Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Nasty malware ! [Solved]

malware

  • This topic is locked This topic is locked

#1
Andreib18

Andreib18

    Member

  • Member
  • PipPipPip
  • 100 posts

My pc got infested after i just plug in a thumd drive that contact a pc being infested   and want to format it.I run malware animalware and antirootkit with no results>here is otl log

 

 

OTL logfile created on: 8/3/2014 12:21:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\andrei\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 50.53% Memory free
8.00 Gb Paging File | 5.58 Gb Available in Paging File | 69.82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97.66 Gb Total Space | 48.66 Gb Free Space | 49.83% Space Free | Partition Type: NTFS
Drive D: | 368.01 Gb Total Space | 98.74 Gb Free Space | 26.83% Space Free | Partition Type: NTFS
 
Computer Name: ANDREI-PC | User Name: andrei | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/08/03 00:12:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\andrei\Downloads\OTL.exe
PRC - [2014/08/02 23:59:48 | 014,349,744 | ---- | M] (Malwarebytes Corp.) -- C:\Users\andrei\Downloads\mbar-1.07.0.1012.exe
PRC - [2014/08/02 23:53:39 | 000,132,096 | ---- | M] (Microsoft) -- C:\Users\andrei\AppData\Roaming\copy1.exe
PRC - [2014/07/15 12:24:50 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/07/06 16:28:46 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2014/06/23 03:41:29 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
PRC - [2014/06/03 07:44:21 | 001,184,056 | ---- | M] (Malwarebytes Corporation) -- C:\Users\andrei\Desktop\mbar\mbar.exe
PRC - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/05/12 07:24:34 | 006,970,168 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014/05/08 16:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/02/15 07:55:24 | 000,311,616 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013/11/19 00:36:38 | 000,087,368 | ---- | M] (Nero AG) -- C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
PRC - [2013/10/18 01:27:02 | 000,166,912 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2013/08/27 22:42:50 | 000,358,480 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2013/08/27 22:42:48 | 000,111,696 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
PRC - [2013/08/27 22:42:14 | 000,437,328 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2013/08/27 21:50:10 | 000,086,096 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
PRC - [2012/12/13 09:41:26 | 001,634,304 | ---- | M] (CMedia) -- C:\Program Files\UNi Xonar Audio\Customapp\AsusAudioCenter.exe
PRC - [2010/11/21 06:24:03 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2008/07/11 16:04:22 | 000,200,704 | ---- | M] () -- C:\Windows\SysWOW64\HsMgr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/07/15 12:24:48 | 000,353,096 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppgooglenaclpluginchrome.dll
MOD - [2014/07/15 12:24:46 | 014,664,008 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll
MOD - [2014/07/15 12:24:44 | 008,537,928 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll
MOD - [2014/07/15 12:24:38 | 000,718,664 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
MOD - [2014/07/15 12:24:36 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll
MOD - [2014/07/15 12:24:35 | 001,732,936 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
MOD - [2012/06/06 10:56:50 | 000,143,360 | ---- | M] () -- C:\Program Files\UNi Xonar Audio\Customapp\VmixP8.dll
MOD - [2010/11/21 06:51:49 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
MOD - [2010/11/21 06:51:24 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
MOD - [2010/11/21 06:48:49 | 012,432,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
MOD - [2010/11/21 06:48:42 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
MOD - [2010/11/21 06:48:25 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
MOD - [2010/11/21 06:48:22 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
MOD - [2010/11/21 06:48:21 | 007,963,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
MOD - [2010/11/21 06:48:14 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
MOD - [2008/07/11 16:04:22 | 000,200,704 | ---- | M] () -- C:\Windows\SysWOW64\HsMgr.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/08/02 23:31:51 | 000,127,752 | ---- | M] (SurfRight B.V.) [Auto | Running] -- C:\Program Files\HitmanPro\hmpsched.exe -- (HitmanProScheduler)
SRV:64bit: - [2012/05/04 14:33:20 | 000,027,760 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV:64bit: - [2009/07/14 04:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 04:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/07/16 05:28:18 | 000,542,912 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/07/09 01:37:24 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/07/06 16:28:46 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014/05/08 16:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/19 00:36:38 | 000,087,368 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe -- (HTCMonitorService)
SRV - [2013/10/18 01:27:02 | 000,166,912 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2013/08/27 22:42:50 | 000,358,480 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2013/08/27 22:42:14 | 000,437,328 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2013/08/27 22:09:34 | 014,401,104 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe -- (VMwareHostd)
SRV - [2013/08/27 21:50:10 | 000,086,096 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2013/08/27 09:33:42 | 000,904,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2012/07/09 10:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 00:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/08/03 00:01:20 | 000,092,888 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV:64bit: - [2014/08/03 00:01:08 | 000,079,064 | ---- | M] (Malwarebytes Corporation) [Kernel | Boot | Unknown] -- C:\Windows\SysNative\drivers\oyjmgew.sys -- (wvuqgp)
DRV:64bit: - [2014/08/02 23:51:52 | 000,122,584 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014/08/02 23:43:31 | 000,032,512 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hitmanpro37.sys -- (hitmanpro37)
DRV:64bit: - [2014/05/12 07:26:10 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/05/12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2014/04/15 19:55:49 | 000,017,280 | ---- | M] (Scott) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys -- (awUSB)
DRV:64bit: - [2014/04/12 20:25:00 | 000,239,616 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2014/03/30 09:26:02 | 000,129,944 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2013/12/26 08:41:40 | 000,206,136 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2013/12/26 08:41:40 | 000,108,856 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013/10/18 01:27:02 | 000,036,928 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2013/08/27 22:42:46 | 000,030,800 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2013/08/27 22:42:20 | 000,064,080 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2013/08/27 22:42:02 | 000,046,160 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2013/08/27 22:42:02 | 000,020,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2013/08/27 09:33:30 | 000,053,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2013/08/27 09:33:26 | 000,038,456 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2013/08/16 04:25:16 | 000,073,296 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vsock.sys -- (vsock)
DRV:64bit: - [2013/08/16 04:25:12 | 000,085,584 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2013/06/28 21:45:00 | 000,036,352 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandnetmodem64.sys -- (ANDNetModem)
DRV:64bit: - [2013/04/19 02:14:12 | 000,029,184 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandnetdiag64.sys -- (AndNetDiag)
DRV:64bit: - [2013/04/11 19:21:08 | 002,734,080 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cmudaxp.sys -- (cmudaxp)
DRV:64bit: - [2012/05/04 14:33:12 | 002,196,592 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2012/04/25 05:08:00 | 000,118,272 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qcusbser.sys -- (qcusbser)
DRV:64bit: - [2010/11/21 06:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 06:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 06:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 06:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 06:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 06:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 06:23:48 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010/11/21 06:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010/11/21 06:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 06:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/21 06:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/08/02 03:00:00 | 000,031,744 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandadb.sys -- (androidusb)
