Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-08-2014 Ran by Preak (administrator) on PREAK-PC on 23-08-2014 12:04:20 Running from D:\pes 2014 Platform: Windows 7 Enterprise Service Pack 1 (X64) OS Language: Angielski (Stany Zjednoczone) Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Andrea Electronics Corporation) C:\Windows\System32\AESRV64.EXE (Scarlet.Crush Productions) C:\Users\Preak\Desktop\ScpServer\bin\ScpService.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe () C:\Windows\SysWOW64\PnkBstrA.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\pg_ctl.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (VMware, Inc.) G:\vmware\vmware-authd.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe () G:\vmware\vmware-hostd.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\rundll32.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe () C:\Program Files (x86)\screenSHU\screenSHU.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe () C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe () C:\Program Files (x86)\GreedyTorrent\GTor.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (OldTimer Tools) D:\pes 2014\OTL.exe () C:\Users\Preak\AppData\Roaming\ACEStream\updater\ace_update.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Valve Corporation) G:\steam\Steam.exe (Valve Corporation) G:\steam\bin\steamwebhelper.exe (Valve Corporation) G:\steam\bin\steamwebhelper.exe (Farbar) D:\pes 2014\FRST64 (2).exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5618456 2013-09-12] (ESET) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8294680 2014-02-28] (Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [500736 2011-05-02] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [224128 2014-03-18] (Oracle Corporation) HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated) HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5021448 2014-08-12] (FNet Co., Ltd.) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [screenSHU] => C:\Program Files (x86)\screenSHU\screenSHU.exe [2112000 2013-09-04] () HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [uTorrent] => C:\Users\Preak\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-02] (BitTorrent Inc.) HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [ASRockXTU] => [X] HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\MountPoints2: {5b2ae33d-2f46-11e3-9cfd-005056c00008} - J:\setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aggiorna ESET license.lnk ShortcutTarget: Aggiorna ESET license.lnk -> C:\Program Files (x86)\ESET\MiNODLogin\launcher.exe (GuillerSoft) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Status Monitor.lnk ShortcutTarget: Status Monitor.lnk -> C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre8\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre8\bin\jp2ssv.dll (Oracle Corporation) Handler: WSIEChrome - {6D02ED5F-FD0D-4C4C - No File Handler-x32: WSIEChrome - {6D02ED5F-FD0D-4C4C - No File Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter-x32: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter-x32: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter-x32: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.172.224.160 89.231.1.206 FireFox: ======== FF ProfilePath: C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=11.5.2 -> C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.5.2 -> C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.5.2 -> C:\Program Files (x86)\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.5.2 -> C:\Program Files (x86)\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: smpmozplug -> C:\Users\Preak\AppData\Local\SigmaPlayer\Sigma\npvlc.dll No File FF Plugin HKCU: @acestream.net/acestreamplugin,version=2.2.9-next -> C:\Users\Preak\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Preak\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc -> F:\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll (Ubisoft) FF Extension: AS Magic Player - C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default\Extensions\magicplayer@acestream.org [2014-08-23] FF Extension: Greasemonkey - C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-03-16] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-04-02] FF HKLM-x32\...