Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Preak (administrator) on PREAK-PC on 01-09-2014 16:00:18 Running from C:\Users\Preak\Desktop\logi Platform: Windows 7 Enterprise Service Pack 1 (X64) OS Language: Angielski (Stany Zjednoczone) Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Andrea Electronics Corporation) C:\Windows\System32\AESRV64.EXE (Scarlet.Crush Productions) C:\Users\Preak\Desktop\ScpServer\bin\ScpService.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe () C:\Windows\SysWOW64\PnkBstrA.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\pg_ctl.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (VMware, Inc.) G:\vmware\vmware-authd.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\9.0\bin\postgres.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe () G:\vmware\vmware-hostd.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe () C:\Program Files (x86)\screenSHU\screenSHU.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe () C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Valve Corporation) G:\steam\Steam.exe (Valve Corporation) G:\steam\bin\steamwebhelper.exe (Valve Corporation) G:\steam\bin\steamwebhelper.exe (Valve Corporation) G:\steam\bin\steamwebhelper.exe (CMedia) C:\Program Files\UNi Xonar Audio\Customapp\AsusAudioCenter.exe (AIMP DevTeam) C:\Program Files (x86)\AIMP3\AIMP3.exe (Last.fm) C:\Program Files (x86)\Last.fm\Last.fm Scrobbler.exe (Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5618456 2013-09-12] (ESET) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8294680 2014-02-28] (Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [500736 2011-05-02] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated) HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5021448 2014-08-12] (FNet Co., Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [screenSHU] => C:\Program Files (x86)\screenSHU\screenSHU.exe [2112000 2013-09-04] () HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\Run: [uTorrent] => C:\Users\Preak\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-02] (BitTorrent Inc.) HKU\S-1-5-21-2973642986-523059004-888739316-1000\...\MountPoints2: {5b2ae33d-2f46-11e3-9cfd-005056c00008} - J:\setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aggiorna ESET license.lnk ShortcutTarget: Aggiorna ESET license.lnk -> C:\Program Files (x86)\ESET\MiNODLogin\launcher.exe (GuillerSoft) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Status Monitor.lnk ShortcutTarget: Status Monitor.lnk -> C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.172.224.160 89.231.1.206 FireFox: ======== FF ProfilePath: C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default FF NetworkProxy: "http", "67.43.32.187" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "type", 1 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll () FF Plugin: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @acestream.net/acestreamplugin,version=2.2.9-next -> C:\Users\Preak\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Preak\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc -> F:\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll (Ubisoft) FF Extension: AS Magic Player - C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default\Extensions\magicplayer@acestream.org [2014-08-23] FF Extension: No Name - C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default\Extensions\staged [2014-08-26] FF Extension: Greasemonkey - C:\Users\Preak\AppData\Roaming\Mozilla\Firefox\Profiles\5puzkh0m.