DRV:64bit: - [2010/03/09 14:08:36 | 000,121,800 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HtcVComV64.sys -- (HtcVCom32)
DRV:64bit: - [2009/11/03 04:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/07/14 04:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 04:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 04:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 04:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 23:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 23:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 23:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 23:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2014/08/02 23:23:36 | 000,029,160 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\Windows\SysWOW64\drivers\TrueSight.sys -- (TrueSight)
DRV - [2014/06/10 09:04:42 | 000,013,480 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2009/07/14 04:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 13 19 37 EF 8F 98 CF 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\andrei\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Error reading preferences file
CHR - Extension: Reverse Youtube Playlist = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhonbaagcobjdmbocblbebcmbmmbfmi\1.0_0\
CHR - Extension: Google Docs = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Reverse Playback for YouTube = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmkcmigpoihikjdbclmhgcgdckcfcjid\0.0.1.73_0\
CHR - Extension: Google Search = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: IE Tab = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.7.24.1_0\ietab_nm_
CHR - Extension: IE Tab = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.7.24.1_0\
CHR - Extension: Google Wallet = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2009/06/11 00:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4 - HKCU..\Run: [eb4b40a5d7e90fb7bb1aadd5beab440b] C:\Users\andrei\AppData\Roaming\copy1.exe (Microsoft)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eb4b40a5d7e90fb7bb1aadd5beab440b.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.ease...oad/SOPCORE.CAB (SopCore Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{198DD62B-EF02-418B-B005-619F08C69779}: DhcpNameServer = 192.168.10.1
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1c1f6350-f18c-11e3-aa60-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{1c1f6350-f18c-11e3-aa60-005056c00008}\Shell\AutoRun\command - "" = F:\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\{1c1f63ba-f18c-11e3-aa60-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{1c1f63ba-f18c-11e3-aa60-005056c00008}\Shell\AutoRun\command - "" = F:\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\{9a07efe1-c3ec-11e3-a3a6-001966e78996}\Shell - "" = AutoRun
O33 - MountPoints2\{9a07efe1-c3ec-11e3-a3a6-001966e78996}\Shell\AutoRun\command - "" = E:\LGAutoRun.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/08/03 00:01:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/08/03 00:01:18 | 000,000,000 | ---D | C] -- C:\Users\andrei\Desktop\mbar
[2014/08/03 00:01:08 | 000,079,064 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\oyjmgew.sys
[2014/08/02 23:53:39 | 000,132,096 | ---- | C] (Microsoft) -- C:\Users\andrei\AppData\Roaming\copy1.exe
[2014/08/02 23:31:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2014/08/02 23:31:09 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2014/08/02 23:29:12 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014/08/02 23:27:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hitman Pro 3.5
[2014/08/02 23:23:27 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2014/08/02 23:12:28 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/08/02 23:11:01 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/08/02 21:27:09 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\foobar2000
[2014/08/02 21:26:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\foobar2000
[2014/08/02 12:09:24 | 007,946,240 | ---- | C] (C-Media Corporation) -- C:\Windows\SysWow64\CmiCnfgp.dll
[2014/08/02 12:09:24 | 000,465,408 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysNative\cmasiopx.dll
[2014/08/02 12:09:24 | 000,303,104 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\cmasiop.dll
[2014/08/02 12:09:24 | 000,212,992 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\HsSrv2.dll
[2014/08/02 12:09:24 | 000,200,704 | ---- | C] (C-Media) -- C:\Windows\SysWow64\Cmpaoxy.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\System\HsSrv642.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\System\HsSrv64.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (CMedia Electronics Inc.) -- C:\Windows\SysWow64\Cm_Oal.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (CMedia Electronics Inc.) -- C:\Windows\SysNative\Cm_Oal.dll
[2014/08/02 12:09:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UNi Xonar Audio
[2014/08/02 12:09:21 | 000,000,000 | ---D | C] -- C:\Program Files\UNi Xonar Audio
[2014/08/02 12:08:48 | 002,734,080 | ---- | C] (C-Media Inc) -- C:\Windows\SysNative\drivers\cmudaxp.sys
[2014/08/02 12:08:48 | 000,315,392 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\CmiFltr.dll
[2014/08/02 12:08:48 | 000,315,392 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\System\CmiFltr.dll
[2014/08/02 12:08:48 | 000,032,768 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysNative\cmudaxp.dll
[2014/08/02 11:44:09 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\ASUS
[2014/08/02 11:43:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Xonar DG Audio
[2014/08/02 11:43:55 | 000,000,000 | ---D | C] -- C:\Program Files\ASUS Xonar DG Audio
[2014/08/02 11:36:53 | 000,212,992 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\HsSrv.dll
[2014/07/26 22:15:41 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
[2014/07/26 22:15:41 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\TransMac
[2014/07/26 22:15:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TransMac
[2014/07/26 15:10:44 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\PowerISO
[2014/07/23 05:09:07 | 000,000,000 | ---D | C] -- C:\Users\andrei\Desktop\paste
[2014/07/23 03:21:13 | 000,000,000 | ---D | C] -- C:\Users\andrei\poze
[2014/07/23 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\PandoraRecovery
[2014/07/23 02:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pandora Recovery
[2014/07/23 02:48:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pandora Recovery
[2014/07/23 02:34:56 | 000,000,000 | ---D | C] -- C:\Users\andrei\Documents\Rm undelete
[2014/07/23 01:49:43 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\R-TT
[2014/07/23 01:49:40 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Undelete
[2014/07/23 01:49:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\R-Undelete
[2014/07/23 01:49:40 | 000,000,000 | ---D | C] -- C:\Users\andrei\Documents\R-TT
[2014/07/23 01:46:06 | 000,000,000 | ---D | C] -- C:\Users\andrei\Desktop\New folder
[2014/07/22 21:55:06 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\Wondershare
[2014/07/22 21:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
[2014/07/22 21:55:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wondershare
[2014/07/22 21:55:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Wondershare
[2014/07/22 21:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare
[2014/07/22 21:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Temp
[2014/07/22 21:54:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare Software Co.,Ltd
[2014/07/17 23:34:19 | 000,085,504 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQPropPageExt.dll
[2014/07/17 23:34:19 | 000,083,968 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQAPO.dll
[2014/07/16 07:53:27 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\Adobe
[2014/07/12 00:03:04 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
[2014/07/06 16:30:52 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\PunkBuster
[2014/07/05 23:34:47 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Macromedia
[2014/07/05 23:32:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2014/07/05 23:32:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2014/07/05 17:57:58 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/05 17:57:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/07/05 17:57:50 | 000,092,888 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/07/05 17:57:50 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/07/05 17:57:50 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/07/05 17:57:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/07/05 17:57:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/06/02 23:54:32 | 000,132,096 | ---- | C] (Microsoft) -- C:\Users\andrei\AppData\Roaming\data.exe