\Firefox\Extensions: [Player@Wondershare.com] - C:\ProgramData\Wondershare\Player\Player@Wondershare.com FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF HKCU\...\Firefox\Extensions: [{841531c9-338a-47e8-9724-864b3be7f84e}] - C:\Program Files (x86)\TubeSaver\131.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com CHR StartupUrls: "hxxp://www.google.com" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll () CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Google\Chrome\Application\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Google\Chrome\Application\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Google\Chrome\Application\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Google\Chrome\Application\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Google\Chrome\Application\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Google\Chrome\Application\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Unity Player) - C:\Users\Preak\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Ace Stream P2P Multimedia Plug-in) - C:\Users\Preak\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies) CHR Plugin: (Raidcall plugin) - C:\Users\Preak\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (Przelewy24) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiicmmpkicnndkhlnnloilpgncbpkbjj [2014-08-07] CHR Extension: (Google Docs) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-01] CHR Extension: (Google Drive) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-01] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-25] CHR Extension: (YouTube) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-01] CHR Extension: (Adblock Plus) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-30] CHR Extension: (Google Search) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-01] CHR Extension: (Screen Capture (by Google)) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpngackimfmofbokmjmljamhdncknpmg [2013-05-15] CHR Extension: (Tampermonkey) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-03-16] CHR Extension: (Steam Market Filter) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\emdpoeanmcbopmmdomongbohbmiolmom [2014-03-14] CHR Extension: (eSports.pl (poczta)) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmohbfidjfncaapkeeihnjpejgbgpdgo [2013-06-13] CHR Extension: (NetBeans Connector) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafdlehgocfcodbgjnpecfajgkeejnaa [2013-12-05] CHR Extension: (The Grids) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgfgflhpelebngbkojdfjjekjnkgdcag [2013-05-28] CHR Extension: (Steam Market Auto-Agree) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlicldafjdigokihkkdlbpfgehihjodl [2014-03-16] CHR Extension: (Night Time In New York City) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek [2013-09-03] CHR Extension: (Window Resizer) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkelicaakdanhinjdeammmilcgefonfh [2013-04-08] CHR Extension: (AS Magic Player) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhnkgpdlogbknkhlgdjlejeljbhflim [2014-08-23] CHR Extension: (Google Wallet) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30] CHR Extension: (ColorPick Eyedropper) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohcpnigalekghcmgcdcenkpelffpdolg [2013-10-07] CHR Extension: (Auto Refresh Plus) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilipfekkmncanaajkapbpancpelijih [2013-10-01] CHR Extension: (Gmail) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-01] CHR HKLM-x32\...\Chrome\Extension: [aaaajccikcnncidhbokfncpooceanool] - C:\ProgramData\AskPartnerNetwork\Toolbar\SPCV7\CRX\ToolbarCR.crx [2013-04-01] CHR HKLM-x32\...