Zamrzání PC, chyby při aktualizaci Windows
Napsal: 20 lis 2015 13:25
Prosím o zkontrolování logu, předem děkuji
PC minimálně jednou denně zamrzne, pomůže jen restart natvrdo, vir nenalezen (SuperAntiSpyWare, Malwarebytes Anti-Malware Home, CCleaner a AdwCleaner)
Windows se odmítá updatovat, zkoušela jsem vše možné, ale nic z různých rad nepomohlo, jedná se o:
*Definition Update for Windows Defender - KB915597 (Definition 1.211.259.0)
*Microsoft.NET Framework 4.5, 4.5.1 a 4.5.2
Kód chyby: 648
**to by bylo prozatím asi tak vše
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:19-11-2015
Ran by Marcela (administrator) on ARSENE10PC (20-11-2015 11:24:14)
Running from L:\Programy
Loaded Profiles: Marcela (Available Profiles: Arsene10 & Kocháč & Marcela & Guest)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Nalpeiron Ltd.) C:\Windows\System32\nlssrv32.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\Zps.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Piotr Pawlowski) C:\Program Files\foobar2000\foobar2000.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4702208 2007-10-31] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-10-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-24] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-06] (AVAST Software)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-09-12] (RealNetworks, Inc.)
HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [704512 2009-04-11] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-19] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-27] (AVAST Software)
Startup: C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ACR Launcher.lnk [2013-02-26]
ShortcutTarget: ACR Launcher.lnk -> C:\Program Files\ACR\AutoClubRev\web\acrlauncher.exe ()
Startup: C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2013-03-09]
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Marcela\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook)
Startup: C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2010-10-19]
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Marci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2010-11-12]
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-21] (Společnost Microsoft)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{385D574C-08D2-4489-ACC2-A57218C6DC8A}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{4D6EAC62-12A0-455D-B6ED-94A08C9F284C}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
URLSearchHook: HKLM -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3682315807-1102343484-1862372431-1005 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-3682315807-1102343484-1862372431-1005 -> {D918A68E-D847-4E26-8CB6-8C1C1C92D11C} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12
BHO: No Name -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-30] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO: GretechBHO Class -> {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} -> C:\Program Files\GRETECH\GomPicker\GomPickerBHO.dll [2013-04-03] (Gretech Corporation)
Toolbar: HKU\S-1-5-21-3682315807-1102343484-1862372431-1005 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603
FF DefaultSearchUrl: hxxp://www.bing.com/search
FF SearchEngineOrder.1: Microsoft (Bing)
FF Homepage: hxxp://streepland.wgz.cz
FF Keyword.URL: hxxp://www.bing.com/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-13] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @comrade.gamespy.com/comrade -> C:\Program Files\GameSpy\Comrade\npcomrade.dll [2009-12-11] (IGN Entertainment)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll [2012-09-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-12] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll [2012-01-14] (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll [2012-01-14] (Veetle Inc)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3682315807-1102343484-1862372431-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Marcela\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-09] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3682315807-1102343484-1862372431-1005: facebook.com/fbDesktopPlugin -> C:\Users\Marcela\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009-06-25] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2013-09-12] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2013-09-12] (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll [2010-11-30] (Nullsoft, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npLegitCheckPlugin.dll [2009-06-25] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nppl3260.dll [2013-09-12] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin2.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin3.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin4.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin5.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin6.dll [2012-11-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin7.dll [2012-11-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nprjplug.dll [2012-09-29] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nprpplugin.dll [2013-09-12] (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npwachk.dll [2010-11-30] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\searchplugins\bing-avast.xml [2014-05-30]
FF SearchPlugin: C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\searchplugins\uloto.xml [2013-10-24]
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-12] [not signed]
FF Extension: CoolPreviews - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2014-12-23] [not signed]
FF Extension: Disconnect - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\2.0@disconnect.me.xpi [2015-06-03]
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-14] [not signed]
FF Extension: All-in-One Sidebar - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2015-10-29]
FF Extension: NetVideoHunter - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\netvideohunter@netvideohunter.com [2015-11-13]
FF Extension: Fastest Search - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\fastestsearch@mingyi.org [2015-06-03]
FF Extension: Scroll To Top - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid0-gRmSxW9ByuHwGjLhtXJg27YnZRs@jetpack.xpi [2015-06-03]
FF Extension: No Name - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2015-10-24] [not signed]
FF Extension: Google™ Translator - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid1-dgnIBwQga0SIBw@jetpack.xpi [2015-10-13]
FF Extension: Gmail™ Notifier Plus - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid1-sqmEAwSoa3FZPc@jetpack.xpi [2015-09-06]
FF Extension: Nimbus Screen Capture - editable screenshots. - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\nimbusscreencaptureff@everhelper.me.xpi [2015-11-11]
FF Extension: Super Start - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\superstart@enjoyfreeware(514).org [2014-11-26] [not signed]
FF Extension: Video DownloadHelper - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-11-11]
FF Extension: FoxClocks - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}.xpi [2015-10-13]