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/08/03 00:12:47 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001UA.job
[2014/08/03 00:12:32 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001Core.job
[2014/08/03 00:01:20 | 000,092,888 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/08/03 00:01:08 | 000,079,064 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\oyjmgew.sys
[2014/08/02 23:55:01 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/02 23:55:01 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/02 23:53:39 | 000,132,096 | ---- | M] () -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eb4b40a5d7e90fb7bb1aadd5beab440b.exe
[2014/08/02 23:51:52 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/08/02 23:51:38 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/08/02 23:46:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/02 23:43:33 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/02 23:43:31 | 000,032,512 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2014/08/02 23:43:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/02 23:43:27 | 3220,652,032 | -HS- | M] () -- C:\hiberfil.sys
[2014/08/02 23:40:27 | 000,001,876 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2014/08/02 23:37:04 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/08/02 23:31:51 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/08/02 23:23:36 | 000,029,160 | ---- | M] () -- C:\Windows\SysWow64\drivers\TrueSight.sys
[2014/08/02 23:20:59 | 000,664,340 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/08/02 23:20:59 | 000,122,734 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/08/02 23:20:58 | 000,785,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/08/02 21:26:13 | 000,001,035 | ---- | M] () -- C:\Users\Public\Desktop\foobar2000.lnk
[2014/08/02 12:09:30 | 000,466,520 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2014/08/02 12:09:30 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2014/08/02 12:09:24 | 000,045,397 | ---- | M] () -- C:\Windows\Cmicnfgp.ini.cfl
[2014/08/02 12:09:24 | 000,000,858 | ---- | M] () -- C:\Windows\Cmicnfgp.ini.imi
[2014/08/02 12:09:24 | 000,000,797 | ---- | M] () -- C:\Windows\System\Cmicnfgp.ini
[2014/08/02 12:09:24 | 000,000,140 | ---- | M] () -- C:\Windows\System\Dlap.pfx
[2014/08/02 11:45:22 | 000,376,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/08/02 11:37:34 | 000,000,004 | ---- | M] () -- C:\Windows\SysWow64\8Äl
[2014/07/27 22:04:25 | 000,000,219 | ---- | M] () -- C:\Users\andrei\Desktop\Dota 2.url
[2014/07/26 22:15:41 | 000,001,011 | ---- | M] () -- C:\Users\andrei\Desktop\TransMac.lnk
[2014/07/24 22:25:41 | 000,002,524 | ---- | M] () -- C:\Users\andrei\Documents\cc_20140724_222538.reg
[2014/07/23 05:08:41 | 000,499,706 | ---- | M] () -- C:\Users\andrei\Documents\G(29.50 GB) Lost File Recovery 2014-07-23 at 05.08.37.res
[2014/07/23 02:48:32 | 000,002,010 | ---- | M] () -- C:\Users\Public\Desktop\Pandora Recovery.lnk
[2014/07/22 21:55:05 | 000,001,218 | ---- | M] () -- C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
[2014/07/19 22:08:17 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/07/17 23:34:26 | 000,001,206 | ---- | M] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2014/07/17 20:55:56 | 000,001,613 | ---- | M] () -- C:\Users\andrei\Desktop\Continue Odin v3.09.lnk
[2014/07/12 00:03:05 | 000,002,528 | ---- | M] () -- C:\Users\andrei\Desktop\Windows 7 USB DVD Download Tool.lnk
[2014/07/11 22:24:19 | 000,000,583 | ---- | M] () -- C:\Users\Public\Desktop\WRC 4 FIA World Rally Championship.lnk
[2014/07/10 21:41:21 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2014/07/10 21:41:21 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014/07/09 22:26:19 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014/07/06 16:28:46 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014/07/04 21:54:46 | 000,000,619 | ---- | M] () -- C:\Users\Public\Desktop\Sniper Elite 3.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/08/02 23:53:51 | 000,132,096 | ---- | C] () -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eb4b40a5d7e90fb7bb1aadd5beab440b.exe
[2014/08/02 23:43:31 | 000,032,512 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2014/08/02 23:40:27 | 000,001,876 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2014/08/02 23:31:51 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/08/02 23:23:36 | 000,029,160 | ---- | C] () -- C:\Windows\SysWow64\drivers\TrueSight.sys
[2014/08/02 21:26:13 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2014/08/02 21:26:13 | 000,001,035 | ---- | C] () -- C:\Users\Public\Desktop\foobar2000.lnk
[2014/08/02 12:09:24 | 000,293,376 | ---- | C] () -- C:\Windows\SysNative\CmiCnfgP.cpl
[2014/08/02 12:09:24 | 000,282,112 | ---- | C] () -- C:\Windows\System\HsMgr64.exe
[2014/08/02 12:09:24 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe
[2014/08/02 12:09:24 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP8.dll
[2014/08/02 12:09:24 | 000,000,062 | ---- | C] () -- C:\Windows\SysNative\cmasiopx.ini
[2014/08/02 12:09:24 | 000,000,057 | ---- | C] () -- C:\Windows\SysWow64\cmasiop.ini
[2014/08/02 12:09:21 | 000,045,397 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl
[2014/08/02 11:43:57 | 001,144,983 | ---- | C] () -- C:\Windows\KB936225x64.msu
[2014/08/02 11:43:55 | 000,827,904 | ---- | C] () -- C:\Windows\SysNative\Cmeauoxy.exe
[2014/08/02 11:37:34 | 000,000,004 | ---- | C] () -- C:\Windows\SysWow64\8Äl
[2014/08/02 11:36:51 | 000,000,140 | ---- | C] () -- C:\Windows\System\Dlap.pfx
[2014/08/02 11:36:30 | 000,000,858 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi
[2014/08/02 11:36:28 | 000,359,424 | ---- | C] () -- C:\Windows\SysNative\CmiInstallResAll64.dll
[2014/08/02 11:36:28 | 000,005,874 | ---- | C] () -- C:\Windows\cmudaxp.ini
[2014/08/02 11:36:28 | 000,005,120 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfg
[2014/08/02 11:36:28 | 000,000,797 | ---- | C] () -- C:\Windows\System\Cmicnfgp.ini
[2014/07/26 22:15:41 | 000,001,011 | ---- | C] () -- C:\Users\andrei\Desktop\TransMac.lnk
[2014/07/24 22:25:39 | 000,002,524 | ---- | C] () -- C:\Users\andrei\Documents\cc_20140724_222538.reg
[2014/07/23 05:08:40 | 000,499,706 | ---- | C] () -- C:\Users\andrei\Documents\G(29.50 GB) Lost File Recovery 2014-07-23 at 05.08.37.res
[2014/07/23 02:48:32 | 000,002,010 | ---- | C] () -- C:\Users\Public\Desktop\Pandora Recovery.lnk
[2014/07/22 21:55:05 | 000,001,218 | ---- | C] () -- C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
[2014/07/17 23:34:26 | 000,001,218 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
[2014/07/17 23:34:26 | 000,001,206 | ---- | C] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2014/07/12 00:03:04 | 000,002,528 | ---- | C] () -- C:\Users\andrei\Desktop\Windows 7 USB DVD Download Tool.lnk
[2014/07/11 22:24:19 | 000,000,583 | ---- | C] () -- C:\Users\Public\Desktop\WRC 4 FIA World Rally Championship.lnk
[2014/07/11 22:24:19 | 000,000,583 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WRC 4 FIA World Rally Championship.lnk
[2014/07/06 16:30:59 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2014/07/06 16:28:46 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014/07/06 16:28:46 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014/07/06 16:28:46 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014/07/05 23:32:43 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/07/05 17:57:51 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/07/04 21:54:46 | 000,000,619 | ---- | C] () -- C:\Users\Public\Desktop\Sniper Elite 3.lnk
[2014/07/04 21:54:46 | 000,000,619 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3.lnk
[2014/06/02 22:18:45 | 000,410,942 | ---- | C] () -- C:\Windows\adb.exe
[2014/06/02 22:18:45 | 000,401,408 | ---- | C] () -- C:\Windows\wget.exe
[2014/06/02 22:18:45 | 000,356,009 | ---- | C] () -- C:\Windows\fastboot.exe
[2014/06/02 22:18:45 | 000,063,488 | ---- | C] () -- C:\Windows\md5sum.exe
[2014/04/15 18:49:27 | 000,798,048 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/04/14 21:23:27 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2014/04/14 21:23:27 | 000,002,411 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2014/01/24 04:31:12 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2014/01/24 04:31:08 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2014/01/24 04:31:08 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2014/01/24 04:31:08 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2014/01/24 04:31:08 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
 
