Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-12-2013 03
Ran by Haba Baba (administrator) on HABABABA-PC on 10-12-2013 20:03:05
Running from C:\Users\Haba Baba\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
() C:\Windows\System32\PnkBstrA.exe
() C:\Windows\System32\PnkBstrB.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
(PowerISO Computing, Inc.) C:\Program Files\PowerISO\PWRISOVM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
() C:\Program Files\Opera\18.0.1284.63\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
(Opera Software) C:\Program Files\Opera\18.0.1284.63\opera.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.)
HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\PowerISO\PWRISOVM.EXE [180224 2010-04-12] (PowerISO Computing, Inc.)
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Policies\Explorer: [TaskbarNoNotification] 1
HKCU\...\Policies\Explorer: [HideSCAHealth] 1
MountPoints2: {108a597a-1df2-11e3-ad37-0018e40734e1} - I:\autorun.exe
MountPoints2: {4a48d380-9e6d-11e1-88e7-0018e40734e1} - G:\suppress_explorer.exe
MountPoints2: {f308a971-9ebb-11e2-96c7-0018e40734e1} - H:\autorun.exe
HKU\dida\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [ 2009-10-30] (DT Soft Ltd)
HKU\dida\...\Run: [Facebook Update] - C:\Users\dida\AppData\Local\Facebook\Update\FacebookUpdate.exe [ 2013-01-15] (Facebook Inc.)
AppInit_DLLs: 0 [ ] ()
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {05CE4604-AAC0-4F0E-8027-0386073A800B} URL =
http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://www.bing.com/search
SearchScopes: HKCU - {399a1442-7377-49e7-8d77-6dc9ed5968c1} URL =
http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826
SearchScopes: HKCU - {5cf5d387-d87c-4408-9a6b-301b0713d62a} URL =
http://www.mapy.cz/?query={searchTerms} ... earch_6826
SearchScopes: HKCU - {eb97f7df-1773-4916-aae6-5af74da8c69d} URL =
http://www.firmy.cz/phr/{searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: No Name - {95289393-33EA-4F8D-B952-483415B9C955} - No File
BHO: No Name - {C93F72A2-2162-4BBA-A07A-F13663C297A6} - No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Toolbar: HKLM - No Name - !{fcbf663e-8530-46f8-a880-ac5abe9d2b23} - No File
Toolbar: HKCU - No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 06 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.230.1
FireFox:
========
FF ProfilePath: C:\Users\Haba Baba\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Haba Baba\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Extension: No Name - C:\Users\Haba Baba\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\staged
FF Extension: No Name - C:\Users\Haba Baba\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\
yasearch@yandex.ru
FF Extension: No Name - C:\Users\Haba Baba\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}
Chrome:
=======
CHR DefaultSearchKeyword: google.cz
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Extension: (Downlooad keeperr) - C:\Users\Haba Baba\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcdnkbahbnmccajhinidpjonfepplloo\1.6
CHR Extension: (GFACE Experience Plugin) - C:\Users\Haba Baba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdlfmdbdibkbfdpjocdaolcheehmpol\0.39.0_0
CHR Extension: (Google Wallet) - C:\Users\Haba Baba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
========================== Services (Whitelisted) =================
R2 avgfws; C:\Program Files\AVG\AVG2014\avgfws.exe [1358944 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2012-09-15] ()
R2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [214520 2013-03-09] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2013-07-17] (Enigma Software Group USA, LLC.)
S3 Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [52080 2007-04-21] ()
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] ()
U4 *etadpug; "C:\Program Files\Google\Desktop\Install\{f6630855-3482-9e43-d54d-97143c5a4b5d}\ \...\???\{f6630855-3482-9e43-d54d-97143c5a4b5d}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
==================== Drivers (Whitelisted) ====================
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6x.sys [47928 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [34576 2007-03-05] (IVT Corporation.)
R3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [27792 2007-03-05] (IVT Corporation.)
R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [18320 2007-03-05] (IVT Corporation.)