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-03-16] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-04-02] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxp://www.google.com" CHR DefaultSearchKeyword: Default -> ACBE22567EA242DEE080383F4BA144B19CCE53673FB21147F28CF46D987F78CD CHR DefaultSearchURL: Default -> F589717AD101FB9A6168FB7B6C3DB125089890B214DAF97E93DEB2AD81E3E5EA CHR Profile: C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Przelewy24) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiicmmpkicnndkhlnnloilpgncbpkbjj [2014-08-07] CHR Extension: (Google Docs) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-01] CHR Extension: (Google Drive) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-01] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-25] CHR Extension: (YouTube) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-01] CHR Extension: (Adblock Plus) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-30] CHR Extension: (Google Search) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-01] CHR Extension: (Tampermonkey) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-03-16] CHR Extension: (Steam Market Filter) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\emdpoeanmcbopmmdomongbohbmiolmom [2014-03-14] CHR Extension: (eSports.pl (poczta)) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmohbfidjfncaapkeeihnjpejgbgpdgo [2013-06-13] CHR Extension: (NetBeans Connector) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafdlehgocfcodbgjnpecfajgkeejnaa [2013-12-05] CHR Extension: (The Grids) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgfgflhpelebngbkojdfjjekjnkgdcag [2013-05-28] CHR Extension: (Steam Market Auto-Agree) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlicldafjdigokihkkdlbpfgehihjodl [2014-03-16] CHR Extension: (Night Time In New York City) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek [2013-09-03] CHR Extension: (Steam Redirect Skipper) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\khmlfpmmbdnmknikgfhgkpejldimabap [2014-08-23] CHR Extension: (Window Resizer) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkelicaakdanhinjdeammmilcgefonfh [2013-04-08] CHR Extension: (Google Wallet) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30] CHR Extension: (ColorPick Eyedropper) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohcpnigalekghcmgcdcenkpelffpdolg [2013-10-07] CHR Extension: (Auto Refresh Plus) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilipfekkmncanaajkapbpancpelijih [2013-10-01] CHR Extension: (Gmail) - C:\Users\Preak\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-01] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AE64Filters; C:\Windows\system32\AESRV64.EXE [111616 2009-06-05] (Andrea Electronics Corporation) [File not signed] S4 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] () [File not signed] R2 Ds3Service; C:\Users\Preak\Desktop\ScpServer\bin\ScpService.exe [381952 2014-04-03] (Scarlet.Crush Productions) [File not signed] R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1337752 2013-09-12] (ESET) S4 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [163840 2013-02-13] (Brio) [File not signed] S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-09] () S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 VMAuthdService; G:\vmware\vmware-authd.exe [79872 2012-08-15] (VMware, Inc.) [File not signed] R2 VMwareHostd; G:\vmware\vmware-hostd.exe [15680000 2012-08-15] () [File not signed] S3 wampapache; f:\wamp\bin\apache\apache2.2.22\bin\httpd.exe [22016 2012-05-13] (Apache Software Foundation) [File not signed] S3 wampmysqld; f:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe [9693696 2012-04-19] () [File not signed] R2 postgresql-x64-9.0; C:/Program Files (x86)/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N "postgresql-x64-9.0" -D "C:/Program Files/PostgreSQL/9.0/data" -w [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [24840 2009-01-07] (IVT Corporation.) S3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [35848 2008-12-07] () R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc) S3 dpmconv; C:\Windows\System32\DRIVERS\dpmconv.sys [259072 2012-07-05] (SIEMENS AG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-10-07] (DT Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-08-16] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-08-12] (FNet Co., Ltd.) S3 hidusbf; C:\Windows\System32\DRIVERS\hidusbf.sys [7808 2013-12-14] (SweetLow) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [30112 2013-05-15] (REALiX(tm)) S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [5353888 2012-12-14] (Intel Corporation) [File not signed] S3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [31624 2008-07-02] (IVT Corporation.