========== ZeroAccess Check ==========
 
[2009/07/14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010/11/21 06:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010/11/21 06:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 06:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/05/18 01:50:42 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Acronis
[2014/08/02 11:44:09 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\ASUS
[2014/07/04 00:11:29 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\DarkSoulsII
[2014/08/02 22:45:38 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\foobar2000
[2014/05/17 06:23:59 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\HTC
[2014/06/16 22:29:15 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Mael
[2014/04/21 18:38:28 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\mgyun
[2014/07/11 22:48:29 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Milestone
[2014/07/23 02:50:56 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\PandoraRecovery
[2014/07/26 15:10:44 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\PowerISO
[2014/07/23 01:49:43 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\R-TT
[2014/06/25 21:01:39 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\RigNRoll_pol
[2014/07/03 20:24:59 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Samsung
[2014/08/03 00:00:04 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\uTorrent
[2014/07/02 23:33:10 | 000,000,000 | -HSD | M] -- C:\Users\andrei\AppData\Roaming\wyUpdate AU
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2014/07/22 00:00:49 | 000,000,000 | ---D | M](C:\Users\andrei\Documents\Fi?iere Outlook) -- C:\Users\andrei\Documents\Fișiere Outlook
[2014/07/03 21:39:24 | 000,000,000 | ---D | C](C:\Users\andrei\Documents\Fi?iere Outlook) -- C:\Users\andrei\Documents\Fișiere Outlook
 
< End of report >
 

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there, the second part of this fix will clean the flash drive

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]

:OTL
O4 - HKCU..\Run: [eb4b40a5d7e90fb7bb1aadd5beab440b] C:\Users\andrei\AppData\Roaming\copy1.exe (Microsoft)
O4 - Startup: C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eb4b40a5d7e90fb7bb1aadd5beab440b.exe ()
[2014/08/02 23:53:39 | 000,132,096 | ---- | C] (Microsoft) -- C:\Users\andrei\AppData\Roaming\copy1.exe
[2014/08/02 21:27:09 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\foobar2000
[2014/08/02 21:26:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\foobar2000
[2014/06/02 23:54:32 | 000,132,096 | ---- | C] (Microsoft) -- C:\Users\andrei\AppData\Roaming\data.exe
[2014/08/02 23:53:39 | 000,132,096 | ---- | M] () -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eb4b40a5d7e90fb7bb1aadd5beab440b.exe
[2014/08/02 21:26:13 | 000,001,035 | ---- | M] () -- C:\Users\Public\Desktop\foobar2000.lnk
[2014/08/02 23:53:51 | 000,132,096 | ---- | C] () -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eb4b40a5d7e90fb7bb1aadd5beab440b.exe

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives
mcshield%20unhide.JPG
Plug in the drive and McShield will start a scan

Then get the log which will be located under the logs tab on the main page

And post that
  • 0

#3
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts
Ok..so i l plug thumb as soon i get home at post logs.thanks
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Plug it in after you have installed MCShield


  • 0

#5
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts
Ok...for example if i plugged in now the my computer freezes...for my own...how bad is this malware from a scale 1 to 10?
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

About 5 but once MCShield is installed it will block and cure it


  • 0

#7
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

here is the logs ,,,, 

OTL : 

 

OTL logfile created on: 8/3/2014 4:24:07 PM - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\andrei\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 2.74 Gb Available Physical Memory | 68.40% Memory free
8.00 Gb Paging File | 6.51 Gb Available in Paging File | 81.43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97.66 Gb Total Space | 52.83 Gb Free Space | 54.09% Space Free | Partition Type: NTFS
Drive D: | 368.01 Gb Total Space | 118.78 Gb Free Space | 32.28% Space Free | Partition Type: NTFS
 