\Chrome\Extension: [bkdegagmpemadclljncealhmmkojfoam] - C:\ProgramData\Wondershare\Player\Player@Wondershare.com.crx [2013-04-01] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AE64Filters; C:\Windows\system32\AESRV64.EXE [111616 2009-06-05] (Andrea Electronics Corporation) [File not signed] S4 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] () [File not signed] R2 Ds3Service; C:\Users\Preak\Desktop\ScpServer\bin\ScpService.exe [381952 2014-04-03] (Scarlet.Crush Productions) [File not signed] R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1337752 2013-09-12] (ESET) S4 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [163840 2013-02-13] (Brio) [File not signed] S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-09] () S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 VMAuthdService; G:\vmware\vmware-authd.exe [79872 2012-08-15] (VMware, Inc.) [File not signed] R2 VMwareHostd; G:\vmware\vmware-hostd.exe [15680000 2012-08-15] () [File not signed] S3 wampapache; f:\wamp\bin\apache\apache2.2.22\bin\httpd.exe [22016 2012-05-13] (Apache Software Foundation) [File not signed] S3 wampmysqld; f:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe [9693696 2012-04-19] () [File not signed] R2 postgresql-x64-9.0; C:/Program Files (x86)/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N "postgresql-x64-9.0" -D "C:/Program Files/PostgreSQL/9.0/data" -w [X] R3 WinHttpAutoProxySvc; winhttp.dll [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [24840 2009-01-07] (IVT Corporation.) S3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [35848 2008-12-07] () R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc) S3 dpmconv; C:\Windows\System32\DRIVERS\dpmconv.sys [259072 2012-07-05] (SIEMENS AG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-10-07] (DT Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-08-16] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-08-12] (FNet Co., Ltd.) S3 hidusbf; C:\Windows\System32\DRIVERS\hidusbf.sys [7808 2013-12-14] (SweetLow) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [30112 2013-05-15] (REALiX(tm)) S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [5353888 2012-12-14] (Intel Corporation) [File not signed] S3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [31624 2008-07-02] (IVT Corporation.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2014-07-10] (http://libusb-win32.sourceforge.net) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation) S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [116264 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [19496 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [158760 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [34856 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [135208 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [151592 2009-05-25] (MCCI Corporation) S3 s7odpx2x64; C:\Windows\System32\DRIVERS\s7odpx2x64.sys [71168 2012-12-19] (SIEMENS AG) S3 s7oppinx64; C:\Windows\System32\DRIVERS\s7oppinx64.sys [107520 2012-07-24] (SIEMENS AG) S3 s7oserix64; C:\Windows\System32\Drivers\s7oserix64.sys [121856 2012-07-24] (SIEMENS AG) S3 s7osmcax64; C:\Windows\System32\DRIVERS\s7osmcax64.sys [199680 2012-07-24] (SIEMENS AG) S3 s7osobux64; C:\Windows\System32\DRIVERS\s7osobux64.sys [153600 2012-07-24] (SIEMENS AG) S3 s7otmcd64x; C:\Windows\System32\Drivers\s7otmcd64x.sys [199680 2012-07-24] (SIEMENS AG) S3 s7otranx64; C:\Windows\System32\DRIVERS\s7otranx64.sys [260096 2012-07-24] (SIEMENS AG) S3 s7otsadx64; C:\Windows\System32\DRIVERS\s7otsadx64.sys [196096 2012-07-24] (SIEMENS AG) S2 s7ousbu64x; C:\Windows\System32\DRIVERS\s7ousbu64x.sys [213504 2012-12-19] (SIEMENS AG) R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-09-18] (Duplex Secure Ltd.) S3 tizeqdrv; C:\Users\Preak\AppData\Roaming\TZAC2\tizeq64.sys [171704 2013-04-01] () S3 vsnl2ada; C:\Windows\System32\DRIVERS\vsnl2ada.sys [126976 2012-05-09] (SIEMENS AG) R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.) U3 a7iwwpm4; C:\Windows\System32\Drivers\a7iwwpm4.sys [0 ] (Microsoft Corporation) S3 ALSysIO; \??\D:\Temp\ALSysIO64.sys [X] S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 GPU-Z; \??\D:\Tmp\GPU-Z.sys [X] S2 s7sn2srtx; system32\DRIVERS\s7sn2srtx.sys [X] S2 SNTIE; system32\DRIVERS\sntie.sys [X] S3 VComm; system32\DRIVERS\VComm.sys [X] S3 VcommMgr; System32\Drivers\VcommMgr.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 XFDriver64; \??