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2014-07-10] (http://libusb-win32.sourceforge.net) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation) S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [116264 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [19496 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [158760 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [34856 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [135208 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [151592 2009-05-25] (MCCI Corporation) S3 s7odpx2x64; C:\Windows\System32\DRIVERS\s7odpx2x64.sys [71168 2012-12-19] (SIEMENS AG) S3 s7oppinx64; C:\Windows\System32\DRIVERS\s7oppinx64.sys [107520 2012-07-24] (SIEMENS AG) S3 s7oserix64; C:\Windows\System32\Drivers\s7oserix64.sys [121856 2012-07-24] (SIEMENS AG) S3 s7osmcax64; C:\Windows\System32\DRIVERS\s7osmcax64.sys [199680 2012-07-24] (SIEMENS AG) S3 s7osobux64; C:\Windows\System32\DRIVERS\s7osobux64.sys [153600 2012-07-24] (SIEMENS AG) S3 s7otmcd64x; C:\Windows\System32\Drivers\s7otmcd64x.sys [199680 2012-07-24] (SIEMENS AG) S3 s7otranx64; C:\Windows\System32\DRIVERS\s7otranx64.sys [260096 2012-07-24] (SIEMENS AG) S3 s7otsadx64; C:\Windows\System32\DRIVERS\s7otsadx64.sys [196096 2012-07-24] (SIEMENS AG) S2 s7ousbu64x; C:\Windows\System32\DRIVERS\s7ousbu64x.sys [213504 2012-12-19] (SIEMENS AG) R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-09-18] (Duplex Secure Ltd.) S3 tizeqdrv; C:\Users\Preak\AppData\Roaming\TZAC2\tizeq64.sys [171704 2013-04-01] () S3 vsnl2ada; C:\Windows\System32\DRIVERS\vsnl2ada.sys [126976 2012-05-09] (SIEMENS AG) R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.) U3 a4qmsln0; C:\Windows\System32\Drivers\a4qmsln0.sys [0 ] (Advanced Micro Devices) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-01 15:54 - 2014-09-01 15:56 - 00000000 ____D () C:\TMP 2014-09-01 14:37 - 2014-09-01 14:37 - 00000000 ____D () C:\ProgramData\McAfee 2014-08-31 19:08 - 2014-08-31 19:08 - 00000000 _____ () C:\STF93CB.tmp 2014-08-31 16:22 - 2014-08-31 16:22 - 00000000 _____ () C:\STF6172.tmp 2014-08-31 13:33 - 2014-08-31 13:33 - 00000000 ____D () C:\ProgramData\XHEO INC 2014-08-31 13:33 - 2014-08-31 13:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Holdem Manager 2 2014-08-31 13:33 - 2014-08-09 13:48 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\HoldemManager 2014-08-31 13:32 - 2014-08-31 13:33 - 00000000 ____D () C:\Program Files (x86)\PSQLINSTALL 2014-08-31 13:32 - 2014-08-31 13:33 - 00000000 ____D () C:\Program Files (x86)\Holdem Manager 2 2014-08-31 13:28 - 2014-08-31 13:28 - 00000000 _____ () C:\Windows\HMHud.INI 2014-08-31 13:19 - 2014-08-31 13:28 - 00034656 _____ () C:\blitzerr.txt 2014-08-31 13:18 - 2014-08-31 13:21 - 00000000 ____D () C:\HMArchive 2014-08-31 13:18 - 2014-08-31 13:18 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\HEM Data 2014-08-31 13:18 - 2014-08-31 13:18 - 00000000 ____D () C:\Users\Preak\AppData\Local\In The Money 2014-08-31 13:02 - 2014-08-31 13:02 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\postgresql 2014-08-31 12:58 - 2014-08-31 12:58 - 00000000 ____D () C:\Program Files (x86)\RVG Software 2014-08-31 01:14 - 2014-08-31 01:14 - 00000000 _____ () C:\STF8D02.tmp 2014-08-31 00:41 - 2014-08-31 00:41 - 00000000 _____ () C:\STFCEE0.tmp 2014-08-30 21:30 - 2014-08-30 21:30 - 00000000 _____ () C:\STFAF78.tmp 2014-08-30 21:27 - 2009-10-26 09:16 - 00034816 _____ () C:\Users\Preak\Desktop\BORDERLANDS_WW.mdf 2014-08-30 21:27 - 2009-10-23 16:47 - 00033406 _____ () C:\Users\Preak\Desktop\BORDERLANDS_WW.mds 2014-08-29 19:53 - 2014-08-29 19:53 - 00000000 _____ () C:\STFD129.tmp 2014-08-28 22:11 - 2014-08-28 22:11 - 00000000 _____ () C:\STFEEFE.tmp 2014-08-28 18:47 - 2014-08-28 18:48 