Computer Name: ANDREI-PC | User Name: andrei | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/08/03 00:12:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\andrei\Downloads\OTL.exe
PRC - [2014/07/15 12:24:50 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/07/06 16:28:46 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2014/06/23 03:41:29 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
PRC - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/05/12 07:24:34 | 006,970,168 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014/05/08 16:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/03/24 21:32:54 | 000,821,600 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
PRC - [2013/11/19 00:36:38 | 000,087,368 | ---- | M] (Nero AG) -- C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
PRC - [2013/10/18 01:27:02 | 000,166,912 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2013/08/27 22:42:50 | 000,358,480 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2013/08/27 22:42:14 | 000,437,328 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2013/08/27 21:50:10 | 000,086,096 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/07/15 12:24:48 | 000,353,096 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppgooglenaclpluginchrome.dll
MOD - [2014/07/15 12:24:44 | 008,537,928 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll
MOD - [2014/07/15 12:24:38 | 000,718,664 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
MOD - [2014/07/15 12:24:36 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll
MOD - [2014/07/15 12:24:35 | 001,732,936 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
MOD - [2014/03/24 21:32:54 | 000,821,600 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/08/02 23:31:51 | 000,127,752 | ---- | M] (SurfRight B.V.) [Auto | Running] -- C:\Program Files\HitmanPro\hmpsched.exe -- (HitmanProScheduler)
SRV:64bit: - [2012/05/04 14:33:20 | 000,027,760 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV:64bit: - [2009/07/14 04:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 04:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/07/16 05:28:18 | 000,542,912 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/07/09 01:37:24 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/07/06 16:28:46 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014/05/08 16:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/19 00:36:38 | 000,087,368 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe -- (HTCMonitorService)
SRV - [2013/10/18 01:27:02 | 000,166,912 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2013/08/27 22:42:50 | 000,358,480 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2013/08/27 22:42:14 | 000,437,328 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2013/08/27 22:09:34 | 014,401,104 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe -- (VMwareHostd)
SRV - [2013/08/27 21:50:10 | 000,086,096 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2013/08/27 09:33:42 | 000,904,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2012/07/09 10:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 00:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/08/03 16:22:49 | 000,122,584 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014/08/03 16:21:22 | 000,032,512 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hitmanpro37.sys -- (hitmanpro37)
DRV:64bit: - [2014/05/12 07:26:10 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/05/12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2014/04/15 19:55:49 | 000,017,280 | ---- | M] (Scott) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys -- (awUSB)
DRV:64bit: - [2014/04/12 20:25:00 | 000,239,616 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2014/03/30 09:26:02 | 000,129,944 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2013/12/26 08:41:40 | 000,206,136 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2013/12/26 08:41:40 | 000,108,856 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013/10/18 01:27:02 | 000,036,928 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2013/08/27 22:42:46 | 000,030,800 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2013/08/27 22:42:20 | 000,064,080 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2013/08/27 22:42:02 | 000,046,160 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2013/08/27 22:42:02 | 000,020,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2013/08/27 09:33:30 | 000,053,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2013/08/27 09:33:26 | 000,038,456 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2013/08/16 04:25:16 | 000,073,296 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vsock.sys -- (vsock)
DRV:64bit: - [2013/08/16 04:25:12 | 000,085,584 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2013/06/28 21:45:00 | 000,036,352 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandnetmodem64.sys -- (ANDNetModem)
DRV:64bit: - [2013/04/19 02:14:12 | 000,029,184 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandnetdiag64.sys -- (AndNetDiag)
DRV:64bit: - [2013/04/11 19:21:08 | 002,734,080 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cmudaxp.sys -- (cmudaxp)
DRV:64bit: - [2012/05/04 14:33:12 | 002,196,592 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2012/04/25 05:08:00 | 000,118,272 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qcusbser.sys -- (qcusbser)
DRV:64bit: - [2010/11/21 06:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 06:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 06:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 06:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 06:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 06:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 06:23:48 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010/11/21 06:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010/11/21 06:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 06:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/21 06:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/08/02 03:00:00 | 000,031,744 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandadb.sys -- (androidusb)
DRV:64bit: - [2010/03/09 14:08:36 | 000,121,800 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HtcVComV64.sys -- (HtcVCom32)
DRV:64bit: - [2009/11/03 04:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/07/14 04:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 04:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 04:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 04:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 23:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 23:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 23:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 23:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2014/08/02 23:23:36 | 000,029,160 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\Windows\SysWOW64\drivers\TrueSight.sys -- (TrueSight)
DRV - [2009/07/14 04:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 13 19 37 EF 8F 98 CF 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\andrei\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Error reading preferences file
CHR - Extension: Reverse Youtube Playlist = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhonbaagcobjdmbocblbebcmbmmbfmi\1.0_0\
CHR - Extension: Google Docs = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Reverse Playback for YouTube = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmkcmigpoihikjdbclmhgcgdckcfcjid\0.0.1.73_0\
CHR - Extension: Google Search = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: IE Tab = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.7.24.1_0\ietab_nm_
CHR - Extension: IE Tab = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\7.7.24.1_0\
CHR - Extension: Google Wallet = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2014/08/03 16:20:20 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O1364bit: - gopher Prefix: missing
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.ease...oad/SOPCORE.CAB (SopCore Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{198DD62B-EF02-418B-B005-619F08C69779}: DhcpNameServer = 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{275A0893-DE66-43C7-9598-DD615926CFD2}: DhcpNameServer = 192.168.126.2
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1c1f6350-f18c-11e3-aa60-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{1c1f6350-f18c-11e3-aa60-005056c00008}\Shell\AutoRun\command - "" = F:\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\{1c1f63ba-f18c-11e3-aa60-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{1c1f63ba-f18c-11e3-aa60-005056c00008}\Shell\AutoRun\command - "" = F:\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\{9a07efe1-c3ec-11e3-a3a6-001966e78996}\Shell - "" = AutoRun
O33 - MountPoints2\{9a07efe1-c3ec-11e3-a3a6-001966e78996}\Shell\AutoRun\command - "" = E:\LGAutoRun.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/08/03 16:24:31 | 002,856,736 | ---- | C] (MyCity) -- C:\Users\andrei\Desktop\MCShield-Setup.exe
[2014/08/03 16:19:56 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/08/03 00:01:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/08/03 00:01:18 | 000,000,000 | ---D | C] -- C:\Users\andrei\Desktop\mbar
[2014/08/02 23:31:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2014/08/02 23:31:09 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2014/08/02 23:29:12 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014/08/02 23:27:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hitman Pro 3.5
[2014/08/02 23:23:27 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2014/08/02 23:12:28 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/08/02 23:11:01 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/08/02 12:09:24 | 007,946,240 | ---- | C] (C-Media Corporation) -- C:\Windows\SysWow64\CmiCnfgp.dll
[2014/08/02 12:09:24 | 000,465,408 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysNative\cmasiopx.dll
[2014/08/02 12:09:24 | 000,303,104 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\cmasiop.dll
[2014/08/02 12:09:24 | 000,212,992 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\HsSrv2.dll
[2014/08/02 12:09:24 | 000,200,704 | ---- | C] (C-Media) -- C:\Windows\SysWow64\Cmpaoxy.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\System\HsSrv642.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\System\HsSrv64.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (CMedia Electronics Inc.) -- C:\Windows\SysWow64\Cm_Oal.dll
[2014/08/02 12:09:24 | 000,122,880 | ---- | C] (CMedia Electronics Inc.) -- C:\Windows\SysNative\Cm_Oal.dll
[2014/08/02 12:09:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UNi Xonar Audio
[2014/08/02 12:09:21 | 000,000,000 | ---D | C] -- C:\Program Files\UNi Xonar Audio
[2014/08/02 12:08:48 | 002,734,080 | ---- | C] (C-Media Inc) -- C:\Windows\SysNative\drivers\cmudaxp.sys
[2014/08/02 12:08:48 | 000,315,392 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\CmiFltr.dll
[2014/08/02 12:08:48 | 000,315,392 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\System\CmiFltr.dll
[2014/08/02 12:08:48 | 000,032,768 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysNative\cmudaxp.dll
[2014/08/02 11:44:09 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\ASUS
[2014/08/02 11:43:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Xonar DG Audio
[2014/08/02 11:43:55 | 000,000,000 | ---D | C] -- C:\Program Files\ASUS Xonar DG Audio
[2014/08/02 11:36:53 | 000,212,992 | ---- | C] (C-Media Electronics Inc.) -- C:\Windows\SysWow64\HsSrv.dll
[2014/07/26 22:15:41 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
[2014/07/26 22:15:41 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\TransMac
[2014/07/26 22:15:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TransMac
[2014/07/26 15:10:44 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\PowerISO
[2014/07/23 05:09:07 | 000,000,000 | ---D | C] -- C:\Users\andrei\Desktop\paste
[2014/07/23 03:21:13 | 000,000,000 | ---D | C] -- C:\Users\andrei\poze
[2014/07/23 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\PandoraRecovery
[2014/07/23 02:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pandora Recovery
[2014/07/23 02:48:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pandora Recovery
[2014/07/23 02:34:56 | 000,000,000 | ---D | C] -- C:\Users\andrei\Documents\Rm undelete
[2014/07/23 01:49:43 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\R-TT
[2014/07/23 01:49:40 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Undelete
[2014/07/23 01:49:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\R-Undelete
[2014/07/23 01:49:40 | 000,000,000 | ---D | C] -- C:\Users\andrei\Documents\R-TT
[2014/07/23 01:46:06 | 000,000,000 | ---D | C] -- C:\Users\andrei\Desktop\New folder
[2014/07/22 21:55:06 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\Wondershare
[2014/07/22 21:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
[2014/07/22 21:55:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wondershare
[2014/07/22 21:55:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Wondershare
[2014/07/22 21:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare
[2014/07/22 21:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Temp
[2014/07/22 21:54:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare Software Co.,Ltd
[2014/07/17 23:34:19 | 000,085,504 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQPropPageExt.dll
[2014/07/17 23:34:19 | 000,083,968 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQAPO.dll
[2014/07/16 07:53:27 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\Adobe
[2014/07/12 00:03:04 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
[2014/07/06 16:30:52 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Local\PunkBuster
[2014/07/05 23:34:47 | 000,000,000 | ---D | C] -- C:\Users\andrei\AppData\Roaming\Macromedia
[2014/07/05 23:32:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2014/07/05 23:32:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2014/07/05 17:57:58 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/05 17:57:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/07/05 17:57:50 | 000,092,888 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/07/05 17:57:50 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/07/05 17:57:50 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/07/05 17:57:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/07/05 17:57:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
 