FF Extension: Open With Photoshop - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\{f3f219f9-cbce-467e-b8fe-6e076d29665c}.xpi [2015-11-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-03] [not signed]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR Profile: C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-19]
CHR Extension: (Gmail Offline) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2015-06-28]
CHR Extension: (Word Online) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2015-06-29]
CHR Extension: (Video Downloader Super) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghciphhakbampjemlfbahnhhaemoeolf [2015-08-04]
CHR Extension: (AdBlock) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-19]
CHR Extension: (History Eraser) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjieilkfnnjoihjjonajndjldjoagffm [2015-07-03]
CHR Extension: (Scroll To Top) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hegiignepmecppikdlbohnnbfjdoaghj [2015-06-06]
CHR Extension: (Munchee Auto Game Bonus Collector) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoejkmpidaklcngdmkfflceeppncmhko [2015-11-09]
CHR Extension: (Kami (formerly Notable PDF)) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljojpiodmlhoehoecppliohmplbgeij [2015-10-09]
CHR Extension: (Downloads) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfchnphgogjhineanplmfkofljiagjfb [2015-06-06]
CHR Extension: (Google Mail Checker) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-06-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]
CHR Extension: (Click&Clean App) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-10-31]
CHR Extension: (Writer) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnengefjfhgcceajaepbjhanoojifmog [2015-06-28]
CHR Profile: C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (No Name) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-26]
CHR Extension: (No Name) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fneepjciffmedhkndoicgobehmcollbn [2015-01-26]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-02]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [ochbjojkpcmlfeagbaahkofepalngihg] - <no Path\update_url>
Opera:
=======
OPR Extension: (AdBlock) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\aobdicepooefnbaeokijohmhjlleamfj [2015-11-18]
OPR Extension: (AdBlock) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg [2015-09-22]
OPR Extension: (AdBlock) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\bgfkfacpekfgmcmmoolalincjgellfmb [2015-11-12]
OPR Extension: (modern scroll) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\eiinejdcihhdbdbipfapahmjndejdpjb [2015-08-06]
OPR Extension: (Gmail Notifier) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\flkijckbigolpahbkklilflpmkalfohc [2015-08-25]
OPR Extension: (Awesome Screenshot: Capture & Annotate) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\foobgjfmnkeainefnnoeghobcdcidhme [2013-12-17]
OPR Extension: (Disconnect) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\hciohocinlhbdkbjldffomiadmnhjnoj [2015-08-06]
OPR Extension: (convert2mp3.net Online Video Converter) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\kefimjmcofjhaphjiadipfoojljnoinn [2015-08-06]
OPR Extension: (History Eraser) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\lfpoajlbkhlfoeeokbppmecpplmieedm [2015-08-06]
OPR Extension: (Download YouTube Videos as MP4) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\maeombkgfpjdnjkhohbjachnnmpbipol [2015-11-11]
OPR Extension: (Scroll To Top) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\mgblffipaipjkemfkjpmdmfedljnifen [2015-08-06]
OPR Extension: (Photo Tagger) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\mknamppckfmfbebjliiohafcmbhladbl [2015-08-06]
OPR Extension: (FVD Video Downloader) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\neacgcjokggofibnbfapeaejhclmpple [2015-08-18]
OPR Extension: (Magic Actions for YouTube™) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\nlffnljnicbkfhnlomjhjlebndachaka [2015-09-15]
OPR Extension: (Instant-Dictionary) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\ofaolbnbcledpejhmplomdppjdnhfnkl [2013-10-15]
OPR Extension: (Google Translate) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcfaommkmdjacdkbaoohklbccfmbnnod [2015-06-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-10-26] (SUPERAntiSpyware.com)
R2 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015936 2015-09-29] (Adobe Systems, Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-27] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3219136 2015-09-27] (Avast Software)
S4 IceDragonUpdater; C:\Program Files\Comodo\IceDragon\icedragon_updater.exe [1821384 2013-04-18] ()
S4 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [303104 2007-10-15] (Motive Communications, Inc.) [File not signed]
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [1377072 2013-09-19] (O&O Software GmbH)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2078216 2015-10-05] (Electronic Arts)
S4 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
S4 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-11-09] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S4 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-09] (TeamViewer GmbH)
R3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S4 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-09-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [76000 2015-09-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-09-27] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-09-27] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2015-11-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [435464 2015-11-06] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [157888 2015-09-27] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57888 2015-09-27] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208664 2015-09-27] (AVAST Software)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [83984 2012-02-23] (Advanced Micro Devices)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-10-27] (Disc Soft Ltd)
R1 eusk2par; C:\Windows\system32\Drivers\eusk2par.sys [25680 2008-12-18] (Aladdin Knowledge Systems Ltd.)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-11-20] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2006-10-18] ()
R0 ngvss; C:\Windows\system32\Drivers\ngvss.sys [107984 2015-09-27] (AVAST Software)
S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2009-08-05] (CACE Technologies)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [59388 2010-04-12] (PowerISO Computing, Inc.) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-05-31] (Duplex Secure Ltd.)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2010-04-27] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2010-04-27] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2010-04-27] (MCCI Corporation)
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-09-27] (Avast Software)
S3 WsAudioDevice_383; C:\Windows\System32\drivers\WsAudioDevice_383.sys [16640 2008-11-19] (Wondershare) [File not signed]