S3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [39184 2007-03-05] (IVT Corporation.)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
R0 BTHidEnum; C:\Windows\System32\Drivers\vbtenum.sys [20880 2007-03-05] (IVT Corporation.)
R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [35600 2007-03-05] (IVT Corporation.)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [13904 2011-05-06] ()
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 s116bus; C:\Windows\System32\DRIVERS\s116bus.sys [83336 2007-04-03] (MCCI Corporation)
S3 s116mdfl; C:\Windows\System32\DRIVERS\s116mdfl.sys [15112 2007-04-03] (MCCI Corporation)
S3 s116mdm; C:\Windows\System32\DRIVERS\s116mdm.sys [108680 2007-04-03] (MCCI Corporation)
S3 s116nd5; C:\Windows\System32\DRIVERS\s116nd5.sys [23176 2007-04-03] (MCCI Corporation)
S3 s116unic; C:\Windows\System32\DRIVERS\s116unic.sys [99080 2007-04-03] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2012-05-15] ()
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2009-09-19] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2009-09-19] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2009-09-19] (MCCI Corporation)
R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [34448 2007-03-05] (IVT Corporation.)
R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [44304 2007-03-05] (IVT Corporation.)
U3 a4rt03za; C:\Windows\System32\Drivers\a4rt03za.sys [0 ] (Microsoft Corporation)
S1 ASPI32; No ImagePath
S1 jjekudvj; \??\C:\Windows\system32\drivers\jjekudvj.sys [x]
S1 ocmwygkz; \??\C:\Windows\system32\drivers\ocmwygkz.sys [x]
S1 prgeqyzs; \??\C:\Windows\system32\drivers\prgeqyzs.sys [x]
S1 pynmjwjo; \??\C:\Windows\system32\drivers\pynmjwjo.sys [x]
S1 qothwumz; \??\C:\Windows\system32\drivers\qothwumz.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-10 20:03 - 2013-12-10 20:03 - 00014439 _____ C:\Users\Haba Baba\Desktop\FRST.txt
2013-12-10 20:02 - 2013-12-10 20:02 - 00000000 ____D C:\FRST
2013-12-10 19:31 - 2013-12-09 07:18 - 01060649 _____ (Farbar) C:\Users\Haba Baba\Desktop\FRST.exe
2013-12-07 17:42 - 2013-12-07 17:42 - 00008423 _____ C:\Users\Haba Baba\Desktop\AdwCleaner[S0].txt
2013-12-07 17:27 - 2013-12-07 17:39 - 00000000 ____D C:\AdwCleaner
2013-12-07 16:54 - 2013-12-07 16:54 - 00006456 _____ C:\Users\Haba Baba\Desktop\JRT.txt
2013-12-07 16:41 - 2013-12-07 16:41 - 00000000 ____D C:\Windows\ERUNT
2013-12-07 16:40 - 2013-11-05 23:36 - 01034531 _____ (Thisisu) C:\Users\Haba Baba\Desktop\JRT_NEW.exe
2013-12-07 16:35 - 2013-12-10 19:59 - 00000478 _____ C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2013-12-07 16:35 - 2013-12-10 18:00 - 00000452 _____ C:\Windows\Tasks\ParetoLogic Registration3.job
2013-12-07 16:35 - 2013-12-07 16:44 - 00000426 _____ C:\Windows\Tasks\ParetoLogic Update Version3.job
2013-12-07 16:35 - 2013-12-07 16:44 - 00000394 _____ C:\Windows\Tasks\RegCure Pro.job
2013-12-07 16:35 - 2013-12-07 16:35 - 00000831 _____ C:\Users\Haba Baba\Desktop\RegCure Pro.lnk
2013-12-07 16:32 - 2004-06-30 05:40 - 01032220 _____ (Thisisu) C:\Users\Haba Baba\Desktop\JRT.exe
2013-12-07 16:31 - 2013-12-07 16:34 - 00000000 ____D C:\Users\Haba Baba\Desktop\0000000
2013-12-05 18:02 - 2013-12-05 18:02 - 00000000 ____D C:\Users\dida\AppData\Local\Opera Software
2013-12-05 18:01 - 2013-12-05 18:01 - 00000000 ____D C:\Users\dida\AppData\Roaming\Opera Software
2013-12-02 17:13 - 2013-12-02 17:13 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Opera Software