\C:\Program Files (x86)\Xfire2\XFDriver64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-23 00:42 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-08-23 00:27 - 2014-08-23 00:33 - 00468234 _____ () C:\Users\Preak\Desktop\sfcdetails.txt 2014-08-16 21:01 - 2014-08-16 21:01 - 00000000 ____D () C:\Users\Preak\Desktop\kopia penis 2014-08-15 10:34 - 2014-08-15 10:34 - 00000000 ____D () C:\Users\Preak\AppData\Local\Risen3 2014-08-15 10:33 - 2014-08-15 10:33 - 00000770 _____ () C:\Users\Public\Desktop\Risen 3 - Titan Lords.lnk 2014-08-12 15:23 - 2012-02-27 03:01 - 00788760 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys 2014-08-12 15:23 - 2012-02-27 03:01 - 00356120 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys 2014-08-12 15:23 - 2012-02-27 03:01 - 00016152 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys 2014-08-12 15:22 - 2014-08-12 15:22 - 00001226 _____ () C:\Users\Public\Desktop\ASRock eXtreme Tuner.lnk 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files (x86)\ASRock Utility 2014-08-12 15:22 - 2012-01-13 12:52 - 00031016 _____ (ASRock Inc.) C:\Windows\system32\Drivers\AsrRamDisk.sys 2014-08-12 15:21 - 2014-08-16 20:22 - 00032320 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETTBOH_305.SYS 2014-08-12 15:21 - 2014-08-12 15:21 - 00016648 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETURPX.SYS 2014-08-12 15:21 - 2014-08-12 15:21 - 00001885 _____ () C:\Users\Public\Desktop\XFast USB.LNK 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\FNET 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\Program Files (x86)\XFastUSB 2014-08-08 23:03 - 2007-03-09 01:52 - 00394752 _____ () C:\Windows\SysWOW64\cygwinb19.dll 2014-08-08 23:03 - 2006-04-10 22:41 - 01066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl32.ocx 2014-08-07 16:50 - 2014-08-07 16:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-05 15:46 - 2014-08-23 00:49 - 00010963 _____ () C:\Windows\setupact.log 2014-08-05 15:46 - 2014-08-06 20:15 - 00001908 _____ () C:\Windows\diagwrn.xml 2014-08-05 15:46 - 2014-08-06 20:15 - 00001908 _____ () C:\Windows\diagerr.xml 2014-08-05 15:46 - 2014-08-06 20:13 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-05 14:55 - 2014-08-05 14:55 - 00000000 ____D () C:\Users\Preak\AppData\Local\e-academy Inc 2014-08-03 14:50 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-08-03 14:50 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-08-03 14:49 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-08-03 14:36 - 2014-08-23 00:53 - 00000000 ____D () C:\Users\Preak\Desktop\logi 2014-08-03 14:34 - 2014-08-23 12:04 - 00000000 ____D () C:\FRST 2014-08-03 13:49 - 2005-12-05 18:07 - 00061136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XInput9_1_0.dll 2014-08-03 12:44 - 2014-08-03 14:54 - 00352614 _____ () C:\Windows\system32\sfcdetails.txt 2014-08-03 12:20 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-08-03 12:20 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2014-08-03 12:20 - 2013-01-13 22:08 - 01504768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2014-08-03 12:20 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2014-08-03 12:20 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-08-03 12:20 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2014-08-03 12:20 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2014-08-03 12:20 - 2010-11-21 05:24 - 01828352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll 2014-08-03 12:19 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-08-03 12:19 - 2006-03-31 12:49 - 00007927 _____ () C:\Windows\SysWOW64\xinput1_1_x86.cat 2014-08-03 12:19 - 2006-03-31 12:49 - 00007927 _____ () C:\Windows\SysWOW64\xinput1_1_x64.cat 2014-08-03 12:19 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-08-03 11:18 - 2014-08-03 11:19 - 00000000 ____D () C:\Users\Preak\Desktop\kopia 2014-08-02 18:24 - 2014-08-02 22:50 - 00003718 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-08-02 18:24 - 2014-08-02 18:24 - 00003476 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2014-08-01 18:21 - 2014-08-01 18:21 - 00001126 _____ () C:\Users\Public\Desktop\MiNODLogin Esplora Licenze.lnk 2014-08-01 18:21 - 2014-08-01 18:21 - 00001120 _____ () C:\Users\Public\Desktop\Aggiorna ESET license.lnk 2014-08-01 09:19 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-01 09:19 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-01 