R2 {C5F942FD-1110-4664-86CE-0C6BDA305235}; C:\Program Files\CyberLink\PowerDVD14\Common\NavFilter\000.fcl [26824 2014-03-17] (CyberLink Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CFcatchme; \??\C:\Users\Marcela\AppData\Local\Temp\CFcatchme.sys [X]
S3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [X]
S3 GPU-Z; \??\C:\Users\KOCH~1.ARS\AppData\Local\Temp\GPU-Z.sys [X]
S4 IObitUnlocker; \??\C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-18 23:11 - 2015-11-18 23:11 - 00011123 _____ C:\Users\Marcela\Desktop\RATF - lyrics.txt
2015-11-18 09:31 - 2015-11-18 09:31 - 00001140 _____ C:\Users\Marcela\Documents\cc_20151118_093112.reg
2015-11-16 19:22 - 2015-11-17 22:12 - 00000969 _____ C:\Users\Marcela\Desktop\Keep playin' that rock 'n' roll.txt
2015-11-16 12:13 - 2015-11-16 12:13 - 841634339 _____ C:\Users\Marcela\Desktop\LITE GRAND I ÖRAT (1981).mp4
2015-11-15 16:06 - 2015-11-15 16:06 - 00080058 _____ C:\Users\Marcela\Desktop\Ricki And The Flash.srt
2015-11-15 15:38 - 2015-11-15 15:38 - 00080061 _____ C:\Users\Marcela\Downloads\Ricki.and.the.Flash.2015.720p.BluRay.x264-GECKOS.srt
2015-11-14 22:09 - 2015-11-14 22:09 - 00032561 _____ C:\Users\Marcela\Downloads\ricki.and.the.flash.(2015).eng.1cd.(6369450).zip
2015-11-14 22:08 - 2015-11-14 22:08 - 00031189 _____ C:\Users\Marcela\Downloads\ricki.and.the.flash.(2015).eng.1cd.(6375184) (1).zip
2015-11-14 21:52 - 2015-11-14 21:52 - 00031189 _____ C:\Users\Marcela\Downloads\ricki.and.the.flash.(2015).eng.1cd.(6375184).zip
2015-11-14 11:06 - 2015-11-14 11:06 - 00005134 _____ C:\Users\Marcela\Documents\cc_20151114_110603.reg
2015-11-13 21:15 - 2015-11-13 21:15 - 00002462 _____ C:\Users\Marcela\Downloads\[kat.cr]adobe.photoshop.cs6.13.1.2.extended.multilanguage.crack.patch.torrent
2015-11-13 21:06 - 2015-11-13 21:06 - 01601585 _____ C:\Users\Marcela\Downloads\adobe-photoshop-CS6-extended-.crack (1).rar
2015-11-13 21:05 - 2015-11-13 21:05 - 01599785 _____ C:\Users\Marcela\Downloads\adobe-photoshop-CS6-extended-.crack.rar
2015-11-12 01:01 - 2015-10-17 15:24 - 02068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-12 00:37 - 2015-10-13 15:31 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-12 00:37 - 2015-10-13 15:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-12 00:36 - 2015-10-17 17:01 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-12 00:35 - 2015-10-14 21:22 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-12 00:35 - 2015-10-14 17:01 - 03606464 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-11-12 00:35 - 2015-10-14 17:01 - 03554752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-12 00:33 - 2015-10-10 17:02 - 00526272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-12 00:30 - 2015-09-26 17:05 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-12 00:30 - 2015-09-26 17:04 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-12 00:30 - 2015-09-26 14:21 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2015-11-12 00:30 - 2015-09-22 14:11 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-11 10:18 - 2015-10-31 18:24 - 11086336 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 06012416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 02006016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-11 10:18 - 2015-10-31 18:24 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll
2015-11-11 10:18 - 2015-10-31 09:41 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-11 10:18 - 2015-10-31 09:34 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-11 10:18 - 2015-10-31 09:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 10:18 - 2015-10-31 09:34 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-11 10:18 - 2015-10-31 09:34 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-11-04 21:22 - 2015-11-17 22:12 - 00000000 ____D C:\Users\Marcela\Desktop\Ricki OST Vegas
2015-11-01 00:32 - 2015-11-01 00:32 - 00000000 ____D C:\5290a1ecd717475bf9acbd
2015-10-30 12:53 - 2015-10-30 14:18 - 861682846 _____ C:\Users\Marcela\Desktop\Ricki And The Flash.mp4
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-20 11:24 - 2015-06-07 18:17 - 00000000 ____D C:\FRST
2015-11-20 11:17 - 2006-11-02 13:47 - 00004608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-20 11:17 - 2006-11-02 13:47 - 00004608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-20 10:56 - 2012-07-30 16:58 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-20 10:38 - 2010-11-04 00:34 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1004UA.job
2015-11-20 10:31 - 2014-09-06 23:53 - 00000000 ____D C:\Users\Marcela\AppData\Roaming\foobar2000
2015-11-20 10:26 - 2010-12-24 00:14 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-20 10:03 - 2008-01-21 02:35 - 01327710 ____N C:\Windows\WindowsUpdate.log
2015-11-20 09:51 - 2015-10-14 14:42 - 00000000 ____D C:\Users\Marcela\AppData\Local\Adobe
2015-11-20 09:34 - 2012-08-01 08:27 - 00000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1005UA.job
2015-11-20 09:33 - 2012-08-01 08:27 - 00000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1005Core.job
2015-11-20 09:26 - 2015-10-17 16:11 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-20 09:21 - 2010-12-24 00:14 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-20 09:20 - 2011-02-21 13:03 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-20 09:17 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-20 01:13 - 2006-11-02 14:01 - 00032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-11-20 00:39 - 2010-11-04 00:34 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1004Core.job
2015-11-19 23:32 - 2013-05-03 13:03 - 00000000 ____D C:\Users\Marcela\Desktop\Shots
2015-11-19 20:26 - 2010-11-20 21:53 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\uTorrent
2015-11-19 19:36 - 2014-12-10 09:23 - 00000000 ___RD C:\Users\Kocháč.Arsene10-PC\Disk Google
2015-11-19 19:34 - 2015-09-22 15:43 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\LocalLow\uTorrent
2015-11-19 10:16 - 2010-10-19 14:16 - 00000000 ____D C:\Program Files\Opera
2015-11-18 23:46 - 2010-12-09 06:52 - 00000000 ____D C:\Users\Marcela\AppData\Roaming\vlc
2015-11-18 16:06 - 2013-04-05 23:03 - 00001680 _____ C:\Users\Marcela\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-11-18 09:16 - 2012-01-09 00:00 - 00000000 ____D C:\Users\Marcela\AppData\Roaming\uTorrent
2015-11-18 09:14 - 2012-12-31 11:11 - 00000000 ____D C:\Users\Marcela\AppData\Local\CrashDumps
2015-11-17 15:19 - 2010-10-17 19:39 - 00000000 ____D C:\Users\Marcela\Desktop\My stuff
2015-11-17 11:49 - 2012-12-30 08:46 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Local\CrashDumps
2015-11-17 11:49 - 2012-10-12 12:47 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Skype
2015-11-16 11:41 - 2015-01-10 23:19 - 00000000 ____D C:\Users\Marcela\Desktop\txt
2015-11-16 11:39 - 2014-05-28 10:30 - 00000000 ____D C:\Users\Marcela\Desktop\Meryl
2015-11-14 10:15 - 2008-05-02 20:44 - 01552978 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-13 13:05 - 2012-01-23 14:50 - 00001356 _____ C:\Users\Marcela\AppData\Local\d3d9caps.dat