2013-12-02 17:13 - 2013-12-02 17:13 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Opera Software
2013-12-02 17:12 - 2013-12-02 17:12 - 00001091 _____ C:\Users\Public\Desktop\Opera.lnk
2013-12-02 16:23 - 2013-12-02 16:26 - 00000000 ____D C:\sh4ldr
2013-12-02 16:23 - 2013-12-02 16:23 - 00002254 _____ C:\Users\Haba Baba\Desktop\SpyHunter.lnk
2013-12-02 16:23 - 2013-12-02 16:23 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2013-12-02 16:22 - 2013-12-02 16:23 - 00000079 _____ C:\Windows\wininit.ini
2013-12-02 16:22 - 2013-12-02 16:22 - 00000665 _____ C:\INSTALL.LOG
2013-12-02 16:10 - 2013-12-02 16:23 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP
2013-12-01 20:27 - 2013-12-02 22:36 - 00000478 _____ C:\Users\Haba Baba\Desktop\Imper.txt
2013-11-30 17:20 - 2013-12-02 16:26 - 00004026 _____ C:\Windows\PFRO.log
2013-11-30 13:54 - 2013-12-10 17:22 - 00000925 _____ C:\Users\Haba Baba\Desktop\Nový textový dokument (2).txt
2013-11-27 22:45 - 2013-12-10 19:39 - 00001456 _____ C:\Windows\setupact.log
2013-11-27 22:45 - 2013-11-27 22:45 - 00000000 _____ C:\Windows\setuperr.log
2013-11-27 21:00 - 2013-12-06 16:03 - 00006409 _____ C:\Users\Haba Baba\Desktop\hijackthis.log
2013-11-27 20:50 - 2013-12-02 21:25 - 00000000 ____D C:\Users\Haba Baba\Desktop\backups
2013-11-27 20:38 - 2013-11-27 20:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Haba Baba\Desktop\hijackthis.exe
2013-11-27 20:19 - 2013-11-27 22:17 - 00000000 ____D C:\Windows\Minidump
2013-11-27 17:31 - 2013-12-02 16:26 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-11-27 17:31 - 2013-12-02 16:23 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-27 17:26 - 2013-05-20 00:10 - 00000864 _____ C:\Users\dida\Desktop\Metro Last Light.lnk
2013-11-25 19:50 - 2013-12-08 14:55 - 00005855 _____ C:\spyhunter.log
2013-11-25 18:50 - 2013-12-08 13:58 - 00007085 _____ C:\sh4_service.log
2013-11-25 18:47 - 2013-12-02 16:26 - 00008192 _____ C:\shldr.mbr
2013-11-25 18:46 - 2013-11-25 18:46 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-25 18:45 - 2013-11-27 17:29 - 00000000 ____D C:\Windows\220FB0354744483A9A0B41DF77061583.TMP
2013-11-23 10:25 - 2013-11-23 10:25 - 00000000 ____D C:\ProgramData\Oracle
2013-11-23 10:25 - 2013-11-23 10:25 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-23 10:25 - 2013-10-08 07:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-11-23 10:25 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-11-23 10:25 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-11-23 10:25 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-11-23 10:22 - 2013-11-23 10:25 - 00004668 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-11-23 10:12 - 2013-11-23 10:12 - 00000000 ____D C:\Users\dida\AppData\Roaming\AVG2014
2013-11-23 10:11 - 2013-11-23 10:20 - 00000000 ____D C:\Users\dida\AppData\Local\Avg2014
2013-11-22 18:24 - 2013-11-22 18:24 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\AVG2014
2013-11-22 18:23 - 2013-11-22 18:23 - 00000947 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-11-22 18:22 - 2013-11-25 19:18 - 00000000 ____D C:\ProgramData\AVG2014
2013-11-22 18:22 - 2013-11-22 18:22 - 00000000 ___HD C:\$AVG
2013-11-22 18:12 - 2013-11-25 17:37 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Avg2014
2013-11-22 18:08 - 2013-11-22 18:08 - 00000000 ____D C:\Program Files\AVG
2013-11-22 16:26 - 2013-11-30 16:30 - 00000000 ____D C:\ProgramData\MFAData
2013-11-22 16:26 - 2013-11-22 16:26 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\MFAData
