Novy Log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-01-2015
Ran by Alik (administrator) on ALIK-PC on 08-01-2015 18:17:05
Running from C:\Users\Alik\Desktop
Loaded Profiles: Alik & postgres (Available profiles: Alik & postgres)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\pg_ctl.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(BitTorrent Inc.) C:\Users\Alik\AppData\Roaming\uTorrent\uTorrent.exe
(forum.viry.cz) C:\Users\Alik\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NUSB3MON] => c:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2015-01-05] (IDT, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630952 2012-07-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [12288 2012-04-19] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2015-01-08] (AVAST Software)
HKU\S-1-5-21-1566090031-1053192374-2067868642-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1566090031-1053192374-2067868642-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-30] (Piriform Ltd)
HKU\S-1-5-21-1566090031-1053192374-2067868642-1000\...\MountPoints2: {5ca5b5ae-8377-11e4-8181-b4b52f918cd2} - I:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1566090031-1053192374-2067868642-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKU\S-1-5-21-1566090031-1053192374-2067868642-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Alik\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM-x32\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-06]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://
www.google.com/"
CHR Profile: C:\Users\Alik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Alik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-06]
CHR Extension: (Vyhledávání Google) - C:\Users\Alik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-06]
CHR Extension: (Avast Online Security) - C:\Users\Alik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-06]
CHR Extension: (Peněženka Google) - C:\Users\Alik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-06]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-08]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-08] (AVAST Software)
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [340480 2015-01-05] (IDT, Inc.) [File not signed]
R2 postgresql-x64-9.0; C:/Program Files/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N "postgresql-x64-9.0" -D "C:/Program Files/PostgreSQL/9.0/data" -w [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11944 2015-01-05] (Advanced Micro Devices Inc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [31872 2012-02-01] (Advanced Micro Devices, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-08] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-08] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-08] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-08] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-08] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-08] ()
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [49584 2015-01-05] (Ralink Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-21] (Disc Soft Ltd)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-05] (REALiX(tm))
S3 massfilter_hs; C:\Windows\system32\drivers\massfilter_hs.sys [20232 2012-06-20] (HandSet Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 rtbth; C:\Windows\System32\DRIVERS\rtbth.sys [1205872 2014-06-27] (Ralink Technology, Corp.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1866080 2012-11-28] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-08 17:26 - 2015-01-08 17:26 - 00002559 _____ () C:\Users\Alik\Desktop\AdwCleaner[S0].txt
2015-01-08 17:21 - 2015-01-08 17:21 - 00000310 _____ () C:\Windows\PFRO.log
2015-01-08 17:21 - 2015-01-08 17:21 - 00000056 _____ () C:\Windows\setupact.log
2015-01-08 17:21 - 2015-01-08 17:21 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-08 17:13 - 2015-01-08 17:20 - 00000000 ____D () C:\AdwCleaner
2015-01-08 17:06 - 2015-01-08 17:06 - 02191360 _____ () C:\Users\Alik\Desktop\adwcleaner_4.107.exe
2015-01-08 13:23 - 2015-01-08 13:23 - 00005790 _____ () C:\Users\Alik\Desktop\Addition.rar
2015-01-08 13:06 - 2015-01-08 18:18 - 00012824 _____ () C:\Users\Alik\Desktop\FRST.txt
2015-01-08 13:05 - 2015-01-08 18:17 - 00000000 ____D () C:\FRST
2015-01-08 13:05 - 2015-01-08 13:05 - 00112640 _____ (forum.viry.cz) C:\Users\Alik\Desktop\FRSTLauncher.exe