2015-11-13 00:17 - 2012-04-04 07:43 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-13 00:17 - 2011-05-20 06:56 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-12 09:28 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-11-12 09:20 - 2015-01-22 09:00 - 00000000 ____D C:\Program Files\TeamViewer
2015-11-12 01:18 - 2006-11-02 13:47 - 04246888 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-12 01:11 - 2006-11-02 13:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-12 00:37 - 2013-08-14 08:08 - 00000000 ____D C:\Windows\system32\MRT
2015-11-12 00:37 - 2006-11-02 11:24 - 143250520 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-11-08 12:48 - 2006-11-02 13:42 - 00000000 ____D C:\Windows\WindowsMobile
2015-11-08 12:41 - 2015-07-30 17:27 - 00000000 ____D C:\AdwCleaner
2015-11-08 12:35 - 2012-07-13 15:41 - 00000000 ____D C:\Program Files\JetAudio
2015-11-08 11:37 - 2010-10-24 13:42 - 00000000 ____D C:\Windows\pss
2015-11-07 16:07 - 2010-10-19 19:09 - 00000000 ____D C:\ProgramData\Adobe
2015-11-06 21:30 - 2015-01-10 16:35 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-11-06 21:30 - 2015-01-10 16:35 - 00435464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-11-06 13:39 - 2010-12-07 15:36 - 00211456 _____ C:\Users\Marcela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-02 12:42 - 2015-10-12 12:28 - 00000000 ____D C:\Users\Public\Documents\CyberLink
2015-11-02 12:42 - 2014-05-04 22:01 - 00000000 ____D C:\ProgramData\CyberLink
2015-10-31 17:12 - 2013-12-31 23:11 - 00000132 _____ C:\Users\Marcela\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-10-28 09:15 - 2010-10-24 00:44 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Local\Adobe
2015-10-26 19:30 - 2010-10-17 15:13 - 00302584 _____ C:\Users\Kocháč.Arsene10-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-22 06:23 - 2010-12-07 15:33 - 00302584 _____ C:\Users\Marcela\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-21 20:44 - 2015-09-08 12:55 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-21 20:43 - 2013-03-27 10:02 - 00000812 _____ C:\Users\Marcela\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-10-21 20:43 - 2010-10-18 21:43 - 00000000 ____D C:\Program Files\GomPlayer
2015-10-21 20:40 - 2010-10-17 17:17 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2015-10-21 14:28 - 2014-12-10 09:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
==================== Files in the root of some directories =======
2010-10-17 18:01 - 2008-09-02 02:09 - 1710070 _____ (Online TV Player.com ) C:\Program Files\tvplayer4.6.0.0.exe
2010-10-17 18:01 - 2010-07-10 10:30 - 0638976 _____ (IObit) C:\Program Files\Uninstall IObit Toolbar.dll
2015-06-22 23:11 - 2015-06-22 23:11 - 0000132 _____ () C:\Users\Marcela\AppData\Roaming\Adobe BMP Format CS6 Prefs
2011-01-17 13:47 - 2013-08-03 19:42 - 0000132 _____ () C:\Users\Marcela\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-12-31 23:11 - 2015-10-31 17:12 - 0000132 _____ () C:\Users\Marcela\AppData\Roaming\Adobe PNG Format CS6 Prefs
2012-10-20 18:49 - 2012-10-20 18:49 - 0000594 _____ () C:\Users\Marcela\AppData\Roaming\AutoGK.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0000120 _____ () C:\Users\Marcela\AppData\Roaming\Camdata.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0000408 _____ () C:\Users\Marcela\AppData\Roaming\CamLayout.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0000408 _____ () C:\Users\Marcela\AppData\Roaming\CamShapes.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0004416 _____ () C:\Users\Marcela\AppData\Roaming\CamStudio.cfg
2014-09-19 19:38 - 2014-09-19 19:38 - 0000670 _____ () C:\Users\Marcela\AppData\Roaming\Contact Sheet II.xml
2014-09-19 19:38 - 2014-09-19 19:44 - 0031235 _____ () C:\Users\Marcela\AppData\Roaming\ContactSheetII.log
2011-10-25 07:34 - 2011-10-25 07:34 - 0000073 _____ () C:\Users\Marcela\AppData\Roaming\default.pls
2014-10-27 18:01 - 2014-10-27 18:01 - 0000029 _____ () C:\Users\Marcela\AppData\Roaming\msleimmv.dat
2014-10-27 18:01 - 2014-10-27 18:01 - 0008629 _____ () C:\Users\Marcela\AppData\Roaming\msutceaj.dat
2015-02-16 21:02 - 2014-12-21 19:37 - 0421200 _____ (Microsoft Corporation) C:\Users\Marcela\AppData\Roaming\msvcp100.dll
2015-02-16 21:02 - 2014-12-21 19:37 - 0770384 _____ (Microsoft Corporation) C:\Users\Marcela\AppData\Roaming\msvcr100.dll
2015-02-16 21:02 - 2015-01-27 15:00 - 1576048 _____ (Mozilla Foundation) C:\Users\Marcela\AppData\Roaming\nss3.dll
2011-04-17 13:45 - 2011-04-17 13:46 - 0191613 _____ () C:\Users\Marcela\AppData\Roaming\PhotoStage.dmp
2013-07-13 13:45 - 2013-07-13 13:44 - 0081582 _____ () C:\Users\Marcela\AppData\Roaming\zulagames.ico
2014-11-27 14:51 - 2014-11-27 14:51 - 0000000 _____ () C:\Users\Marcela\AppData\Local\20141127_1351_HGD86_2834417672.zip
2011-03-24 10:58 - 2014-01-13 14:41 - 0001680 _____ () C:\Users\Marcela\AppData\Local\Adobe Save for Web 12.0 Prefs
2013-04-05 23:03 - 2015-11-18 16:06 - 0001680 _____ () C:\Users\Marcela\AppData\Local\Adobe Save for Web 13.0 Prefs
2012-01-23 14:50 - 2015-11-13 13:05 - 0001356 _____ () C:\Users\Marcela\AppData\Local\d3d9caps.dat
2010-12-07 15:36 - 2015-11-06 13:39 - 0211456 _____ () C:\Users\Marcela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-04-01 16:40 - 2011-04-01 16:40 - 0000058 _____ () C:\Users\Marcela\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2010-10-24 03:33 - 2010-10-30 12:04 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
2012-06-13 16:12 - 2012-06-13 22:36 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-11-28 13:02 - 2013-02-01 11:47 - 0000194 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2014-09-07 15:21 - 2014-09-07 15:21 - 0001534 _____ () C:\ProgramData\ss.ini
Files to move or delete:
====================
C:\Users\Public\install_icq7.exe
Some files in TEMP:
====================
C:\Users\Arsene10\AppData\Local\temp\Foxit Reader Updater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-20 10:19
==================== End of FRST.txt ============================
PC minimálně jednou denně zamrzne, pomůže jen restart natvrdo, vir nenalezen (SuperAntiSpyWare, Malwarebytes Anti-Malware Home, CCleaner a AdwCleaner)
Windows se odmítá updatovat, zkoušela jsem vše možné, ale nic z různých rad nepomohlo, jedná se o:
*Definition Update for Windows Defender - KB915597 (Definition 1.211.259.0)
*Microsoft.NET Framework 4.5, 4.5.1 a 4.5.2
Kód chyby: 648
**to by bylo prozatím asi tak vše
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:19-11-2015
Ran by Marcela (administrator) on ARSENE10PC (20-11-2015 11:24:14)
Running from L:\Programy
Loaded Profiles: Marcela (Available Profiles: Arsene10 & Kocháč & Marcela & Guest)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Nalpeiron Ltd.) C:\Windows\System32\nlssrv32.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\Zps.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Piotr Pawlowski) C:\Program Files\foobar2000\foobar2000.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4702208 2007-10-31] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-10-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-24] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-06] (AVAST Software)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-09-12] (RealNetworks, Inc.)
HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [704512 2009-04-11] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-19] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-27] (AVAST Software)
Startup: C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ACR Launcher.lnk [2013-02-26]
ShortcutTarget: ACR Launcher.lnk -> C:\Program Files\ACR\AutoClubRev\web\acrlauncher.exe ()
Startup: C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2013-03-09]
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Marcela\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook)
Startup: C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2010-10-19]
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Marci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2010-11-12]
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-21] (Společnost Microsoft)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{385D574C-08D2-4489-ACC2-A57218C6DC8A}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{4D6EAC62-12A0-455D-B6ED-94A08C9F284C}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKU\S-1-5-21-3682315807-1102343484-1862372431-1005\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
URLSearchHook: HKLM -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3682315807-1102343484-1862372431-1005 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-3682315807-1102343484-1862372431-1005 -> {D918A68E-D847-4E26-8CB6-8C1C1C92D11C} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12
BHO: No Name -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-30] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO: GretechBHO Class -> {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} -> C:\Program Files\GRETECH\GomPicker\GomPickerBHO.dll [2013-04-03] (Gretech Corporation)
Toolbar: HKU\S-1-5-21-3682315807-1102343484-1862372431-1005 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603
FF DefaultSearchUrl: hxxp://www.bing.com/search
FF SearchEngineOrder.1: Microsoft (Bing)
FF Homepage: hxxp://streepland.wgz.cz
FF Keyword.URL: hxxp://www.bing.com/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-13] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @comrade.gamespy.com/comrade -> C:\Program Files\GameSpy\Comrade\npcomrade.dll [2009-12-11] (IGN Entertainment)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll [2012-09-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-12] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll [2012-01-14] (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll [2012-01-14] (Veetle Inc)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3682315807-1102343484-1862372431-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Marcela\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-09] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3682315807-1102343484-1862372431-1005: facebook.com/fbDesktopPlugin -> C:\Users\Marcela\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009-06-25] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2013-09-12] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-12-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2013-09-12] (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll [2010-11-30] (Nullsoft, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npLegitCheckPlugin.dll [2009-06-25] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nppl3260.dll [2013-09-12] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin2.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin3.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin4.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin5.dll [2014-04-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin6.dll [2012-11-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npqtplugin7.dll [2012-11-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nprjplug.dll [2012-09-29] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\nprpplugin.dll [2013-09-12] (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Users\Marcela\AppData\Roaming\mozilla\plugins\npwachk.dll [2010-11-30] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\searchplugins\bing-avast.xml [2014-05-30]
FF SearchPlugin: C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\searchplugins\uloto.xml [2013-10-24]
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-12] [not signed]
FF Extension: CoolPreviews - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2014-12-23] [not signed]
FF Extension: Disconnect - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\2.0@disconnect.me.xpi [2015-06-03]
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-14] [not signed]
FF Extension: All-in-One Sidebar - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2015-10-29]
FF Extension: NetVideoHunter - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\extensions\netvideohunter@netvideohunter.com [2015-11-13]
FF Extension: Fastest Search - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\fastestsearch@mingyi.org [2015-06-03]
FF Extension: Scroll To Top - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid0-gRmSxW9ByuHwGjLhtXJg27YnZRs@jetpack.xpi [2015-06-03]
FF Extension: No Name - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2015-10-24] [not signed]
FF Extension: Google™ Translator - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid1-dgnIBwQga0SIBw@jetpack.xpi [2015-10-13]
FF Extension: Gmail™ Notifier Plus - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\jid1-sqmEAwSoa3FZPc@jetpack.xpi [2015-09-06]
FF Extension: Nimbus Screen Capture - editable screenshots. - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\nimbusscreencaptureff@everhelper.me.xpi [2015-11-11]
FF Extension: Super Start - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\superstart@enjoyfreeware(514).org [2014-11-26] [not signed]
FF Extension: Video DownloadHelper - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-11-11]
FF Extension: FoxClocks - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}.xpi [2015-10-13]
FF Extension: Open With Photoshop - C:\Users\Marcela\AppData\Roaming\Mozilla\Firefox\Profiles\rp5o7t1x.default-1368478040603\Extensions\{f3f219f9-cbce-467e-b8fe-6e076d29665c}.xpi [2015-11-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-03] [not signed]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR Profile: C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-19]
CHR Extension: (Gmail Offline) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2015-06-28]
CHR Extension: (Word Online) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2015-06-29]