2013-11-22 16:25 - 2013-12-01 20:27 - 00001486 _____ C:\Users\Haba Baba\Desktop\ImperIcon voe!.txt
2013-11-22 16:25 - 2013-11-27 18:11 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Media Player Classic
2013-11-22 16:25 - 2013-11-23 13:39 - 00000000 ____D C:\Users\Haba Baba\Desktop\Čtivo 8)
2013-11-22 12:21 - 2013-11-22 12:23 - 00000000 ____D C:\Windows\rescache
2013-11-20 21:46 - 2013-12-02 18:50 - 00000000 __SHD C:\ProgramData\blacksilver0
2013-11-15 11:45 - 2013-11-15 11:45 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Blizzard Entertainment
2013-11-15 10:00 - 2013-11-15 10:08 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-11-15 01:54 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-15 01:54 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-15 01:54 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-15 01:54 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-15 01:54 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-15 01:54 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-14 21:52 - 2013-12-01 00:24 - 00000000 ____D C:\Program Files\Common Files\Blizzard Entertainment
2013-11-14 21:33 - 2013-11-14 21:33 - 00000540 _____ C:\Users\dida\Desktop\World of Warcraft Installer.lnk
2013-11-14 21:20 - 2013-11-14 21:20 - 00000000 ____D C:\ProgramData\Blizzard
2013-11-14 08:41 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 08:41 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 08:41 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 08:41 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 08:41 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 08:41 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 08:41 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 08:41 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 08:41 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 08:41 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 08:41 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 08:41 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 08:41 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 08:41 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 08:41 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 08:41 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 08:41 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 08:41 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-10 21:00 - 2013-11-10 21:00 - 00126976 _____ (Blizzard Entertainment) C:\Windows\War3Unin.exe
2013-11-10 21:00 - 2013-11-10 21:00 - 00013889 _____ C:\Windows\War3Unin.dat
2013-11-10 21:00 - 2013-11-10 21:00 - 00002829 _____ C:\Windows\War3Unin.pif
2013-11-10 21:00 - 2013-11-10 21:00 - 00000642 _____ C:\Users\Haba Baba\Desktop\Warcraft III.lnk
2013-11-10 21:00 - 2013-11-10 21:00 - 00000642 _____ C:\Users\dida\Desktop\Warcraft III.lnk
2013-11-10 21:00 - 2013-11-10 21:00 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warcraft III
==================== One Month Modified Files and Folders =======
2013-12-10 20:03 - 2013-12-10 20:03 - 00014439 _____ C:\Users\Haba Baba\Desktop\FRST.txt
2013-12-10 20:02 - 2013-12-10 20:02 - 00000000 ____D C:\FRST
2013-12-10 20:01 - 2013-10-19 21:45 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-10 19:59 - 2013-12-07 16:35 - 00000478 _____ C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2013-12-10 19:59 - 2013-10-03 20:45 - 00000424 ____H C:\Windows\Tasks\schedule!3036567561.job