09:19 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-01 09:19 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-01 09:19 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-01 09:19 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-01 09:19 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-01 09:19 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-01 09:19 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-01 09:19 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-01 09:19 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-01 09:19 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-01 09:19 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-01 09:19 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-07-30 22:14 - 2014-07-30 22:14 - 00105600 _____ () C:\Users\Preak\Desktop\save.sav 2014-07-30 17:47 - 2014-07-30 17:47 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\SKIDROW 2014-07-30 17:30 - 2014-07-30 17:30 - 00105368 _____ () C:\Users\1.save 2014-07-30 15:36 - 2014-07-30 15:36 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\Wayforward Technologies 2014-07-29 18:45 - 2014-07-29 18:45 - 00043701 _____ () C:\Windows\Cmicnfgp.ini.cfl 2014-07-29 18:45 - 2014-07-29 18:45 - 00000630 _____ () C:\Windows\Cmicnfgp.ini.imi 2014-07-29 18:45 - 2014-07-29 18:45 - 00000569 _____ () C:\Windows\system\Cmicnfgp.ini 2014-07-29 18:45 - 2013-11-12 09:30 - 00831488 ____N () C:\Windows\system32\Cmeauoxy.exe 2014-07-29 18:45 - 2013-10-17 10:29 - 07958528 _____ (C-Media Corporation) C:\Windows\SysWOW64\CmiCnfgp.dll 2014-07-29 18:45 - 2013-10-16 10:55 - 00143360 _____ () C:\Windows\SysWOW64\VmixP8.dll 2014-07-29 18:45 - 2013-03-13 23:47 - 00004525 ____N () C:\Windows\Cmicnfgp.ini.cfg 2014-07-29 18:45 - 2013-03-07 21:08 - 00005874 ____N () C:\Windows\cmudaxp.ini 2014-07-29 18:45 - 2012-10-05 09:37 - 00465408 ____N (C-Media Electronics Inc.) C:\Windows\system32\cmasiopx.dll 2014-07-29 18:45 - 2012-10-05 09:37 - 00303104 _____ (C-Media Electronics Inc.) C:\Windows\SysWOW64\cmasiop.dll 2014-07-29 18:45 - 2012-01-06 09:30 - 00212992 _____ (C-Media Electronics Inc.) C:\Windows\SysWOW64\HsSrv2.dll 2014-07-29 18:45 - 2012-01-06 09:30 - 00122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv642.dll 2014-07-29 18:45 - 2012-01-06 09:30 - 00122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv64.dll 2014-07-29 18:45 - 2010-07-15 16:12 - 00000062 ____N () C:\Windows\system32\cmasiopx.ini 2014-07-29 18:45 - 2010-07-15 16:12 - 00000057 _____ () C:\Windows\SysWOW64\cmasiop.ini 2014-07-29 18:45 - 2008-07-11 15:04 - 00200704 _____ () C:\Windows\SysWOW64\HsMgr.exe 2014-07-29 18:45 - 2008-07-11 15:03 - 00282112 ____N () C:\Windows\system\HsMgr64.exe 2014-07-29 18:45 - 2007-12-13 17:12 - 00122880 ____N (CMedia Electronics Inc.) C:\Windows\system32\Cm_Oal.dll 2014-07-29 18:45 - 2007-12-13 17:12 - 00122880 _____ (CMedia Electronics Inc.) C:\Windows\SysWOW64\Cm_Oal.dll 2014-07-29 18:45 - 2006-09-13 10:21 - 00200704 _____ (C-Media) C:\Windows\SysWOW64\Cmpaoxy.dll 2014-07-29 18:42 - 2014-07-29 18:43 - 00000000 ____D () C:\Program Files (x86)\Driver Fusion 2014-07-29 18:42 - 2014-07-29 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Fusion 2014-07-28 11:54 - 2014-07-28 11:54 - 00000905 _____ () C:\Users\Public\Desktop\AIMP3.lnk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-23 12:04 - 2014-08-03 14:34 - 00000000 ____D () C:\FRST 2014-08-23 12:01 - 2013-05-26 22:05 - 00000000 ____D () C:\Users\Preak\AppData\Local\CrashDumps 2014-08-23 12:00 - 2013-08-30 15:00 - 00325140 _____ () C:\Users\Preak\Network_Meter_Data.js 2014-08-23 11:43 - 2014-06-17 05:38 - 00001048 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf89dd969508d3.job 2014-08-23 11:06 - 2014-06-05 00:53 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-23 10:51 - 2009-07-14 06:45 - 00008240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-23 10:51 - 2009-07-14 06:45 - 00008240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-23 08:50 - 2014-01-24 21:23 - 00000388 _____ () C:\Windows\Tasks\update-S-1-5-21-2973642986-523059004-888739316-1000.job 2014-08-23 06:12 - 2013-05-16 23:22 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{1E04A170-3DC2-480D-8FDF-4E1A6EAF853D} 