========== Files - Modified Within 30 Days ==========
 
[2014/08/03 16:24:33 | 002,856,736 | ---- | M] (MyCity) -- C:\Users\andrei\Desktop\MCShield-Setup.exe
[2014/08/03 16:22:49 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/08/03 16:22:34 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/03 16:22:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/03 16:22:15 | 3220,652,032 | -HS- | M] () -- C:\hiberfil.sys
[2014/08/03 16:21:42 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/03 16:21:42 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/03 16:20:20 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2014/08/03 13:46:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/03 13:37:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/08/03 13:34:21 | 000,009,496 | ---- | M] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2014/08/03 12:12:28 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001UA.job
[2014/08/03 00:12:32 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001Core.job
[2014/08/03 00:01:20 | 000,092,888 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/08/02 23:51:38 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/08/02 23:40:27 | 000,001,876 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2014/08/02 23:31:51 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/08/02 23:23:36 | 000,029,160 | ---- | M] () -- C:\Windows\SysWow64\drivers\TrueSight.sys
[2014/08/02 23:20:59 | 000,664,340 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/08/02 23:20:59 | 000,122,734 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/08/02 23:20:58 | 000,785,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/08/02 12:09:30 | 000,466,520 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2014/08/02 12:09:30 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2014/08/02 12:09:24 | 000,045,397 | ---- | M] () -- C:\Windows\Cmicnfgp.ini.cfl
[2014/08/02 12:09:24 | 000,000,858 | ---- | M] () -- C:\Windows\Cmicnfgp.ini.imi
[2014/08/02 12:09:24 | 000,000,797 | ---- | M] () -- C:\Windows\System\Cmicnfgp.ini
[2014/08/02 12:09:24 | 000,000,140 | ---- | M] () -- C:\Windows\System\Dlap.pfx
[2014/08/02 11:45:22 | 000,376,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/08/02 11:37:34 | 000,000,004 | ---- | M] () -- C:\Windows\SysWow64\8Äl
[2014/07/27 22:04:25 | 000,000,219 | ---- | M] () -- C:\Users\andrei\Desktop\Dota 2.url
[2014/07/26 22:15:41 | 000,001,011 | ---- | M] () -- C:\Users\andrei\Desktop\TransMac.lnk
[2014/07/24 22:25:41 | 000,002,524 | ---- | M] () -- C:\Users\andrei\Documents\cc_20140724_222538.reg
[2014/07/23 05:08:41 | 000,499,706 | ---- | M] () -- C:\Users\andrei\Documents\G(29.50 GB) Lost File Recovery 2014-07-23 at 05.08.37.res
[2014/07/23 02:48:32 | 000,002,010 | ---- | M] () -- C:\Users\Public\Desktop\Pandora Recovery.lnk
[2014/07/22 21:55:05 | 000,001,218 | ---- | M] () -- C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
[2014/07/19 22:08:17 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/07/17 23:34:26 | 000,001,206 | ---- | M] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2014/07/17 20:55:56 | 000,001,613 | ---- | M] () -- C:\Users\andrei\Desktop\Continue Odin v3.09.lnk
[2014/07/12 00:03:05 | 000,002,528 | ---- | M] () -- C:\Users\andrei\Desktop\Windows 7 USB DVD Download Tool.lnk
[2014/07/11 22:24:19 | 000,000,583 | ---- | M] () -- C:\Users\Public\Desktop\WRC 4 FIA World Rally Championship.lnk
[2014/07/10 21:41:21 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2014/07/10 21:41:21 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014/07/09 22:26:19 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014/07/06 16:28:46 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014/07/04 21:54:46 | 000,000,619 | ---- | M] () -- C:\Users\Public\Desktop\Sniper Elite 3.lnk
 