2013-12-10 19:59 - 2013-02-04 23:38 - 00000942 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-10 19:59 - 2012-10-20 16:01 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Skype
2013-12-10 19:44 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\tracing
2013-12-10 19:39 - 2013-11-27 22:45 - 00001456 _____ C:\Windows\setupact.log
2013-12-10 19:39 - 2012-06-04 18:50 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-12-10 19:39 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-10 19:37 - 2009-07-14 05:34 - 00017168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-10 19:37 - 2009-07-14 05:34 - 00017168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-10 19:36 - 2012-05-25 14:36 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\PMB Files
2013-12-10 19:21 - 2012-04-10 16:24 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Last.fm
2013-12-10 19:08 - 2013-02-04 23:38 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-10 18:47 - 2012-05-25 14:36 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-10 18:40 - 2013-01-15 21:35 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4117245281-1480158384-2095474572-1001UA.job
2013-12-10 18:00 - 2013-12-07 16:35 - 00000452 _____ C:\Windows\Tasks\ParetoLogic Registration3.job
2013-12-10 17:57 - 2012-10-23 19:52 - 00000944 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4117245281-1480158384-2095474572-1000UA.job
2013-12-10 17:22 - 2013-11-30 13:54 - 00000925 _____ C:\Users\Haba Baba\Desktop\Nový textový dokument (2).txt
2013-12-09 07:18 - 2013-12-10 19:31 - 01060649 _____ (Farbar) C:\Users\Haba Baba\Desktop\FRST.exe
2013-12-08 21:40 - 2013-01-15 21:35 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4117245281-1480158384-2095474572-1001Core.job
2013-12-08 20:57 - 2012-10-23 19:52 - 00000922 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4117245281-1480158384-2095474572-1000Core.job
2013-12-08 14:55 - 2013-11-25 19:50 - 00005855 _____ C:\spyhunter.log
2013-12-08 13:58 - 2013-11-25 18:50 - 00007085 _____ C:\sh4_service.log
2013-12-07 17:42 - 2013-12-07 17:42 - 00008423 _____ C:\Users\Haba Baba\Desktop\AdwCleaner[S0].txt
2013-12-07 17:39 - 2013-12-07 17:27 - 00000000 ____D C:\AdwCleaner
2013-12-07 16:54 - 2013-12-07 16:54 - 00006456 _____ C:\Users\Haba Baba\Desktop\JRT.txt
2013-12-07 16:48 - 2012-09-26 20:32 - 00000000 ____D C:\Program Files\Dll-Files.com Fixer
2013-12-07 16:44 - 2013-12-07 16:35 - 00000426 _____ C:\Windows\Tasks\ParetoLogic Update Version3.job
2013-12-07 16:44 - 2013-12-07 16:35 - 00000394 _____ C:\Windows\Tasks\RegCure Pro.job
2013-12-07 16:41 - 2013-12-07 16:41 - 00000000 ____D C:\Windows\ERUNT
2013-12-07 16:35 - 2013-12-07 16:35 - 00000831 _____ C:\Users\Haba Baba\Desktop\RegCure Pro.lnk
2013-12-07 16:34 - 2013-12-07 16:31 - 00000000 ____D C:\Users\Haba Baba\Desktop\0000000
2013-12-07 16:32 - 2012-04-10 15:20 - 00393450 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-06 16:03 - 2013-11-27 21:00 - 00006409 _____ C:\Users\Haba Baba\Desktop\hijackthis.log
2013-12-06 15:44 - 2012-04-10 15:49 - 00000000 ____D C:\Program Files\Opera
2013-12-05 18:10 - 2013-02-04 23:39 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-05 18:02 - 2013-12-05 18:02 - 00000000 ____D C:\Users\dida\AppData\Local\Opera Software
2013-12-05 18:01 - 2013-12-05 18:01 - 00000000 ____D C:\Users\dida\AppData\Roaming\Opera Software
2013-12-02 22:36 - 2013-12-01 20:27 - 00000478 _____ C:\Users\Haba Baba\Desktop\Imper.txt