2014-08-23 05:43 - 2013-08-29 02:58 - 00001044 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cea452e2e8c39c.job 2014-08-23 03:40 - 2013-04-01 20:30 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\uTorrent 2014-08-23 03:04 - 2013-04-04 21:12 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\vlc 2014-08-23 02:00 - 2014-06-20 00:04 - 00000000 ____D () C:\Users\Preak\AppData\Local\Adobe 2014-08-23 01:38 - 2013-04-01 18:51 - 01607397 _____ () C:\Windows\WindowsUpdate.log 2014-08-23 01:09 - 2013-08-31 15:27 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\ACEStream 2014-08-23 01:08 - 2013-08-31 16:12 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\.ACEStream 2014-08-23 00:57 - 2013-04-02 18:38 - 00754136 _____ () C:\Windows\system32\perfh015.dat 2014-08-23 00:57 - 2013-04-02 18:38 - 00164038 _____ () C:\Windows\system32\perfc015.dat 2014-08-23 00:57 - 2009-07-14 07:13 - 01713170 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-23 00:53 - 2014-08-03 14:36 - 00000000 ____D () C:\Users\Preak\Desktop\logi 2014-08-23 00:50 - 2014-02-11 22:51 - 00020138 _____ () C:\Users\Preak\IP_Log_Data.js 2014-08-23 00:50 - 2013-05-28 22:33 - 00000000 ____D () C:\Users\Preak\AppData\Local\screenSHU 2014-08-23 00:49 - 2014-08-05 15:46 - 00010963 _____ () C:\Windows\setupact.log 2014-08-23 00:49 - 2014-07-07 14:51 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-08-23 00:49 - 2013-08-31 15:44 - 00000028 _____ () C:\Users\Preak\AppData\Roaming\Network Meter_Usage.ini 2014-08-23 00:49 - 2013-06-04 21:35 - 00000000 ____D () C:\ProgramData\VMware 2014-08-23 00:49 - 2013-04-11 19:58 - 00151552 _____ () C:\Windows\KMSEmulator.exe 2014-08-23 00:49 - 2013-04-10 16:38 - 00002982 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-08-23 00:49 - 2013-04-10 16:38 - 00000292 _____ () C:\Windows\Tasks\AutoKMS.job 2014-08-23 00:49 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-23 00:45 - 2014-05-16 20:38 - 00098590 _____ () C:\Windows\PFRO.log 2014-08-23 00:45 - 2013-04-18 21:44 - 00000000 ____D () C:\Users\postgres 2014-08-23 00:44 - 2013-09-03 23:32 - 00000000 ____D () C:\AdwCleaner 2014-08-23 00:38 - 2014-06-04 22:27 - 00126111 _____ () C:\Windows\DirectX.log 2014-08-23 00:33 - 2014-08-23 00:27 - 00468234 _____ () C:\Users\Preak\Desktop\sfcdetails.txt 2014-08-23 00:16 - 2013-09-18 00:37 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-22 22:43 - 2013-04-01 22:27 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\TS3Client 2014-08-22 22:01 - 2013-04-02 19:14 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\AIMP3 2014-08-22 21:05 - 2014-07-14 20:05 - 00000000 ____D () C:\Program Files (x86)\PKR 2014-08-22 18:14 - 2013-06-22 00:18 - 00000000 ____D () C:\Users\Preak\AppData\Local\Last.fm 2014-08-22 14:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-08-20 23:25 - 2013-10-07 17:18 - 00000000 ____D () C:\ProgramData\TEMP 2014-08-16 21:01 - 2014-08-16 21:01 - 00000000 ____D () C:\Users\Preak\Desktop\kopia penis 2014-08-16 20:22 - 2014-08-12 15:21 - 00032320 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETTBOH_305.SYS 2014-08-15 10:34 - 2014-08-15 10:34 - 00000000 ____D () C:\Users\Preak\AppData\Local\Risen3 2014-08-15 10:33 - 2014-08-15 10:33 - 00000770 _____ () C:\Users\Public\Desktop\Risen 3 - Titan Lords.lnk 2014-08-14 15:11 - 2013-06-04 21:35 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\VMware 2014-08-14 15:11 - 2013-06-04 21:35 - 00000000 ____D () C:\Users\Preak\AppData\Local\VMware 2014-08-13 14:43 - 2014-01-05 14:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-12 20:50 - 2014-05-16 20:38 - 04974280 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-12 15:23 - 2014-05-13 16:38 - 00078424 _____ () C:\Users\Preak\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-12 15:22 - 2014-08-12 15:22 - 00001226 _____ () C:\Users\Public\Desktop\ASRock eXtreme Tuner.lnk 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files (x86)\ASRock Utility 2014-08-12 15:21 - 2014-08-12 15:21 - 00016648 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETURPX.SYS 2014-08-12 15:21 - 2014-08-12 15:21 - 00001885 _____ () C:\Users\Public\Desktop\XFast USB.LNK 