ... earchTerms}
SearchScopes: HKCU - {CBE84712-40E5-44C8-8E92-E8F8FBB10EB9} URL = http://mp3tubetoolbar.com/?tmp=toolbar_ ... d8baecee31
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb188/?se ... rfOaT&i=26
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 241D135DDA}
SearchScopes: HKCU - {F2AE882A-D5B4-4EEE-ADF6-A50BA6A9189E} URL = http://search.conduit.com/ResultsExt.as ... =CT3220468
BHO: No Name - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - No File
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Toolbar: HKLM - No Name - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - No File
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR Extension: () - C:\Users\Dajanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.19
CHR Extension: (iVidi Chrome Toolbar) - C:\Users\Dajanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef\1.0_0
CHR Extension: (MixiDj Chrome Toolbar) - C:\Users\Dajanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0
CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\Dajanka\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Dajanka\AppData\Local\GamePlayLabs Plugin\gplplugin.crx
========================== Services (Whitelisted) =================
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2013-11-01] (Creative Labs)
S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1064312 2013-09-12] (Flexera Software LLC)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 mitsijm2014; C:\Program Files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe [723744 2013-01-25] (Autodesk, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files\Wise\Wise Care 365\BootTime.exe [580232 2013-04-25] (WiseCleaner.com)
==================== Drivers (Whitelisted) ====================
R3 athur; C:\Windows\System32\DRIVERS\athur.sys [1500160 2010-01-05] (Atheros Communications, Inc.)
S3 gdrv; C:\Windows\gdrv.sys [16608 2013-01-16] (Windows (R) 2000 DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
S3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2010-01-23] (Padus, Inc.)
S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1761280 2009-09-10] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-10-29] (Duplex Secure Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project)
S3 VASDeviceDrm; C:\Windows\System32\drivers\vasdDev.sys [1451312 2012-03-19] (ShiningMorning Inc.)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.)
S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.)
R3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [17920 2009-07-31] (Creative Technology Ltd.)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [x]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-04 18:37 - 2013-12-04 18:37 - 00013514 _____ C:\Users\Dajanka\Downloads\FRST.txt
2013-12-04 18:37 - 2013-12-04 18:37 - 00000000 ____D C:\FRST
2013-12-04 18:36 - 2013-12-04 18:36 - 01092737 _____ (Farbar) C:\Users\Dajanka\Downloads\FRST.exe
2013-12-04 18:20 - 2013-12-04 18:20 - 00622553 _____ (code generator) C:\Users\Dajanka\Downloads\Steam Wallet Hack code generator 2013.exe
2013-12-01 12:44 - 2013-12-04 17:53 - 00000000 ____D C:\Users\Dajanka\Documents\Euro Truck Simulator 2
2013-12-01 12:38 - 2013-12-01 12:38 - 00000216 _____ C:\Users\Dajanka\Desktop\Euro Truck Simulator 2.url
2013-12-01 10:14 - 2013-12-01 10:14 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Chromium