2013-12-02 21:25 - 2013-11-27 20:50 - 00000000 ____D C:\Users\Haba Baba\Desktop\backups
2013-12-02 18:50 - 2013-11-20 21:46 - 00000000 __SHD C:\ProgramData\blacksilver0
2013-12-02 18:08 - 2013-10-03 20:44 - 00000000 ____D C:\ProgramData\Downlooad keeperr
2013-12-02 17:13 - 2013-12-02 17:13 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Opera Software
2013-12-02 17:13 - 2013-12-02 17:13 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Opera Software
2013-12-02 17:12 - 2013-12-02 17:12 - 00001091 _____ C:\Users\Public\Desktop\Opera.lnk
2013-12-02 17:12 - 2012-04-10 15:18 - 00001417 _____ C:\Users\Haba Baba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-02 17:09 - 2013-04-06 16:15 - 00000000 ____D C:\ProgramData\InstallMate
2013-12-02 16:26 - 2013-12-02 16:23 - 00000000 ____D C:\sh4ldr
2013-12-02 16:26 - 2013-11-30 17:20 - 00004026 _____ C:\Windows\PFRO.log
2013-12-02 16:26 - 2013-11-27 17:31 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-12-02 16:26 - 2013-11-25 18:47 - 00008192 _____ C:\shldr.mbr
2013-12-02 16:23 - 2013-12-02 16:23 - 00002254 _____ C:\Users\Haba Baba\Desktop\SpyHunter.lnk
2013-12-02 16:23 - 2013-12-02 16:23 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2013-12-02 16:23 - 2013-12-02 16:22 - 00000079 _____ C:\Windows\wininit.ini
2013-12-02 16:23 - 2013-12-02 16:10 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP
2013-12-02 16:23 - 2013-11-27 17:31 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-12-02 16:22 - 2013-12-02 16:22 - 00000665 _____ C:\INSTALL.LOG
2013-12-02 16:09 - 2012-05-05 23:12 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2013-12-01 20:27 - 2013-11-22 16:25 - 00001486 _____ C:\Users\Haba Baba\Desktop\ImperIcon voe!.txt
2013-12-01 00:25 - 2013-01-26 15:00 - 00000000 ____D C:\Users\Haba Baba\Desktop\Audiosurf
2013-12-01 00:24 - 2013-11-14 21:52 - 00000000 ____D C:\Program Files\Common Files\Blizzard Entertainment
2013-11-30 16:30 - 2013-11-22 16:26 - 00000000 ____D C:\ProgramData\MFAData
2013-11-30 15:04 - 2012-12-20 19:25 - 00000000 ____D C:\Users\Haba Baba\Desktop\babo Onen PLOCHA bordel
2013-11-27 22:45 - 2013-11-27 22:45 - 00000000 _____ C:\Windows\setuperr.log
2013-11-27 22:17 - 2013-11-27 20:19 - 00000000 ____D C:\Windows\Minidump
2013-11-27 20:38 - 2013-11-27 20:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Haba Baba\Desktop\hijackthis.exe
2013-11-27 20:35 - 2012-04-10 16:16 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Winamp
2013-11-27 18:11 - 2013-11-22 16:25 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Media Player Classic
2013-11-27 17:29 - 2013-11-25 18:45 - 00000000 ____D C:\Windows\220FB0354744483A9A0B41DF77061583.TMP
2013-11-25 19:49 - 2013-06-11 12:39 - 00000991 _____ C:\Users\dida\Desktop\421621_4871935477688_237660243_n.lnk
2013-11-25 19:18 - 2013-11-22 18:22 - 00000000 ____D C:\ProgramData\AVG2014
2013-11-25 18:46 - 2013-11-25 18:46 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-25 17:37 - 2013-11-22 18:12 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Avg2014
2013-11-23 13:39 - 2013-11-22 16:25 - 00000000 ____D C:\Users\Haba Baba\Desktop\Čtivo 8)
2013-11-23 10:25 - 2013-11-23 10:25 - 00000000 ____D C:\ProgramData\Oracle
2013-11-23 10:25 - 2013-11-23 10:25 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-23 10:25 - 2013-11-23 10:22 - 00004668 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-11-23 10:25 - 2013-03-22 00:39 - 00000000 ____D C:\Program Files\Java