2015-01-08 12:53 - 2015-01-08 12:53 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-01-08 12:53 - 2015-01-08 12:53 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-01-08 12:53 - 2015-01-08 12:53 - 00001964 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-01-08 12:45 - 2015-01-08 12:45 - 02124288 _____ (Farbar) C:\Users\Alik\Desktop\FRST64.exe
2015-01-08 03:11 - 2015-01-08 17:09 - 00007601 _____ () C:\Users\Alik\AppData\Local\Resmon.ResmonCfg
2015-01-05 08:45 - 2015-01-05 08:45 - 00110080 _____ (Advanced Micro Devices) C:\Windows\system32\DelayAPO.dll
2015-01-05 08:45 - 2015-01-05 08:45 - 00094720 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys
2015-01-05 08:42 - 2015-01-05 08:42 - 02472136 _____ (Ralink Technology, Corp.) C:\Windows\system32\Drivers\netr28x.sys
2015-01-05 08:42 - 2015-01-05 08:42 - 00941784 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2015-01-05 08:42 - 2015-01-05 08:42 - 00332080 _____ (Ralink Technology, Inc.) C:\Windows\system32\RaCoInstx.dll
2015-01-05 08:42 - 2015-01-05 08:42 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2015-01-05 08:42 - 2015-01-05 08:42 - 00013973 _____ () C:\Windows\system32\RaCoInst.dat
2015-01-05 08:40 - 2015-01-05 08:40 - 02213376 _____ (IDT, Inc.) C:\Windows\system32\stapo64.dll
2015-01-05 08:40 - 2015-01-05 08:40 - 00697856 _____ (IDT, Inc.) C:\Windows\system32\stapi64.dll
2015-01-05 08:40 - 2015-01-05 08:40 - 00551936 _____ (IDT, Inc.) C:\Windows\system32\Drivers\stwrt64.sys
2015-01-05 08:40 - 2015-01-05 08:40 - 00499200 _____ (IDT, Inc.) C:\Windows\system32\stcplx64.dll
2015-01-05 08:40 - 2015-01-05 08:40 - 00256000 _____ (IDT, Inc.) C:\Windows\system32\st646499.dll
2015-01-05 08:39 - 2015-01-05 08:39 - 00227648 _____ (Advanced Micro Devices, INC.) C:\Windows\system32\Drivers\amdxhc.sys
2015-01-05 08:38 - 2015-01-05 08:38 - 00106816 _____ (Advanced Micro Devices, INC.) C:\Windows\system32\Drivers\amdhub30.sys
2015-01-05 08:37 - 2015-01-05 08:37 - 00049584 _____ (Ralink Corporation) C:\Windows\system32\Drivers\IvtUrbBtFlt.sys
2015-01-05 08:37 - 2015-01-05 08:37 - 00011944 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\Drivers\amdide64.sys
2015-01-05 08:31 - 2015-01-05 08:31 - 00203352 _____ (JMicron Technology Corporation) C:\Windows\SysWOW64\jmcricon.dll
2015-01-05 08:31 - 2015-01-05 08:31 - 00203352 _____ (JMicron Technology Corporation) C:\Windows\system32\jmcricon.dll
2015-01-05 08:31 - 2015-01-05 08:31 - 00176880 _____ (JMicron Technology Corporation) C:\Windows\system32\Drivers\jmcr.sys
2015-01-05 08:28 - 2015-01-08 12:59 - 00002852 _____ () C:\Windows\System32\Tasks\Driver Booster SkipUAC (Alik)
2015-01-05 08:28 - 2015-01-05 08:46 - 00002150 _____ () C:\Users\Public\Desktop\Driver Booster 2.lnk
2015-01-05 08:28 - 2015-01-05 08:28 - 00026528 _____ (REALiX(tm)) C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS
2015-01-05 08:28 - 2015-01-05 08:28 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\IObit
2015-01-05 08:28 - 2015-01-05 08:28 - 00000000 ____D () C:\ProgramData\ProductData
2015-01-05 08:28 - 2015-01-05 08:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
2015-01-05 08:28 - 2015-01-05 08:28 - 00000000 ____D () C:\ProgramData\IObit
2015-01-05 08:28 - 2015-01-05 08:28 - 00000000 ____D () C:\Program Files (x86)\IObit
2015-01-05 08:25 - 2015-01-05 08:25 - 00000000 ____D () C:\ProgramData\Innovative Solutions
2015-01-05 08:22 - 2014-06-27 03:29 - 01205872 _____ (Ralink Technology, Corp.) C:\Windows\system32\Drivers\rtbth.sys
2015-01-05 08:22 - 2014-06-27 03:29 - 00040958 _____ () C:\Windows\system32\Drivers\rt3298.bin
2015-01-05 08:16 - 2015-01-05 08:16 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\Innovative Solutions
2015-01-05 08:15 - 2015-01-05 08:34 - 00000000 ____D () C:\Program Files (x86)\Innovative Solutions
2015-01-05 08:15 - 2015-01-05 08:16 - 00000000 ____D () C:\Users\Alik\AppData\Local\Innovative Solutions
2015-01-05 00:43 - 2015-01-05 00:43 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\hpqLog
2015-01-05 00:43 - 2015-01-05 00:43 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\Hewlett-Packard
2015-01-05 00:42 - 2015-01-05 00:43 - 65338512 _____ (Hewlett-Packard Company ) C:\Users\Alik\Downloads\sp61822.exe
2015-01-05 00:38 - 2015-01-05 00:43 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2015-01-05 00:38 - 2015-01-05 00:38 - 00000000 ____D () C:\Program Files (x86)\Hp