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\FMRTE14 2014-08-28 18:45 - 2014-08-28 18:45 - 00000654 _____ () C:\Users\Public\Desktop\FMRTE 14.lnk 2014-08-28 18:43 - 2014-08-28 18:43 - 00000000 _____ () C:\STF280F.tmp 2014-08-27 14:51 - 2014-08-27 14:59 - 00000000 ____D () C:\Users\Preak\Documents\The Crew 2014-08-27 14:51 - 2014-08-27 14:55 - 00000000 ____D () C:\Users\Preak\Documents\ProfileCache 2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\Users\Preak\AppData\Local\Ubisoft 2014-08-26 21:51 - 2014-08-26 21:51 - 00000000 ____D () C:\Users\Preak\AppData\Local\Skype 2014-08-26 21:51 - 2014-08-26 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-26 19:03 - 2014-08-26 19:03 - 00000231 _____ () C:\Users\Preak\Desktop\The Crew (Beta).url 2014-08-26 19:00 - 2014-08-26 19:00 - 00001201 _____ () C:\Users\Preak\Desktop\Uplay.lnk 2014-08-24 23:11 - 2014-09-01 14:58 - 00000000 ____D () C:\ProgramData\TEMP 2014-08-23 00:27 - 2014-08-23 00:33 - 00468234 _____ () C:\Users\Preak\Desktop\sfcdetails.txt 2014-08-15 10:34 - 2014-08-15 10:34 - 00000000 ____D () C:\Users\Preak\AppData\Local\Risen3 2014-08-15 10:33 - 2014-08-15 10:33 - 00000770 _____ () C:\Users\Public\Desktop\Risen 3 - Titan Lords.lnk 2014-08-12 15:23 - 2012-02-27 03:01 - 00788760 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys 2014-08-12 15:23 - 2012-02-27 03:01 - 00356120 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys 2014-08-12 15:23 - 2012-02-27 03:01 - 00016152 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files (x86)\ASRock Utility 2014-08-12 15:22 - 2012-01-13 12:52 - 00031016 _____ (ASRock Inc.) C:\Windows\system32\Drivers\AsrRamDisk.sys 2014-08-12 15:21 - 2014-08-16 20:22 - 00032320 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETTBOH_305.SYS 2014-08-12 15:21 - 2014-08-12 15:21 - 00016648 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETURPX.SYS 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\FNET 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\Program Files (x86)\XFastUSB 2014-08-08 23:03 - 2007-03-09 01:52 - 00394752 _____ () C:\Windows\SysWOW64\cygwinb19.dll 2014-08-08 23:03 - 2006-04-10 22:41 - 01066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl32.ocx 2014-08-07 16:50 - 2014-08-07 16:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-05 15:46 - 2014-09-01 14:57 - 00013595 _____ () C:\Windows\setupact.log 2014-08-05 15:46 - 2014-08-06 20:15 - 00001908 _____ () C:\Windows\diagwrn.xml 2014-08-05 15:46 - 2014-08-06 20:15 - 00001908 _____ () C:\Windows\diagerr.xml 2014-08-05 15:46 - 2014-08-06 20:13 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-05 14:55 - 2014-08-05 14:55 - 00000000 ____D () C:\Users\Preak\AppData\Local\e-academy Inc 2014-08-03 14:50 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-08-03 14:50 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-08-03 14:49 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-08-03 14:36 - 2014-09-01 16:00 - 00000000 ____D () C:\Users\Preak\Desktop\logi 2014-08-03 14:34 - 2014-09-01 16:00 - 00000000 ____D () C:\FRST 2014-08-03 13:49 - 2014-09-01 15:53 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XInput9_1_0.dll 2014-08-03 12:44 - 2014-08-03 14:54 - 00352614 _____ () C:\Windows\system32\sfcdetails.txt 2014-08-03 12:20 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-08-03 12:20 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2014-08-03 12:20 - 2013-01-13 22:08 - 01504768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2014-08-03 12:20 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2014-08-03 12:20 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2014-08-03 12:20 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2014-08-03 12:20 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2014-08-03 12:20 - 2010-11-21 05:24 - 01828352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll 2014-08-03 12:19 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-08-03 12:19 - 2006-03-31 12:49 - 00007927 _____ () C:\Windows\SysWOW64\xinput1_1_x86.cat 2014-08-03 