2013-11-23 10:20 - 2013-11-23 10:11 - 00000000 ____D C:\Users\dida\AppData\Local\Avg2014
2013-11-23 10:12 - 2013-11-23 10:12 - 00000000 ____D C:\Users\dida\AppData\Roaming\AVG2014
2013-11-22 18:24 - 2013-11-22 18:24 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\AVG2014
2013-11-22 18:23 - 2013-11-22 18:23 - 00000947 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-11-22 18:22 - 2013-11-22 18:22 - 00000000 ___HD C:\$AVG
2013-11-22 18:08 - 2013-11-22 18:08 - 00000000 ____D C:\Program Files\AVG
2013-11-22 16:33 - 2013-01-27 23:28 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\TuneUp Software
2013-11-22 16:26 - 2013-11-22 16:26 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\MFAData
2013-11-22 12:23 - 2013-11-22 12:21 - 00000000 ____D C:\Windows\rescache
2013-11-22 11:01 - 2012-04-15 13:53 - 00067416 _____ C:\Users\dida\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-21 21:15 - 2009-07-14 05:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-11-21 20:45 - 2012-04-10 16:13 - 00067416 _____ C:\Users\Haba Baba\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-21 20:44 - 2009-07-14 05:33 - 00301536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-21 19:30 - 2012-08-07 18:29 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Vso
2013-11-21 19:30 - 2012-05-15 09:57 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\DAEMON Tools Lite
2013-11-21 19:28 - 2012-04-11 01:11 - 00000000 ____D C:\Windows\Panther
2013-11-21 18:48 - 2012-04-12 15:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-11-21 18:48 - 2012-04-12 15:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-11-21 18:47 - 2013-02-04 23:38 - 00000000 ____D C:\Program Files\Google
2013-11-21 18:41 - 2013-02-04 23:38 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Google
2013-11-15 11:45 - 2013-11-15 11:45 - 00000000 ____D C:\Users\Haba Baba\AppData\Local\Blizzard Entertainment
2013-11-15 10:08 - 2013-11-15 10:00 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-11-14 21:52 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2013-11-14 21:33 - 2013-11-14 21:33 - 00000540 _____ C:\Users\dida\Desktop\World of Warcraft Installer.lnk
2013-11-14 21:20 - 2013-11-14 21:20 - 00000000 ____D C:\ProgramData\Blizzard
2013-11-14 17:02 - 2012-04-10 15:34 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-12 16:18 - 2013-01-09 21:50 - 00000000 ____D C:\Windows\system32\appmgmt
2013-11-11 22:54 - 2012-05-23 18:39 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-10 21:00 - 2013-11-10 21:00 - 00126976 _____ (Blizzard Entertainment) C:\Windows\War3Unin.exe
2013-11-10 21:00 - 2013-11-10 21:00 - 00013889 _____ C:\Windows\War3Unin.dat
2013-11-10 21:00 - 2013-11-10 21:00 - 00002829 _____ C:\Windows\War3Unin.pif
2013-11-10 21:00 - 2013-11-10 21:00 - 00000642 _____ C:\Users\Haba Baba\Desktop\Warcraft III.lnk
2013-11-10 21:00 - 2013-11-10 21:00 - 00000642 _____ C:\Users\dida\Desktop\Warcraft III.lnk
2013-11-10 21:00 - 2013-11-10 21:00 - 00000000 ____D C:\Users\Haba Baba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warcraft III
2013-11-10 12:55 - 2012-10-20 16:01 - 00000000 ____D C:\ProgramData\Skype
ZeroAccess:
C:\Users\Haba Baba\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
Some content of TEMP:
====================
C:\Users\Haba Baba\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Haba Baba\AppData\Local\Temp\Update.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2013-12-04 22:10
==================== End Of Log ============================