CHR Extension: (Video Downloader Super) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghciphhakbampjemlfbahnhhaemoeolf [2015-08-04]
CHR Extension: (AdBlock) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-19]
CHR Extension: (History Eraser) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjieilkfnnjoihjjonajndjldjoagffm [2015-07-03]
CHR Extension: (Scroll To Top) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hegiignepmecppikdlbohnnbfjdoaghj [2015-06-06]
CHR Extension: (Munchee Auto Game Bonus Collector) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoejkmpidaklcngdmkfflceeppncmhko [2015-11-09]
CHR Extension: (Kami (formerly Notable PDF)) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljojpiodmlhoehoecppliohmplbgeij [2015-10-09]
CHR Extension: (Downloads) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfchnphgogjhineanplmfkofljiagjfb [2015-06-06]
CHR Extension: (Google Mail Checker) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-06-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]
CHR Extension: (Click&Clean App) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-10-31]
CHR Extension: (Writer) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnengefjfhgcceajaepbjhanoojifmog [2015-06-28]
CHR Profile: C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (No Name) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-26]
CHR Extension: (No Name) - C:\Users\Marcela\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fneepjciffmedhkndoicgobehmcollbn [2015-01-26]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-02]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [ochbjojkpcmlfeagbaahkofepalngihg] - <no Path\update_url>
Opera:
=======
OPR Extension: (AdBlock) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\aobdicepooefnbaeokijohmhjlleamfj [2015-11-18]
OPR Extension: (AdBlock) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg [2015-09-22]
OPR Extension: (AdBlock) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\bgfkfacpekfgmcmmoolalincjgellfmb [2015-11-12]
OPR Extension: (modern scroll) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\eiinejdcihhdbdbipfapahmjndejdpjb [2015-08-06]
OPR Extension: (Gmail Notifier) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\flkijckbigolpahbkklilflpmkalfohc [2015-08-25]
OPR Extension: (Awesome Screenshot: Capture & Annotate) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\foobgjfmnkeainefnnoeghobcdcidhme [2013-12-17]
OPR Extension: (Disconnect) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\hciohocinlhbdkbjldffomiadmnhjnoj [2015-08-06]
OPR Extension: (convert2mp3.net Online Video Converter) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\kefimjmcofjhaphjiadipfoojljnoinn [2015-08-06]
OPR Extension: (History Eraser) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\lfpoajlbkhlfoeeokbppmecpplmieedm [2015-08-06]
OPR Extension: (Download YouTube Videos as MP4) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\maeombkgfpjdnjkhohbjachnnmpbipol [2015-11-11]
OPR Extension: (Scroll To Top) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\mgblffipaipjkemfkjpmdmfedljnifen [2015-08-06]
OPR Extension: (Photo Tagger) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\mknamppckfmfbebjliiohafcmbhladbl [2015-08-06]
OPR Extension: (FVD Video Downloader) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\neacgcjokggofibnbfapeaejhclmpple [2015-08-18]
OPR Extension: (Magic Actions for YouTube™) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\nlffnljnicbkfhnlomjhjlebndachaka [2015-09-15]
OPR Extension: (Instant-Dictionary) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\ofaolbnbcledpejhmplomdppjdnhfnkl [2013-10-15]
OPR Extension: (Google Translate) - C:\Users\Marcela\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcfaommkmdjacdkbaoohklbccfmbnnod [2015-06-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-10-26] (SUPERAntiSpyware.com)
R2 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015936 2015-09-29] (Adobe Systems, Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-27] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3219136 2015-09-27] (Avast Software)
S4 IceDragonUpdater; C:\Program Files\Comodo\IceDragon\icedragon_updater.exe [1821384 2013-04-18] ()
S4 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [303104 2007-10-15] (Motive Communications, Inc.) [File not signed]
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [1377072 2013-09-19] (O&O Software GmbH)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2078216 2015-10-05] (Electronic Arts)
S4 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
S4 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-11-09] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S4 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-09] (TeamViewer GmbH)
R3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S4 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [32896 2011-11-28] (AnvSoft Inc.) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-09-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [76000 2015-09-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-09-27] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-09-27] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2015-11-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [435464 2015-11-06] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [157888 2015-09-27] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57888 2015-09-27] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208664 2015-09-27] (AVAST Software)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [83984 2012-02-23] (Advanced Micro Devices)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-10-27] (Disc Soft Ltd)
R1 eusk2par; C:\Windows\system32\Drivers\eusk2par.sys [25680 2008-12-18] (Aladdin Knowledge Systems Ltd.)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-11-20] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2006-10-18] ()
R0 ngvss; C:\Windows\system32\Drivers\ngvss.sys [107984 2015-09-27] (AVAST Software)
S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2009-08-05] (CACE Technologies)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [59388 2010-04-12] (PowerISO Computing, Inc.) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-05-31] (Duplex Secure Ltd.)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2010-04-27] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2010-04-27] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2010-04-27] (MCCI Corporation)
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-09-27] (Avast Software)