12:19 - 2006-03-31 12:49 - 00007927 _____ () C:\Windows\SysWOW64\xinput1_1_x64.cat 2014-08-03 12:19 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-08-02 18:24 - 2014-08-02 22:50 - 00003718 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-08-02 18:24 - 2014-08-02 18:24 - 00003476 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-01 16:00 - 2014-08-03 14:36 - 00000000 ____D () C:\Users\Preak\Desktop\logi 2014-09-01 16:00 - 2014-08-03 14:34 - 00000000 ____D () C:\FRST 2014-09-01 16:00 - 2013-08-30 15:00 - 00330011 _____ () C:\Users\Preak\Network_Meter_Data.js 2014-09-01 16:00 - 2013-04-02 19:14 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\AIMP3 2014-09-01 15:58 - 2013-06-22 00:18 - 00000000 ____D () C:\Users\Preak\AppData\Local\Last.fm 2014-09-01 15:56 - 2014-09-01 15:54 - 00000000 ____D () C:\TMP 2014-09-01 15:54 - 2014-06-05 01:31 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\XInput9_1_0.dll 2014-09-01 15:53 - 2014-08-03 13:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XInput9_1_0.dll 2014-09-01 15:51 - 2009-07-14 06:45 - 00008240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-01 15:51 - 2009-07-14 06:45 - 00008240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-01 15:44 - 2013-04-04 21:12 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\vlc 2014-09-01 15:43 - 2014-06-17 05:38 - 00001048 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf89dd969508d3.job 2014-09-01 15:06 - 2014-06-05 00:53 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-01 14:58 - 2014-08-24 23:11 - 00000000 ____D () C:\ProgramData\TEMP 2014-09-01 14:57 - 2014-08-05 15:46 - 00013595 _____ () C:\Windows\setupact.log 2014-09-01 14:55 - 2014-06-04 22:27 - 00182893 _____ () C:\Windows\DirectX.log 2014-09-01 14:54 - 2013-08-29 11:49 - 00000000 ____D () C:\ProgramData\Origin 2014-09-01 14:41 - 2013-04-02 18:38 - 00754136 _____ () C:\Windows\system32\perfh015.dat 2014-09-01 14:41 - 2013-04-02 18:38 - 00164038 _____ () C:\Windows\system32\perfc015.dat 2014-09-01 14:41 - 2009-07-14 07:13 - 01713170 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-01 14:37 - 2014-09-01 14:37 - 00000000 ____D () C:\ProgramData\McAfee 2014-09-01 14:37 - 2014-06-05 00:53 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-01 14:37 - 2013-04-01 19:08 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-01 14:37 - 2013-04-01 19:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-01 14:35 - 2013-04-01 20:30 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\uTorrent 2014-09-01 14:34 - 2014-02-11 22:51 - 00021202 _____ () C:\Users\Preak\IP_Log_Data.js 2014-09-01 14:34 - 2013-08-29 02:58 - 00001044 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cea452e2e8c39c.job 2014-09-01 14:34 - 2013-05-28 22:33 - 00000000 ____D () C:\Users\Preak\AppData\Local\screenSHU 2014-09-01 14:34 - 2013-04-01 18:51 - 01344727 _____ () C:\Windows\WindowsUpdate.log 2014-09-01 14:33 - 2014-07-07 14:51 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-09-01 14:33 - 2013-06-04 21:35 - 00000000 ____D () C:\ProgramData\VMware 2014-09-01 14:33 - 2013-04-18 21:44 - 00000000 ____D () C:\Users\postgres 2014-09-01 14:33 - 2013-04-11 19:58 - 00151552 _____ () C:\Windows\KMSEmulator.exe 2014-09-01 14:33 - 2013-04-10 16:38 - 00002982 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-09-01 14:33 - 2013-04-10 16:38 - 00000292 _____ () C:\Windows\Tasks\AutoKMS.job 2014-09-01 14:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-01 07:52 - 2013-08-31 15:44 - 00000028 _____ () C:\Users\Preak\AppData\Roaming\Network Meter_Usage.ini 2014-09-01 04:49 - 2014-01-24 21:23 - 00000388 _____ () C:\Windows\Tasks\update-S-1-5-21-2973642986-523059004-888739316-1000.job 2014-09-01 00:39 - 2014-01-22 02:11 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\Skype 2014-08-31 22:50 - 2013-08-31 16:12 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\.ACEStream 2014-08-31 20:02 - 2013-05-26 22:05 - 00000000 ____D () C:\Users\Preak\AppData\Local\CrashDumps 2014-08-31 19:08 - 2014-08-31 19:08 - 00000000 _____ () C:\STF93CB.tmp 2014-08-31 17:55 - 2013-05-16 23:22 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{1E04A170-3DC2-480D-8FDF-4E1A6EAF853D} 2014-08-31 16:29 - 2013-10-07 13:46 - 00007596 _____ () C:\Users\Preak\AppData\Local\Resmon.ResmonCfg 2014-08-31 16:22 - 2014-08-31 16:22 - 00000000 _____ () C:\STF6172.tmp 2014-08-31 13:33 - 2014-08-31 13:33 - 00000000 ____D () C:\ProgramData\XHEO INC 2014-08-31 13:33 - 2014-08-31 13:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Holdem Manager 2 2014-08-31 13:33 - 2014-08-31 13:32 - 00000000 ____D () C:\Program Files (x86)\PSQLINSTALL 2014-08-31 13:33 - 2014-08-31 13:32 - 00000000 ____D () C:\Program Files (x86)\Holdem Manager 2 2014-08-31 13:28 - 2014-08-31 13:28 - 00000000 _____ () C:\Windows\HMHud.INI 2014-08-31 13:28 - 2014-08-31 13:19 - 00034656 _____ () C:\blitzerr.txt 2014-08-31 13:21 - 2014-08-31 13:18 - 00000000 ____D () C:\HMArchive 2014-08-31 13:18 - 2014-08-31 13:18 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\HEM Data 2014-08-31 13:18 - 2014-08-31 13:18 - 00000000 ____D () C:\Users\Preak\AppData\Local\In The Money 2014-08-31 13:02 - 2014-08-31 13:02 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\postgresql 2014-08-31 13:00 - 2013-04-18 21:36 - 00000000 ____D () C:\Program Files (x86)\PokerTracker 4 2014-08-31 12:58 - 2014-08-31 12:58 - 00000000 ____D () C:\Program Files (x86)\RVG Software 2014-08-31 01:14 - 2014-08-31 01:14 - 00000000 _____ () C:\STF8D02.tmp 2014-08-31 00:41 - 2014-08-31 00:41 - 00000000 _____ () C:\STFCEE0.tmp 2014-08-30 21:30 - 2014-08-30 21:30 - 00000000 _____ () C:\STFAF78.tmp 2014-08-30 16:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-08-29 19:53 - 2014-08-29 19:53 - 00000000 _____ () C:\STFD129.tmp 2014-08-29 17:48 - 2013-04-01 22:27 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\TS3Client 2014-08-28 22:11 - 2014-08-28 22:11 - 00000000 _____ () C:\STFEEFE.tmp 2014-08-28 18:48 - 2014-08-28 18:47 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\FMRTE14 2014-08-28 18:45 - 2014-08-28 18:45 - 00000654 _____ () C:\Users\Public\Desktop\FMRTE 14.lnk 2014-08-28 18:43 - 2014-08-28 18:43 - 00000000 _____ () C:\STF280F.tmp 2014-08-27 14:59 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Preak\Documents\The Crew 2014-08-27 14:55 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Preak\Documents\ProfileCache 2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\Users\Preak\AppData\Local\Ubisoft 2014-08-27 14:50 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-08-26 21:51 - 2014-08-26 21:51 - 00000000 ____D () C:\Users\Preak\AppData\Local\Skype 2014-08-26 21:51 - 2014-08-26 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-26 21:51 - 2014-01-22 02:11 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-08-26 21:51 - 2014-01-22 02:11 - 00000000 ____D () C:\ProgramData\Skype 2014-08-26 19:03 - 2014-08-26 19:03 - 00000231 _____ () C:\Users\Preak\Desktop\The Crew (Beta).url 2014-08-26 19:02 - 2013-04-01 18:51 - 00000000 ____D () C:\Users\Preak 2014-08-26 19:00 - 2014-08-26 19:00 - 00001201 _____ () C:\Users\Preak\Desktop\Uplay.lnk 2014-08-24 22:09 - 2014-05-16 20:38 - 00101392 _____ () C:\Windows\PFRO.log 2014-08-24 22:07 - 2014-07-17 00:29 - 00000000 ____D () C:\Windows\System32\Tasks\XonarSwitch 2014-08-24 22:06 - 2014-06-03 19:29 - 00000000 ____D () C:\ProgramData\Oracle 2014-08-24 22:03 - 2014-06-03 19:28 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-08-24 22:03 - 2013-10-07 13:33 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-08-24 22:03 - 2013-10-07 13:33 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-08-24 22:03 - 2013-10-07 13:33 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-08-24 22:03 - 2013-10-07 13:33 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-08-24 22:03 - 2013-10-07 13:33 - 00000000 ____D () C:\Program Files\Java 2014-08-24 22:03 - 2013-04-02 18:47 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-08-24 22:03 - 2013-04-02 18:47 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-08-24 