2015-01-05 00:37 - 2015-01-05 00:37 - 05165056 _____ () C:\Users\Alik\Downloads\HPSupportSolutionsFramework-11.51.0048.msi
2015-01-03 21:11 - 2015-01-03 21:11 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\IDT
2015-01-03 15:45 - 2015-01-03 21:58 - 00005019 _____ () C:\Users\Alik\Documents\TombRaider.log
2015-01-03 15:45 - 2015-01-03 15:45 - 00000000 ____D () C:\Users\Alik\AppData\Local\SKIDROW
2015-01-03 15:44 - 2015-01-03 15:44 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-01-03 15:43 - 2015-01-03 15:43 - 00000693 _____ () C:\Users\Public\Desktop\Tomb Raider.lnk
2015-01-03 15:43 - 2015-01-03 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2014-12-22 21:24 - 2014-12-24 11:35 - 00000476 _____ () C:\Users\Alik\Desktop\play list.txt
2014-12-19 18:27 - 2014-12-19 18:27 - 00000000 ____D () C:\Users\Alik\AppData\Local\Full tilt
2014-12-18 05:05 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 05:05 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-14 13:36 - 2014-12-14 13:36 - 00000000 ____D () C:\Users\Alik\.android
2014-12-14 13:36 - 2014-12-14 13:36 - 00000000 ____D () C:\Program Files\ZTE_Handset_USB_Driver
2014-12-14 13:36 - 2012-09-04 13:49 - 00162816 _____ (HS Coporation) C:\Windows\system32\Drivers\ghsnet.sys
2014-12-14 13:36 - 2012-09-04 13:42 - 00123520 _____ (HS Coporation) C:\Windows\system32\Drivers\ghsser.sys
2014-12-14 13:36 - 2012-07-18 13:58 - 00132104 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\zghsser.sys
2014-12-14 13:36 - 2012-06-20 11:51 - 00171272 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\zghsnet.sys
2014-12-14 13:36 - 2012-06-20 11:51 - 00020232 _____ (HandSet Incorporated) C:\Windows\system32\Drivers\massfilter_hs.sys
2014-12-14 13:36 - 2011-10-26 15:31 - 00067608 _____ (Google, inc) C:\Windows\AdbWinUsbApi.dll
2014-12-14 13:36 - 2011-08-15 16:43 - 00584584 _____ () C:\Windows\adb.exe
2014-12-14 13:36 - 2011-08-15 16:43 - 00102936 _____ (Google, inc) C:\Windows\AdbWinApi.dll
2014-12-14 13:33 - 2014-12-14 13:53 - 00000000 ____D () C:\Users\Alik\Desktop\ps3 foto
2014-12-11 03:29 - 2014-12-11 03:29 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-11 03:03 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-11 03:03 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-10 03:48 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-10 03:48 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-10 03:48 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-10 03:48 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-10 03:48 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-10 03:48 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-10 03:48 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-10 03:48 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-10 03:48 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 03:48 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 03:48 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 03:47 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-10 03:47 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-10 03:47 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-10 03:47 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-10 03:47 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 03:47 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-10 03:47 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-10 03:47 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-10 03:47 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-10 03:47 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-10 03:47 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-10 03:47 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-10 03:47 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-10 03:47 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-10 03:47 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-10 03:47 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-10 03:47 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 03:47 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-10 03:47 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-10 03:47 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-10 03:47 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 03:47 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-10 03:47 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-10 03:47 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-10 