2013-12-01 10:13 - 2013-12-04 18:22 - 00000000 ____D C:\Program Files\Rockstar Games
2013-12-01 10:13 - 2013-12-01 10:14 - 00000000 ____D C:\Users\Dajanka\Documents\Rockstar Games
2013-12-01 10:13 - 2013-12-01 10:13 - 00000000 ____D C:\ProgramData\Rockstar Games
2013-11-29 06:48 - 2013-12-04 18:06 - 00347534 _____ C:\Windows\WindowsUpdate.log
2013-11-29 06:47 - 2013-12-04 13:45 - 00000504 _____ C:\Windows\setupact.log
2013-11-29 06:47 - 2013-12-03 16:16 - 00001704 _____ C:\Windows\PFRO.log
2013-11-29 06:47 - 2013-11-29 06:47 - 04012552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00192128 _____ C:\Users\Dajanka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00000000 _____ C:\Windows\setuperr.log
2013-11-28 19:13 - 2013-11-28 19:26 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Oxy
2013-11-27 21:56 - 2013-11-27 21:56 - 00000114 _____ C:\Users\Dajanka\Desktop\plot.log
2013-11-25 20:10 - 2013-12-03 21:05 - 00000617 _____ C:\Users\Dajanka\Documents\plot.log
2013-11-25 19:13 - 2013-11-25 19:13 - 00000072 _____ C:\Users\Dajanka\Desktop\Inventor.txt
2013-11-25 16:01 - 2013-11-25 16:01 - 00000212 _____ C:\Users\Dajanka\Desktop\Counter-Strike.url
2013-11-24 14:11 - 2013-12-03 21:05 - 00050978 _____ C:\Users\Dajanka\Desktop\STC zadanie.dwg
2013-11-24 14:11 - 2013-12-03 20:52 - 00061546 _____ C:\Users\Dajanka\Desktop\STC zadanie.bak
2013-11-24 13:59 - 2013-11-24 13:59 - 00000203 _____ C:\Users\Dajanka\Documents\debug.log
2013-11-23 21:54 - 2013-11-23 21:54 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Autodesk,_Inc
2013-11-23 21:41 - 2013-11-23 21:41 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Granta Design
2013-11-23 20:01 - 2013-11-23 20:01 - 00001243 _____ C:\Users\Public\Desktop\Autodesk Vault Basic 2014.lnk
2013-11-23 19:23 - 2013-11-23 21:41 - 00000000 ____D C:\Users\Dajanka\Documents\Inventor
2013-11-23 19:18 - 2013-11-23 19:18 - 00002245 _____ C:\Users\Public\Desktop\Autodesk Inventor Professional 2014.lnk
2013-11-23 18:59 - 2013-11-23 18:59 - 00002149 _____ C:\Users\Public\Desktop\Autodesk Design Review 2013.lnk
2013-11-23 18:56 - 2013-11-23 18:56 - 00002135 _____ C:\Users\Public\Desktop\DWG TrueView 2014.lnk
2013-11-22 20:45 - 2013-11-23 20:06 - 00002039 _____ C:\Users\Public\Desktop\Autodesk ReCap.lnk
2013-11-22 20:32 - 2013-11-22 20:32 - 00002098 _____ C:\Users\Public\Desktop\AutoCAD 2014 – Čeština (Czech).lnk
2013-11-22 20:25 - 2013-11-23 20:00 - 00000000 ____D C:\Users\Public\Documents\Autodesk
2013-11-22 19:40 - 2013-11-23 20:06 - 00000000 ____D C:\Program Files\Autodesk
2013-11-22 19:38 - 2013-11-23 19:29 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-11-22 13:12 - 2013-11-22 20:43 - 00000000 ___RD C:\Users\Dajanka\Desktop\BUGGY
2013-11-21 18:11 - 2013-11-22 14:40 - 00000000 ____D C:\Autodesk
2013-11-20 18:08 - 2013-11-20 18:08 - 00001120 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-11-17 19:50 - 2013-11-17 19:50 - 00000000 ____D C:\Users\Dajanka\AppData\Local\bitComposer
2013-11-13 20:55 - 2013-11-13 20:55 - 00000000 ____D C:\Users\Dajanka\AppData\Local\SKIDROW
2013-11-11 21:16 - 2013-11-11 21:16 - 00000002 _____ C:\Users\Public\Documents\Web.txt
2013-11-04 16:15 - 2013-11-04 16:15 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Geckofx
==================== One Month Modified Files and Folders =======
2013-12-04 18:37 - 2013-12-04 18:37 - 00013514 _____ C:\Users\Dajanka\Downloads\FRST.txt