22:03 - 2013-04-02 18:47 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-08-24 22:03 - 2013-04-02 18:47 - 00000000 ____D () C:\Program Files (x86)\Java 2014-08-24 02:45 - 2014-05-15 05:13 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\ObviousIdea 2014-08-23 21:52 - 2013-04-18 21:37 - 00000000 ____D () C:\Users\Preak\AppData\Local\PokerTracker 4 2014-08-23 21:51 - 2014-01-06 16:25 - 00001074 _____ () C:\Users\postgres\Desktop\PokerTracker 4.lnk 2014-08-23 01:09 - 2013-08-31 15:27 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\ACEStream 2014-08-23 00:33 - 2014-08-23 00:27 - 00468234 _____ () C:\Users\Preak\Desktop\sfcdetails.txt 2014-08-23 00:16 - 2013-09-18 00:37 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-22 21:05 - 2014-07-14 20:05 - 00000000 ____D () C:\Program Files (x86)\PKR 2014-08-16 20:22 - 2014-08-12 15:21 - 00032320 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETTBOH_305.SYS 2014-08-15 10:34 - 2014-08-15 10:34 - 00000000 ____D () C:\Users\Preak\AppData\Local\Risen3 2014-08-15 10:33 - 2014-08-15 10:33 - 00000770 _____ () C:\Users\Public\Desktop\Risen 3 - Titan Lords.lnk 2014-08-14 15:11 - 2013-06-04 21:35 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\VMware 2014-08-14 15:11 - 2013-06-04 21:35 - 00000000 ____D () C:\Users\Preak\AppData\Local\VMware 2014-08-13 14:43 - 2014-01-05 14:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-12 20:50 - 2014-05-16 20:38 - 04974280 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-12 15:23 - 2014-05-13 16:38 - 00078424 _____ () C:\Users\Preak\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files\ASRock Utility 2014-08-12 15:22 - 2014-08-12 15:22 - 00000000 ____D () C:\Program Files (x86)\ASRock Utility 2014-08-12 15:21 - 2014-08-12 15:21 - 00016648 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETURPX.SYS 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\ProgramData\FNET 2014-08-12 15:21 - 2014-08-12 15:21 - 00000000 ____D () C:\Program Files (x86)\XFastUSB 2014-08-11 16:28 - 2014-04-24 15:46 - 00000540 __RSH () C:\ProgramData\ntuser.pol 2014-08-09 13:48 - 2014-08-31 13:33 - 00000000 ____D () C:\Users\Preak\AppData\Roaming\HoldemManager 2014-08-09 12:56 - 2013-04-01 22:25 - 00000000 ____D () C:\Users\Preak\AppData\Local\TeamSpeak 3 Client 2014-08-08 23:03 - 2014-06-05 00:53 - 00020150 _____ () C:\Windows\unins000.dat 2014-08-08 23:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2014-08-08 22:57 - 2013-05-14 01:10 - 01684808 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-08-07 16:50 - 2014-08-07 16:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-06 20:15 - 2014-08-05 15:46 - 00001908 _____ () C:\Windows\diagwrn.xml 2014-08-06 20:15 - 2014-08-05 15:46 - 00001908 _____ () C:\Windows\diagerr.xml 2014-08-06 20:13 - 2014-08-05 15:46 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-06 20:13 - 2013-04-22 19:59 - 00000000 ____D () C:\Users\Preak\AppData\Local\PokerStars.EU 2014-08-05 14:55 - 2014-08-05 14:55 - 00000000 ____D () C:\Users\Preak\AppData\Local\e-academy Inc 2014-08-03 14:54 - 2014-08-03 12:44 - 00352614 _____ () C:\Windows\system32\sfcdetails.txt 2014-08-02 22:50 - 2014-08-02 18:24 - 00003718 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-08-02 20:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-02 18:24 - 2014-08-02 18:24 - 00003476 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2014-08-02 18:24 - 2014-07-16 15:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-08-02 11:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF Files to move or delete: ==================== C:\Users\Preak\IP_Log_Data.js C:\Users\Preak\Network_Meter_Data.js Some content of TEMP: ==================== C:\Users\Preak\AppData\Local\Temp\License Authorization.exe C:\Users\Preak\AppData\Local\Temp\SkypeSetup.exe C:\Users\Preak\AppData\Local\Temp\vlc-2.1.5-win32.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION! LastRegBack: 2014-08-27 00:54 ==================== End Of Log ============================