03:47 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-10 03:47 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-10 03:47 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-10 03:47 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-10 03:47 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-10 03:47 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-10 03:47 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-10 03:47 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-10 03:47 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-10 03:47 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-10 03:47 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-10 03:47 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-10 03:47 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-10 03:47 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-10 03:47 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-10 03:47 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 03:47 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-10 03:47 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-10 03:47 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-10 03:47 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-10 03:47 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-10 03:47 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-10 03:47 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-10 03:47 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-10 03:47 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-10 03:47 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-10 03:47 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-10 03:47 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-10 03:47 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-10 03:47 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-10 03:47 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 03:47 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-10 03:47 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 03:47 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-10 03:47 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 03:47 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 03:47 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 03:47 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 03:47 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 03:47 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-10 03:47 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 03:47 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-10 03:47 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-10 03:47 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-08 18:17 - 2014-10-15 20:41 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\uTorrent
2015-01-08 17:55 - 2014-10-07 07:38 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-08 17:54 - 2014-10-06 18:31 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-08 17:30 - 2009-07-14 05:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-08 17:30 - 2009-07-14 05:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-08 17:26 - 2014-10-06 17:30 - 02070459 _____ () C:\Windows\WindowsUpdate.log
2015-01-08 17:23 - 2014-10-06 18:37 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-08 17:22 - 2014-10-06 18:31 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-08 17:21 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-08 17:13 - 2014-10-21 01:49 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\DAEMON Tools Lite
2015-01-08 14:35 - 2011-04-12 09:34 - 00668376 _____ () C:\Windows\system32\perfh005.dat
2015-01-08 14:35 - 2011-04-12 09:34 - 00141004 _____ () C:\Windows\system32\perfc005.dat
2015-01-08 14:35 - 2009-07-14 06:13 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-08 12:56 - 2014-11-20 19:27 - 00000000 ____D () C:\Users\postgres.Alik-PC
2015-01-08 12:53 - 2014-10-06 18:32 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-08 12:53 - 2014-10-06 18:31 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-01-08 12:53 - 2014-10-06 18:31 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-01-08 12:40 - 2014-10-06 19:05 - 00000000 ____D () C:\Users\Alik\AppData\Local\Battle.net
2015-01-07 05:48 - 2014-10-06 18:40 - 00000000 ____D () C:\Users\Alik\AppData\Roaming\vlc
2015-01-06 12:09 - 2014-10-21 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forward Development