2013-12-04 18:37 - 2013-12-04 18:37 - 00000000 ____D C:\FRST
2013-12-04 18:36 - 2013-12-04 18:36 - 01092737 _____ (Farbar) C:\Users\Dajanka\Downloads\FRST.exe
2013-12-04 18:22 - 2013-12-01 10:13 - 00000000 ____D C:\Program Files\Rockstar Games
2013-12-04 18:20 - 2013-12-04 18:20 - 00622553 _____ (code generator) C:\Users\Dajanka\Downloads\Steam Wallet Hack code generator 2013.exe
2013-12-04 18:06 - 2013-11-29 06:48 - 00347534 _____ C:\Windows\WindowsUpdate.log
2013-12-04 18:05 - 2013-02-07 16:24 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-04 17:56 - 2012-04-14 18:39 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-04 17:54 - 2013-01-04 15:03 - 00000926 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-04 17:53 - 2013-12-01 12:44 - 00000000 ____D C:\Users\Dajanka\Documents\Euro Truck Simulator 2
2013-12-04 17:37 - 2013-01-24 21:42 - 00000000 ____D C:\Program Files\Steam
2013-12-04 16:42 - 2013-02-14 15:05 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\TS3Client
2013-12-04 16:21 - 2013-01-24 21:42 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-12-04 13:50 - 2009-07-14 05:34 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-04 13:50 - 2009-07-14 05:34 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-04 13:45 - 2013-11-29 06:47 - 00000504 _____ C:\Windows\setupact.log
2013-12-04 13:45 - 2013-09-08 18:20 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Wise Care 365
2013-12-04 13:45 - 2013-05-24 16:25 - 00000402 _____ C:\Windows\Tasks\Wise Care 365.job
2013-12-04 13:45 - 2013-04-07 18:28 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-12-04 13:45 - 2013-01-04 15:03 - 00000922 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-04 13:45 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-04 13:44 - 2010-01-22 20:57 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-03 21:05 - 2013-11-25 20:10 - 00000617 _____ C:\Users\Dajanka\Documents\plot.log
2013-12-03 21:05 - 2013-11-24 14:11 - 00050978 _____ C:\Users\Dajanka\Desktop\STC zadanie.dwg
2013-12-03 20:52 - 2013-11-24 14:11 - 00061546 _____ C:\Users\Dajanka\Desktop\STC zadanie.bak
2013-12-03 18:33 - 2013-09-12 14:02 - 00000000 ____D C:\Users\Dajanka\AppData\Local\cache
2013-12-03 16:16 - 2013-11-29 06:47 - 00001704 _____ C:\Windows\PFRO.log
2013-12-02 20:02 - 2013-10-09 15:53 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-12-01 12:38 - 2013-12-01 12:38 - 00000216 _____ C:\Users\Dajanka\Desktop\Euro Truck Simulator 2.url
2013-12-01 10:14 - 2013-12-01 10:14 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Chromium
2013-12-01 10:14 - 2013-12-01 10:13 - 00000000 ____D C:\Users\Dajanka\Documents\Rockstar Games
2013-12-01 10:13 - 2013-12-01 10:13 - 00000000 ____D C:\ProgramData\Rockstar Games
2013-11-30 17:42 - 2010-01-22 20:43 - 00392604 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-29 17:00 - 2013-05-24 16:25 - 00000382 _____ C:\Windows\Tasks\Wise Turbo Checker.job
2013-11-29 06:47 - 2013-11-29 06:47 - 04012552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00192128 _____ C:\Users\Dajanka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-29 06:47 - 2013-11-29 06:47 - 00000000 _____ C:\Windows\setuperr.log
2013-11-29 06:47 - 2009-07-14 05:53 - 00032610 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-28 19:26 - 2013-11-28 19:13 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Oxy
2013-11-27 21:56 - 2013-11-27 21:56 - 00000114 _____ C:\Users\Dajanka\Desktop\plot.log