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\FNET 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\Program Files (x86)\XFastUSB 2014-08-11 16:28 - 2014-04-24 15:46 - 00000540 __RSH () C:\ProgramData\ntuser.pol 2014-08-09 12:56 - 2013-04-01 22:25 - 00000000 ____D () C:\Users\Preak\AppData\Local\TeamSpeak 3 Client 2014-08-08 23:03 - 2014-06-05 00:53 - 00020150 _____ () C:\Windows\unins000.dat 2014-08-08 23:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2014-08-08 22:57 - 2013-05-14 01:10 - 01684808 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-08-07 16:50 - 2014-08-07 16:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-06 20:15 - 2014-08-05 15:46 - 00001908 _____ () C:\Windows\diagwrn.xml 2014-08-06 20:15 - 2014-08-05 15:46 - 00001908 _____ () C:\Windows\diagerr.xml 2014-08-06 20:13 - 2014-08-05 15:46 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-06 20:13 - 2013-04-22 19:59 - 00000000 ____D () C:\Users\Preak\AppData\Local\PokerStars.EU 2014-08-05 14:55 - 2014-08-05 14:55 - 00000000 ____D () C:\Users\Preak\AppData\Local\e-academy Inc 2014-08-03 14:54 - 2014-08-03 12:44 - 00352614 _____ () C:\Windows\system32\sfcdetails.txt 2014-08-03 11:19 - 2014-08-03 11:18 - 00000000 ____D () C:\Users\Preak\Desktop\kopia 2014-08-02 22:50 - 2014-08-02 18:24 - 00003718 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-08-02 20:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-02 18:24 - 2014-08-02 18:24 - 00003476 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2014-08-02 18:24 - 2014-07-16 15:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-08-02 11:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-01 18:21 - 2014-08-01 18:21 - 00001126 _____ () C:\Users\Public\Desktop\MiNODLogin Esplora Licenze.lnk 2014-08-01 18:21 - 2014-08-01 18:21 - 00001120 _____ () C:\Users\Public\Desktop\Aggiorna ESET license.lnk 2014-07-31 16:01 - 2014-05-15 05:13 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\ObviousIdea 2014-07-30 22:22 - 2014-07-16 16:29 - 00000000 ____D () C:\Users\Preak\Documents\Visual Studio 2010 2014-07-30 22:14 - 2014-07-30 22:14 - 00105600 _____ () C:\Users\Preak\Desktop\save.sav 2014-07-30 17:47 - 2014-07-30 17:47 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\SKIDROW 2014-07-30 17:30 - 2014-07-30 17:30 - 00105368 _____ () C:\Users\1.save 2014-07-30 16:53 - 2014-07-19 13:40 - 00000000 ____D () C:\Trials Fusion 2014-07-30 15:36 - 2014-07-30 15:36 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\Wayforward Technologies 2014-07-29 18:46 - 2013-04-01 19:45 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\ASUS 2014-07-29 18:45 - 2014-07-29 18:45 - 00043701 _____ () C:\Windows\Cmicnfgp.ini.cfl 2014-07-29 18:45 - 2014-07-29 18:45 - 00000630 _____ () C:\Windows\Cmicnfgp.ini.imi 2014-07-29 18:45 - 2014-07-29 18:45 - 00000569 _____ () C:\Windows\system\Cmicnfgp.ini 2014-07-29 18:45 - 2013-04-01 19:45 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-07-29 18:45 - 2013-04-01 19:45 - 00123480 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-07-29 18:45 - 2013-04-01 19:41 - 00000140 _____ () C:\Windows\system\Dlap.pfx 2014-07-29 18:43 - 2014-07-29 18:42 - 00000000 ____D () C:\Program Files (x86)\Driver Fusion 2014-07-29 18:42 - 2014-07-29 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Fusion 2014-07-28 17:31 - 2013-04-01 18:51 - 00000000 ____D () C:\Users\Preak 2014-07-28 15:25 - 2014-07-19 13:42 - 00105920 _____ () C:\Users\1.sav.backup 2014-07-28 15:25 - 2014-07-19 13:41 - 00105920 _____ () C:\Users\1.sav 2014-07-28 11:54 - 2014-07-28 11:54 - 00000905 _____ () C:\Users\Public\Desktop\AIMP3.lnk 2014-07-28 11:54 - 2013-04-02 19:14 - 00000000 ____D () C:\Program Files (x86)\AIMP3 2014-07-28 11:46 - 2014-05-15 17:40 - 00000099 _____ () C:\Users\Preak\Desktop\Nowy dokument tekstowy (2).txt 2014-07-27 17:48 - 2013-04-02 01:07 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\BESTplayer 2014-07-24 15:14 - 2013-08-29 11:49 - 00000000 ____D () C:\ProgramData\Origin Files to move or delete: ==================== C:\Users\Preak\IP_Log_Data.js C:\Users\Preak\Network_Meter_Data.js ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-18 00:17 ==================== End Of Log ============================