2015-01-06 12:06 - 2014-10-22 19:53 - 00000000 ____D () C:\Program Files\VID_0E8F&PID_0003
2015-01-06 12:06 - 2014-10-22 19:53 - 00000000 ____D () C:\Program Files (x86)\VID_0E8F&PID_0003
2015-01-05 08:51 - 2009-07-14 05:45 - 00272432 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-05 08:42 - 2014-10-06 18:06 - 00005652 _____ () C:\Windows\system32\RaCoInst.log
2015-01-05 08:42 - 2014-10-06 18:04 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2015-01-05 08:41 - 2014-10-06 19:29 - 00001646 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRS Premium Sound.lnk
2015-01-05 08:41 - 2014-10-06 19:28 - 00000000 ____D () C:\Program Files\IDT
2015-01-05 08:40 - 2014-10-06 19:29 - 06154240 _____ (IDT, Inc.) C:\Windows\system32\stlang64.dll
2015-01-05 08:40 - 2014-10-06 19:29 - 01703424 _____ (IDT, Inc.) C:\Windows\sttray64.exe
2015-01-05 08:40 - 2014-10-06 19:29 - 00031771 _____ () C:\Windows\system32\SS15&17_3.XML
2015-01-05 08:39 - 2014-10-06 19:29 - 08157184 _____ (IDT, Inc.) C:\Windows\system32\IDTNHP.dll
2015-01-05 08:39 - 2014-10-06 19:29 - 08131584 _____ (IDT, Inc.) C:\Windows\system32\IDTNGUI.exe
2015-01-05 08:39 - 2014-10-06 19:29 - 02233344 _____ (IDT, Inc.) C:\Windows\system32\IDTNX.dll
2015-01-05 08:39 - 2014-10-06 19:29 - 01897984 _____ (IDT, Inc.) C:\Windows\system32\IDTNC64.cpl
2015-01-05 08:39 - 2014-10-06 19:29 - 00464384 _____ (SRS Labs, Inc.) C:\Windows\system32\slapoi64.dll
2015-01-05 08:39 - 2014-10-06 19:29 - 00253952 _____ (IDT, Inc.) C:\Windows\system32\IDTNJ.exe
2015-01-05 08:39 - 2014-10-06 19:29 - 00224768 _____ (IDT, Inc.) C:\Windows\system32\HPToneCtrls64.dll
2015-01-05 08:37 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-05 08:34 - 2014-10-07 07:38 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-05 08:34 - 2014-10-07 07:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-05 08:34 - 2014-10-07 07:38 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-05 05:32 - 2014-10-06 18:10 - 00059144 _____ () C:\Users\Alik\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-05 00:43 - 2014-10-06 17:53 - 00000000 ____D () C:\swsetup
2015-01-03 21:19 - 2014-10-07 07:37 - 00000000 ____D () C:\Users\Alik\AppData\Local\Adobe
2014-12-30 21:36 - 2014-10-06 18:49 - 00000000 ____D () C:\Users\Alik\AppData\Local\PokerStars
2014-12-30 14:36 - 2014-11-20 19:11 - 00000000 ____D () C:\Program Files (x86)\PokerTracker 4
2014-12-23 20:29 - 2014-10-06 18:36 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-23 20:29 - 2014-10-06 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-23 20:29 - 2014-10-06 18:36 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-21 15:49 - 2014-11-19 16:06 - 00000000 ____D () C:\Users\Alik\AppData\Local\NetBet Poker
2014-12-18 10:13 - 2014-10-06 18:18 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-12-14 13:36 - 2014-10-06 17:35 - 00000000 ____D () C:\Users\Alik
2014-12-12 15:00 - 2014-10-06 18:32 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-11 04:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-11 03:29 - 2014-10-07 00:49 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-11 03:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-11 03:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-11 03:11 - 2014-10-06 21:07 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-11 03:06 - 2014-10-06 21:07 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Alik\AppData\Local\Temp\Quarantine.exe
C:\Users\Alik\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-08 13:44
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:97.66 GB) (Free:66.07 GB) NTFS
Drive d: () (Fixed) (Total:6.65 GB) (Free:3.13 GB) NTFS
Drive e: () (Fixed) (Total:568.96 GB) (Free:95.97 GB) NTFS
Drive f: (HP_TOOLS) (Fixed) (Total:1.95 GB) (Free:1.67 GB) FAT32
Drive h: (Tomb Raider - D2) (CDROM) (Total:2.11 GB) (Free:0 GB) CDFS
Available physical RAM: 1757.45 MB
Total physical RAM: 3532.11 MB
Percentage of memory in use: 50%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: A264DD36)
Partition 1: (Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=3.4 GB) - (Type=83)
Partition 3: (Not Active) - (Size=2 GB) - (Type=0C)
Partition 4: (Not Active) - (Size=673.3 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:FB6A21E3
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Alik\Desktop" je 36 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================