========== Files Created - No Company Name ==========
 
[2014/08/03 11:41:12 | 000,009,496 | ---- | C] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2014/08/02 23:40:27 | 000,001,876 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2014/08/02 23:31:51 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/08/02 23:23:36 | 000,029,160 | ---- | C] () -- C:\Windows\SysWow64\drivers\TrueSight.sys
[2014/08/02 21:26:13 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2014/08/02 12:09:24 | 000,293,376 | ---- | C] () -- C:\Windows\SysNative\CmiCnfgP.cpl
[2014/08/02 12:09:24 | 000,282,112 | ---- | C] () -- C:\Windows\System\HsMgr64.exe
[2014/08/02 12:09:24 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe
[2014/08/02 12:09:24 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP8.dll
[2014/08/02 12:09:24 | 000,000,062 | ---- | C] () -- C:\Windows\SysNative\cmasiopx.ini
[2014/08/02 12:09:24 | 000,000,057 | ---- | C] () -- C:\Windows\SysWow64\cmasiop.ini
[2014/08/02 12:09:21 | 000,045,397 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl
[2014/08/02 11:43:57 | 001,144,983 | ---- | C] () -- C:\Windows\KB936225x64.msu
[2014/08/02 11:43:55 | 000,827,904 | ---- | C] () -- C:\Windows\SysNative\Cmeauoxy.exe
[2014/08/02 11:37:34 | 000,000,004 | ---- | C] () -- C:\Windows\SysWow64\8Äl
[2014/08/02 11:36:51 | 000,000,140 | ---- | C] () -- C:\Windows\System\Dlap.pfx
[2014/08/02 11:36:30 | 000,000,858 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi
[2014/08/02 11:36:28 | 000,359,424 | ---- | C] () -- C:\Windows\SysNative\CmiInstallResAll64.dll
[2014/08/02 11:36:28 | 000,005,874 | ---- | C] () -- C:\Windows\cmudaxp.ini
[2014/08/02 11:36:28 | 000,005,120 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfg
[2014/08/02 11:36:28 | 000,000,797 | ---- | C] () -- C:\Windows\System\Cmicnfgp.ini
[2014/07/26 22:15:41 | 000,001,011 | ---- | C] () -- C:\Users\andrei\Desktop\TransMac.lnk
[2014/07/24 22:25:39 | 000,002,524 | ---- | C] () -- C:\Users\andrei\Documents\cc_20140724_222538.reg
[2014/07/23 05:08:40 | 000,499,706 | ---- | C] () -- C:\Users\andrei\Documents\G(29.50 GB) Lost File Recovery 2014-07-23 at 05.08.37.res
[2014/07/23 02:48:32 | 000,002,010 | ---- | C] () -- C:\Users\Public\Desktop\Pandora Recovery.lnk
[2014/07/22 21:55:05 | 000,001,218 | ---- | C] () -- C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
[2014/07/17 23:34:26 | 000,001,218 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
[2014/07/17 23:34:26 | 000,001,206 | ---- | C] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2014/07/12 00:03:04 | 000,002,528 | ---- | C] () -- C:\Users\andrei\Desktop\Windows 7 USB DVD Download Tool.lnk
[2014/07/11 22:24:19 | 000,000,583 | ---- | C] () -- C:\Users\Public\Desktop\WRC 4 FIA World Rally Championship.lnk
[2014/07/11 22:24:19 | 000,000,583 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WRC 4 FIA World Rally Championship.lnk
[2014/07/06 16:30:59 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2014/07/06 16:28:46 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014/07/06 16:28:46 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014/07/06 16:28:46 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014/07/05 23:32:43 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/07/05 17:57:51 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/07/04 21:54:46 | 000,000,619 | ---- | C] () -- C:\Users\Public\Desktop\Sniper Elite 3.lnk
[2014/07/04 21:54:46 | 000,000,619 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3.lnk
[2014/06/02 22:18:45 | 000,410,942 | ---- | C] () -- C:\Windows\adb.exe
[2014/06/02 22:18:45 | 000,401,408 | ---- | C] () -- C:\Windows\wget.exe
[2014/06/02 22:18:45 | 000,356,009 | ---- | C] () -- C:\Windows\fastboot.exe
[2014/06/02 22:18:45 | 000,063,488 | ---- | C] () -- C:\Windows\md5sum.exe
[2014/04/15 18:49:27 | 000,798,048 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/04/14 21:23:27 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2014/04/14 21:23:27 | 000,002,411 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2014/01/24 04:31:12 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2014/01/24 04:31:08 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2014/01/24 04:31:08 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2014/01/24 04:31:08 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2014/01/24 04:31:08 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
 
========== ZeroAccess Check ==========
 
[2009/07/14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010/11/21 06:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010/11/21 06:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 06:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/05/18 01:50:42 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Acronis
[2014/08/02 11:44:09 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\ASUS
[2014/07/04 00:11:29 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\DarkSoulsII
[2014/05/17 06:23:59 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\HTC
[2014/06/16 22:29:15 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Mael
[2014/04/21 18:38:28 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\mgyun
[2014/07/11 22:48:29 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Milestone
[2014/07/23 02:50:56 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\PandoraRecovery
[2014/07/26 15:10:44 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\PowerISO
[2014/07/23 01:49:43 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\R-TT
[2014/06/25 21:01:39 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\RigNRoll_pol
[2014/07/03 20:24:59 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\Samsung
[2014/08/03 00:00:04 | 000,000,000 | ---D | M] -- C:\Users\andrei\AppData\Roaming\uTorrent
[2014/07/02 23:33:10 | 000,000,000 | -HSD | M] -- C:\Users\andrei\AppData\Roaming\wyUpdate AU
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2014/07/22 00:00:49 | 000,000,000 | ---D | M](C:\Users\andrei\Documents\Fi?iere Outlook) -- C:\Users\andrei\Documents\Fișiere Outlook
[2014/07/03 21:39:24 | 000,000,000 | ---D | C](C:\Users\andrei\Documents\Fi?iere Outlook) -- C:\Users\andrei\Documents\Fișiere Outlook
 
< End of report >
 
 
And mcshield 
 

>>> MCShield AllScans.txt <<<
 
-----------------------------
 
 
 
 
MCShield ::Anti-Malware Tool:: http://www.mcshield.net/
 
>>> v 3.0.5.28 / DB: 2014.7.28.1 / Windows 7 <<<
 
 
8/3/2014 4:30:48 PM > Drive C: - scan started (no label ~98 GB, NTFS HDD )...
 
 
 
=> The drive is clean.
 
 
8/3/2014 4:30:48 PM > Drive D: - scan started (no label ~368 GB, NTFS HDD )...
 
 
 
=> The drive is clean.
 
 
 
 
 
MCShield ::Anti-Malware Tool:: http://www.mcshield.net/
 
>>> v 3.0.5.28 / DB: 2014.7.28.1 / Windows 7 <<<
 
 
8/3/2014 4:32:09 PM > Drive E: - scan started (no label ~29616 MB, NTFS flash drive )...
 
 
 
=> The drive is clean.
 
 
 
 

  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer behaving now

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#9
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts
I m not home right now...it s weirs.dat usb appears clean
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Is that the one you thought was infected ?


  • 0

Advertisements


#11
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts
The one that infected the pc. Yes
  • 0

