Hi, Gringo
Thanks for fast answer
Here is:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-07-2013 01
Ran by SYSTEM on 10-07-2013 03:02:21
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-10-02] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM\...\Run: [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [IgfxTray] - C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] - C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [UIExec] - "C:\Program Files\T-Mobile Internet Manager\UIExec.exe" [132608 2010-02-23] ()
HKLM\...\Run: [MSC] - "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [997920 2011-06-15] (Microsoft Corporation)
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1183744 2007-02-21] (Analog Devices, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-27] (Synaptics, Inc.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe, [x]
HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [ 2009-07-13] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [ 2009-07-13] (Microsoft Corporation)
HKU\Martin\...\Run: [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Martin\...\Run: [Advanced SystemCare 6] - "C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart [ 2013-01-15] (IObit)
HKU\Martin\...\Winlogon: [Shell] explorer.exe,C:\Users\Martin\AppData\Roaming\skype.dat <==== ATTENTION
Startup: C:\ProgramData\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
========================== Services (Whitelisted) =================
S2 AdvancedSystemCareService6; C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe [465216 2013-01-15] (IObit)
S2 MsMpSvc; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-27] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [208944 2011-04-27] (Microsoft Corporation)
S2 UI Assistant Service; C:\Program Files\T-Mobile Internet Manager\AssistantServices.exe [241664 2010-02-23] ()
==================== Drivers (Whitelisted) ====================
S3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [219352 2009-06-05] (Intel Corporation)
S3 GemCCID; C:\Windows\System32\Drivers\GemCCID.sys [89600 2009-08-10] (Gemalto)
S1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
S3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-04-18] (Microsoft Corporation)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [801896 2011-04-08] (Realtek Semiconductor Corporation )
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-10 03:01 - 2013-07-10 03:01 - 00000000 ____D C:\FRST
2013-07-09 16:25 - 2013-07-09 16:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\IObit
2013-07-09 16:25 - 2013-07-09 16:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\IObit
==================== One Month Modified Files and Folders =======
2013-07-10 03:01 - 2013-07-10 03:01 - 00000000 ____D C:\FRST
2013-07-09 16:45 - 2013-05-13 00:23 - 00000004 ____A C:\Users\Martin\AppData\Roaming\skype.ini
2013-07-09 16:45 - 2012-01-31 01:17 - 01091141 ____A C:\Windows\WindowsUpdate.log
2013-07-09 16:44 - 2012-02-01 09:02 - 00000936 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-09 16:35 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-09 16:35 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-09 16:32 - 2012-01-31 01:24 - 00330874 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-09 16:27 - 2013-03-17 06:19 - 00010303 ____A C:\Windows\setupact.log
2013-07-09 16:27 - 2012-02-01 09:02 - 00000932 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-09 16:27 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-09 16:25 - 2013-07-09 16:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\IObit
2013-07-09 16:25 - 2013-07-09 16:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\IObit
Files to move or delete:
====================
C:\Users\Martin\AppData\Roaming\skype.dat
C:\Users\Martin\AppData\Roaming\skype.ini
C:\Users\Martin\Application Data\skype.dat
C:\Users\Martin\Application Data\skype.ini
==================== Known DLLs (Whitelisted) ============
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-05-09 06:40:55
Restore point made on: 2013-07-09 14:03:23
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 1015.3 MB
Available physical RAM: 648 MB
Total Pagefile: 1015.3 MB
Available Pagefile: 656.78 MB
Total Virtual: 2047.88 MB
Available Virtual: 1936.05 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:48.83 GB) (Free:22.8 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (D: disc) (Fixed) (Total:62.95 GB) (Free:59.17 GB) NTFS
Drive f: (ELOPAK 2GB) (Removable) (Total:1.79 GB) (Free:1.79 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 4B824628)
Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=63 GB) - (Type=OF Extended)
========================================================
Disk: 1 (Size: 2 GB) (Disk ID: 003D2A91)
Partition 1: (Active) - (Size=2 GB) - (Type=0B)
LastRegBack: 2013-07-09 13:58
==================== End Of Log ============================
Edited by Damba, 09 July 2013 - 09:42 PM.