S3 WsAudioDevice_383; C:\Windows\System32\drivers\WsAudioDevice_383.sys [16640 2008-11-19] (Wondershare) [File not signed]
R2 {C5F942FD-1110-4664-86CE-0C6BDA305235}; C:\Program Files\CyberLink\PowerDVD14\Common\NavFilter\000.fcl [26824 2014-03-17] (CyberLink Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CFcatchme; \??\C:\Users\Marcela\AppData\Local\Temp\CFcatchme.sys [X]
S3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [X]
S3 GPU-Z; \??\C:\Users\KOCH~1.ARS\AppData\Local\Temp\GPU-Z.sys [X]
S4 IObitUnlocker; \??\C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-18 23:11 - 2015-11-18 23:11 - 00011123 _____ C:\Users\Marcela\Desktop\RATF - lyrics.txt
2015-11-18 09:31 - 2015-11-18 09:31 - 00001140 _____ C:\Users\Marcela\Documents\cc_20151118_093112.reg
2015-11-16 19:22 - 2015-11-17 22:12 - 00000969 _____ C:\Users\Marcela\Desktop\Keep playin' that rock 'n' roll.txt
2015-11-16 12:13 - 2015-11-16 12:13 - 841634339 _____ C:\Users\Marcela\Desktop\LITE GRAND I ÖRAT (1981).mp4
2015-11-15 16:06 - 2015-11-15 16:06 - 00080058 _____ C:\Users\Marcela\Desktop\Ricki And The Flash.srt
2015-11-15 15:38 - 2015-11-15 15:38 - 00080061 _____ C:\Users\Marcela\Downloads\Ricki.and.the.Flash.2015.720p.BluRay.x264-GECKOS.srt
2015-11-14 22:09 - 2015-11-14 22:09 - 00032561 _____ C:\Users\Marcela\Downloads\ricki.and.the.flash.(2015).eng.1cd.(6369450).zip
2015-11-14 22:08 - 2015-11-14 22:08 - 00031189 _____ C:\Users\Marcela\Downloads\ricki.and.the.flash.(2015).eng.1cd.(6375184) (1).zip
2015-11-14 21:52 - 2015-11-14 21:52 - 00031189 _____ C:\Users\Marcela\Downloads\ricki.and.the.flash.(2015).eng.1cd.(6375184).zip
2015-11-14 11:06 - 2015-11-14 11:06 - 00005134 _____ C:\Users\Marcela\Documents\cc_20151114_110603.reg
2015-11-13 21:15 - 2015-11-13 21:15 - 00002462 _____ C:\Users\Marcela\Downloads\[kat.cr]adobe.photoshop.cs6.13.1.2.extended.multilanguage.crack.patch.torrent
2015-11-13 21:06 - 2015-11-13 21:06 - 01601585 _____ C:\Users\Marcela\Downloads\adobe-photoshop-CS6-extended-.crack (1).rar
2015-11-13 21:05 - 2015-11-13 21:05 - 01599785 _____ C:\Users\Marcela\Downloads\adobe-photoshop-CS6-extended-.crack.rar
2015-11-12 01:01 - 2015-10-17 15:24 - 02068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-12 00:37 - 2015-10-13 15:31 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-12 00:37 - 2015-10-13 15:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-12 00:36 - 2015-10-17 17:01 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-12 00:35 - 2015-10-14 21:22 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-12 00:35 - 2015-10-14 17:01 - 03606464 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-11-12 00:35 - 2015-10-14 17:01 - 03554752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-12 00:33 - 2015-10-10 17:02 - 00526272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-12 00:30 - 2015-09-26 17:05 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-12 00:30 - 2015-09-26 17:04 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-12 00:30 - 2015-09-26 14:21 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2015-11-12 00:30 - 2015-09-22 14:11 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-11 10:18 - 2015-10-31 18:24 - 11086336 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 06012416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 02006016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-11 10:18 - 2015-10-31 18:24 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-11 10:18 - 2015-10-31 18:24 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll
2015-11-11 10:18 - 2015-10-31 09:41 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-11 10:18 - 2015-10-31 09:34 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-11 10:18 - 2015-10-31 09:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 10:18 - 2015-10-31 09:34 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-11 10:18 - 2015-10-31 09:34 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-11-04 21:22 - 2015-11-17 22:12 - 00000000 ____D C:\Users\Marcela\Desktop\Ricki OST Vegas
2015-11-01 00:32 - 2015-11-01 00:32 - 00000000 ____D C:\5290a1ecd717475bf9acbd
2015-10-30 12:53 - 2015-10-30 14:18 - 861682846 _____ C:\Users\Marcela\Desktop\Ricki And The Flash.mp4
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-20 11:24 - 2015-06-07 18:17 - 00000000 ____D C:\FRST
2015-11-20 11:17 - 2006-11-02 13:47 - 00004608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-20 11:17 - 2006-11-02 13:47 - 00004608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-20 10:56 - 2012-07-30 16:58 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-20 10:38 - 2010-11-04 00:34 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1004UA.job
2015-11-20 10:31 - 2014-09-06 23:53 - 00000000 ____D C:\Users\Marcela\AppData\Roaming\foobar2000
2015-11-20 10:26 - 2010-12-24 00:14 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-20 10:03 - 2008-01-21 02:35 - 01327710 ____N C:\Windows\WindowsUpdate.log
2015-11-20 09:51 - 2015-10-14 14:42 - 00000000 ____D C:\Users\Marcela\AppData\Local\Adobe
2015-11-20 09:34 - 2012-08-01 08:27 - 00000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1005UA.job
2015-11-20 09:33 - 2012-08-01 08:27 - 00000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1005Core.job
2015-11-20 09:26 - 2015-10-17 16:11 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-20 09:21 - 2010-12-24 00:14 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-20 09:20 - 2011-02-21 13:03 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-20 09:17 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-20 01:13 - 2006-11-02 14:01 - 00032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-11-20 00:39 - 2010-11-04 00:34 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3682315807-1102343484-1862372431-1004Core.job
2015-11-19 23:32 - 2013-05-03 13:03 - 00000000 ____D C:\Users\Marcela\Desktop\Shots
2015-11-19 20:26 - 2010-11-20 21:53 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\uTorrent
2015-11-19 19:36 - 2014-12-10 09:23 - 00000000 ___RD C:\Users\Kocháč.Arsene10-PC\Disk Google
2015-11-19 19:34 - 2015-09-22 15:43 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\LocalLow\uTorrent
2015-11-19 10:16 - 2010-10-19 14:16 - 00000000 ____D C:\Program Files\Opera
2015-11-18 23:46 - 2010-12-09 06:52 - 00000000 ____D C:\Users\Marcela\AppData\Roaming\vlc
2015-11-18 16:06 - 2013-04-05 23:03 - 00001680 _____ C:\Users\Marcela\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-11-18 09:16 - 2012-01-09 00:00 - 00000000 ____D C:\Users\Marcela\AppData\Roaming\uTorrent
2015-11-18 09:14 - 2012-12-31 11:11 - 00000000 ____D C:\Users\Marcela\AppData\Local\CrashDumps