2013-11-26 19:32 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-25 19:13 - 2013-11-25 19:13 - 00000072 _____ C:\Users\Dajanka\Desktop\Inventor.txt
2013-11-25 16:01 - 2013-11-25 16:01 - 00000212 _____ C:\Users\Dajanka\Desktop\Counter-Strike.url
2013-11-24 18:14 - 2013-02-11 18:05 - 00004106 _____ C:\Users\Dajanka\Desktop\configcs16.cfg
2013-11-24 13:59 - 2013-11-24 13:59 - 00000203 _____ C:\Users\Dajanka\Documents\debug.log
2013-11-24 13:59 - 2013-09-11 13:13 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\Autodesk
2013-11-23 21:54 - 2013-11-23 21:54 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Autodesk,_Inc
2013-11-23 21:41 - 2013-11-23 21:41 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Granta Design
2013-11-23 21:41 - 2013-11-23 19:23 - 00000000 ____D C:\Users\Dajanka\Documents\Inventor
2013-11-23 21:39 - 2013-09-11 13:13 - 00000000 ____D C:\ProgramData\Autodesk
2013-11-23 20:06 - 2013-11-22 20:45 - 00002039 _____ C:\Users\Public\Desktop\Autodesk ReCap.lnk
2013-11-23 20:06 - 2013-11-22 19:40 - 00000000 ____D C:\Program Files\Autodesk
2013-11-23 20:01 - 2013-11-23 20:01 - 00001243 _____ C:\Users\Public\Desktop\Autodesk Vault Basic 2014.lnk
2013-11-23 20:00 - 2013-11-22 20:25 - 00000000 ____D C:\Users\Public\Documents\Autodesk
2013-11-23 19:29 - 2013-11-22 19:38 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-11-23 19:23 - 2013-09-12 13:31 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Autodesk
2013-11-23 19:18 - 2013-11-23 19:18 - 00002245 _____ C:\Users\Public\Desktop\Autodesk Inventor Professional 2014.lnk
2013-11-23 18:59 - 2013-11-23 18:59 - 00002149 _____ C:\Users\Public\Desktop\Autodesk Design Review 2013.lnk
2013-11-23 18:56 - 2013-11-23 18:56 - 00002135 _____ C:\Users\Public\Desktop\DWG TrueView 2014.lnk
2013-11-22 20:43 - 2013-11-22 13:12 - 00000000 ___RD C:\Users\Dajanka\Desktop\BUGGY
2013-11-22 20:32 - 2013-11-22 20:32 - 00002098 _____ C:\Users\Public\Desktop\AutoCAD 2014 – Čeština (Czech).lnk
2013-11-22 14:40 - 2013-11-21 18:11 - 00000000 ____D C:\Autodesk
2013-11-21 19:47 - 2013-02-22 19:45 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\CoreFTP
2013-11-21 19:47 - 2013-01-20 09:40 - 00000000 ____D C:\Users\Dajanka\AppData\Roaming\uTorrent
2013-11-21 18:08 - 2010-01-22 20:32 - 00000000 ____D C:\Users\Dajanka
2013-11-20 18:08 - 2013-11-20 18:08 - 00001120 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-11-20 18:08 - 2013-02-14 15:03 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-11-19 11:21 - 2010-01-22 21:17 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-17 19:50 - 2013-11-17 19:50 - 00000000 ____D C:\Users\Dajanka\AppData\Local\bitComposer
2013-11-14 19:55 - 2013-01-04 15:02 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Deployment
2013-11-13 20:55 - 2013-11-13 20:55 - 00000000 ____D C:\Users\Dajanka\AppData\Local\SKIDROW
2013-11-11 21:16 - 2013-11-11 21:16 - 00000002 _____ C:\Users\Public\Documents\Web.txt
2013-11-04 16:15 - 2013-11-04 16:15 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Geckofx
2013-11-04 16:14 - 2010-01-23 18:45 - 00000000 ____D C:\Users\Dajanka\AppData\Local\Downloaded Installations
Some content of TEMP:
====================
C:\Users\Dajanka\AppData\Local\Temp\DownloadManager.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-26 09:30
==================== End Of Log ============================