2015-11-17 15:19 - 2010-10-17 19:39 - 00000000 ____D C:\Users\Marcela\Desktop\My stuff
2015-11-17 11:49 - 2012-12-30 08:46 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Local\CrashDumps
2015-11-17 11:49 - 2012-10-12 12:47 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Roaming\Skype
2015-11-16 11:41 - 2015-01-10 23:19 - 00000000 ____D C:\Users\Marcela\Desktop\txt
2015-11-16 11:39 - 2014-05-28 10:30 - 00000000 ____D C:\Users\Marcela\Desktop\Meryl
2015-11-14 10:15 - 2008-05-02 20:44 - 01552978 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-13 13:05 - 2012-01-23 14:50 - 00001356 _____ C:\Users\Marcela\AppData\Local\d3d9caps.dat
2015-11-13 00:17 - 2012-04-04 07:43 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-13 00:17 - 2011-05-20 06:56 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-12 09:28 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-11-12 09:20 - 2015-01-22 09:00 - 00000000 ____D C:\Program Files\TeamViewer
2015-11-12 01:18 - 2006-11-02 13:47 - 04246888 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-12 01:11 - 2006-11-02 13:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-12 00:37 - 2013-08-14 08:08 - 00000000 ____D C:\Windows\system32\MRT
2015-11-12 00:37 - 2006-11-02 11:24 - 143250520 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-11-08 12:48 - 2006-11-02 13:42 - 00000000 ____D C:\Windows\WindowsMobile
2015-11-08 12:41 - 2015-07-30 17:27 - 00000000 ____D C:\AdwCleaner
2015-11-08 12:35 - 2012-07-13 15:41 - 00000000 ____D C:\Program Files\JetAudio
2015-11-08 11:37 - 2010-10-24 13:42 - 00000000 ____D C:\Windows\pss
2015-11-07 16:07 - 2010-10-19 19:09 - 00000000 ____D C:\ProgramData\Adobe
2015-11-06 21:30 - 2015-01-10 16:35 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-11-06 21:30 - 2015-01-10 16:35 - 00435464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-11-06 13:39 - 2010-12-07 15:36 - 00211456 _____ C:\Users\Marcela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-02 12:42 - 2015-10-12 12:28 - 00000000 ____D C:\Users\Public\Documents\CyberLink
2015-11-02 12:42 - 2014-05-04 22:01 - 00000000 ____D C:\ProgramData\CyberLink
2015-10-31 17:12 - 2013-12-31 23:11 - 00000132 _____ C:\Users\Marcela\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-10-28 09:15 - 2010-10-24 00:44 - 00000000 ____D C:\Users\Kocháč.Arsene10-PC\AppData\Local\Adobe
2015-10-26 19:30 - 2010-10-17 15:13 - 00302584 _____ C:\Users\Kocháč.Arsene10-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-22 06:23 - 2010-12-07 15:33 - 00302584 _____ C:\Users\Marcela\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-21 20:44 - 2015-09-08 12:55 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-21 20:43 - 2013-03-27 10:02 - 00000812 _____ C:\Users\Marcela\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-10-21 20:43 - 2010-10-18 21:43 - 00000000 ____D C:\Program Files\GomPlayer
2015-10-21 20:40 - 2010-10-17 17:17 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2015-10-21 14:28 - 2014-12-10 09:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
==================== Files in the root of some directories =======
2010-10-17 18:01 - 2008-09-02 02:09 - 1710070 _____ (Online TV Player.com ) C:\Program Files\tvplayer4.6.0.0.exe
2010-10-17 18:01 - 2010-07-10 10:30 - 0638976 _____ (IObit) C:\Program Files\Uninstall IObit Toolbar.dll
2015-06-22 23:11 - 2015-06-22 23:11 - 0000132 _____ () C:\Users\Marcela\AppData\Roaming\Adobe BMP Format CS6 Prefs
2011-01-17 13:47 - 2013-08-03 19:42 - 0000132 _____ () C:\Users\Marcela\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-12-31 23:11 - 2015-10-31 17:12 - 0000132 _____ () C:\Users\Marcela\AppData\Roaming\Adobe PNG Format CS6 Prefs
2012-10-20 18:49 - 2012-10-20 18:49 - 0000594 _____ () C:\Users\Marcela\AppData\Roaming\AutoGK.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0000120 _____ () C:\Users\Marcela\AppData\Roaming\Camdata.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0000408 _____ () C:\Users\Marcela\AppData\Roaming\CamLayout.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0000408 _____ () C:\Users\Marcela\AppData\Roaming\CamShapes.ini
2013-12-29 00:29 - 2014-09-26 19:46 - 0004416 _____ () C:\Users\Marcela\AppData\Roaming\CamStudio.cfg
2014-09-19 19:38 - 2014-09-19 19:38 - 0000670 _____ () C:\Users\Marcela\AppData\Roaming\Contact Sheet II.xml
2014-09-19 19:38 - 2014-09-19 19:44 - 0031235 _____ () C:\Users\Marcela\AppData\Roaming\ContactSheetII.log
2011-10-25 07:34 - 2011-10-25 07:34 - 0000073 _____ () C:\Users\Marcela\AppData\Roaming\default.pls
2014-10-27 18:01 - 2014-10-27 18:01 - 0000029 _____ () C:\Users\Marcela\AppData\Roaming\msleimmv.dat
2014-10-27 18:01 - 2014-10-27 18:01 - 0008629 _____ () C:\Users\Marcela\AppData\Roaming\msutceaj.dat
2015-02-16 21:02 - 2014-12-21 19:37 - 0421200 _____ (Microsoft Corporation) C:\Users\Marcela\AppData\Roaming\msvcp100.dll
2015-02-16 21:02 - 2014-12-21 19:37 - 0770384 _____ (Microsoft Corporation) C:\Users\Marcela\AppData\Roaming\msvcr100.dll
2015-02-16 21:02 - 2015-01-27 15:00 - 1576048 _____ (Mozilla Foundation) C:\Users\Marcela\AppData\Roaming\nss3.dll
2011-04-17 13:45 - 2011-04-17 13:46 - 0191613 _____ () C:\Users\Marcela\AppData\Roaming\PhotoStage.dmp
2013-07-13 13:45 - 2013-07-13 13:44 - 0081582 _____ () C:\Users\Marcela\AppData\Roaming\zulagames.ico
2014-11-27 14:51 - 2014-11-27 14:51 - 0000000 _____ () C:\Users\Marcela\AppData\Local\20141127_1351_HGD86_2834417672.zip
2011-03-24 10:58 - 2014-01-13 14:41 - 0001680 _____ () C:\Users\Marcela\AppData\Local\Adobe Save for Web 12.0 Prefs
2013-04-05 23:03 - 2015-11-18 16:06 - 0001680 _____ () C:\Users\Marcela\AppData\Local\Adobe Save for Web 13.0 Prefs
2012-01-23 14:50 - 2015-11-13 13:05 - 0001356 _____ () C:\Users\Marcela\AppData\Local\d3d9caps.dat
2010-12-07 15:36 - 2015-11-06 13:39 - 0211456 _____ () C:\Users\Marcela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-04-01 16:40 - 2011-04-01 16:40 - 0000058 _____ () C:\Users\Marcela\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2010-10-24 03:33 - 2010-10-30 12:04 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
2012-06-13 16:12 - 2012-06-13 22:36 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-11-28 13:02 - 2013-02-01 11:47 - 0000194 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2014-09-07 15:21 - 2014-09-07 15:21 - 0001534 _____ () C:\ProgramData\ss.ini
Files to move or delete:
====================
C:\Users\Public\install_icq7.exe
Some files in TEMP:
====================
C:\Users\Arsene10\AppData\Local\temp\Foxit Reader Updater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-20 10:19
==================== End of FRST.txt ============================