#12
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

Logs from farbar ,,,also i see that in appdata/roaming is no .exe file and i could format the thumb 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014
Ran by andrei (administrator) on ANDREI-PC on 03-08-2014 18:44:05
Running from C:\Users\andrei\Downloads
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 8
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\...\MountPoints2: E - E:\setup.exe
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\...\MountPoints2: F - F:\autorun.exe
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\...\MountPoints2: {1c1f6350-f18c-11e3-aa60-005056c00008} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\...\MountPoints2: {1c1f63ba-f18c-11e3-aa60-005056c00008} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\...\MountPoints2: {9a07efe1-c3ec-11e3-a3a6-001966e78996} - E:\LGAutoRun.exe
ShellIconOverlayIdentifiers-x32:  SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32:  SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32:  SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x131937EF8F98CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
DPF: HKLM-x32 {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.ease...oad/SOPCORE.CAB
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\andrei\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
Chrome: 
=======
CHR HomePage: hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=48&UP=SPA677E41D-505A-4D53-965A-2E2641F6FC12&SSPV=
CHR StartupUrls: "hxxp://google.ro/"
CHR Extension: (Reverse Youtube Playlist) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhonbaagcobjdmbocblbebcmbmmbfmi [2014-06-08]
CHR Extension: (Google Docs) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-12]
CHR Extension: (Google Drive) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-12]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-13]
CHR Extension: (YouTube) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-12]
CHR Extension: (Reverse Playback for YouTube) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmkcmigpoihikjdbclmhgcgdckcfcjid [2014-06-09]
CHR Extension: (Google Search) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-12]
CHR Extension: (IE Tab) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-05-17]
CHR Extension: (Google Wallet) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-12]
CHR Extension: (Gmail) - C:\Users\andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-12]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-18] () [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-07-06] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)
S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [14401104 2013-08-27] ()
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-19] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 androidusb; C:\Windows\System32\Drivers\lgandadb.sys [31744 2010-08-02] (Google Inc)
S3 awUSB; C:\Windows\System32\DRIVERS\USBDrv_AMD64.sys [17280 2014-04-15] (Scott)
R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2734080 2013-04-11] (C-Media Inc)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [118272 2012-04-25] (QUALCOMM Incorporated)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U3 TrueSight; C:\Windows\SysWOW64\drivers\TrueSight.sys [29160 2014-08-02] ()
R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-08-16] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [33872 2013-02-22] (VMware, Inc.)
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
S2 VBoxDRV; \??\F:\VirtualBox\Portable-VirtualBox\app64\drivers\VBoxDrv\VBoxDrv.sys [X]
S2 VBoxUSBMon; \??\F:\VirtualBox\Portable-VirtualBox\app64\drivers\USB\filter\VBoxUSBMon.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-03 18:44 - 2014-08-03 18:44 - 00010088 _____ () C:\Users\andrei\Downloads\FRST.txt
2014-08-03 18:43 - 2014-08-03 18:44 - 00000000 ____D () C:\FRST
2014-08-03 18:43 - 2014-08-03 18:43 - 02094080 _____ (Farbar) C:\Users\andrei\Downloads\FRST64.exe
2014-08-03 18:39 - 2014-08-03 18:39 - 00000005 _____ () C:\Windows\SysWOW64\lMMLDeleteUserData42107612FX.tmp
2014-08-03 16:30 - 2014-08-03 18:39 - 00000000 ____D () C:\ProgramData\MCShield
2014-08-03 16:30 - 2014-08-03 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MCShield
2014-08-03 16:30 - 2014-08-03 16:30 - 00000000 ____D () C:\Program Files (x86)\MCShield
2014-08-03 16:24 - 2014-08-03 16:24 - 02856736 _____ (MyCity) C:\Users\andrei\Desktop\MCShield-Setup.exe
2014-08-03 16:19 - 2014-08-03 16:19 - 00000000 ____D () C:\_OTL
2014-08-03 13:08 - 2014-08-03 13:09 - 00052373 _____ () C:\Users\andrei\Downloads\Pawn.Stars.Season.06.(Part.I)--- NoGrp.torrent
2014-08-03 12:42 - 2014-08-03 13:16 - 00000016 _____ () C:\Windows\system32\config\software.szfi
2014-08-03 11:41 - 2014-08-03 13:34 - 00009496 _____ () C:\Windows\system32\Drivers\kgpcpy.cfg
2014-08-03 11:35 - 2014-08-03 11:35 - 00707664 _____ (iS3, Inc.) C:\Users\andrei\Downloads\SZSetup_AID10121_AV.exe
2014-08-03 00:28 - 2014-08-03 16:28 - 00088218 _____ () C:\Users\andrei\Downloads\OTL.Txt
2014-08-03 00:28 - 2014-08-03 00:28 - 00056686 _____ () C:\Users\andrei\Downloads\Extras.Txt
2014-08-03 00:10 - 2014-08-03 00:12 - 00602112 _____ (OldTimer Tools) C:\Users\andrei\Downloads\OTL.exe
2014-08-03 00:01 - 2014-08-03 00:27 - 00000000 ____D () C:\Users\andrei\Desktop\mbar
2014-08-03 00:01 - 2014-08-03 00:27 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-02 23:59 - 2014-08-02 23:59 - 14349744 _____ (Malwarebytes Corp.) C:\Users\andrei\Downloads\mbar-1.07.0.1012.exe
2014-08-02 23:40 - 2014-08-02 23:40 - 00001876 _____ () C:\Windows\system32\.crusader
2014-08-02 23:38 - 2014-08-02 23:39 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\andrei\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-02 23:29 - 2014-08-02 23:42 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-02 23:28 - 2014-08-02 23:28 - 11188736 _____ (SurfRight B.V.) C:\Users\andrei\Downloads\HitmanPro_x64.exe
2014-08-02 23:27 - 2014-08-02 23:27 - 00000000 ____D () C:\Program Files (x86)\Hitman Pro 3.5
2014-08-02 23:23 - 2014-08-02 23:23 - 00029160 _____ () C:\Windows\SysWOW64\Drivers\TrueSight.sys
2014-08-02 23:23 - 2014-08-02 23:23 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-08-02 23:19 - 2014-08-03 18:39 - 00003026 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2014-08-02 23:15 - 2014-08-03 16:17 - 00001606 _____ () C:\Windows\PFRO.log
2014-08-02 23:12 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-02 23:11 - 2014-08-02 23:13 - 00000000 ____D () C:\AdwCleaner
2014-08-02 23:11 - 2014-08-02 23:11 - 04806744 _____ () C:\Users\andrei\Downloads\RogueKiller.exe
2014-08-02 23:09 - 2014-08-02 23:09 - 01361309 _____ () C:\Users\andrei\Downloads\adwcleaner_3.302.exe
2014-08-02 23:05 - 2014-08-02 23:05 - 00854410 _____ () C:\Users\andrei\Downloads\SecurityCheck.exe
2014-08-02 21:26 - 2014-08-02 21:26 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2014-08-02 21:19 - 2014-08-02 21:19 - 03797776 _____ (foobar2000.org) C:\Users\andrei\Downloads\foobar2000_v1.3.3.exe
2014-08-02 12:18 - 2014-08-02 12:18 - 10067700 _____ () C:\Users\andrei\Downloads\dolby_game.rar
2014-08-02 12:18 - 2014-08-02 12:18 - 03814867 _____ () C:\Users\andrei\Downloads\dolby_argon.rar
2014-08-02 12:18 - 2014-08-02 12:18 - 00000000 ____D () C:\Users\andrei\Downloads\dolby_argon
2014-08-02 12:09 - 2014-08-02 12:09 - 00045397 _____ () C:\Windows\Cmicnfgp.ini.cfl
2014-08-02 12:09 - 2014-08-02 12:09 - 00000126 _____ () C:\Users\andrei\Downloads\installsettings.ini
2014-08-02 12:09 - 2014-08-02 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UNi Xonar Audio
2014-08-02 12:09 - 2014-08-02 12:09 - 00000000 ____D () C:\Program Files\UNi Xonar Audio
2014-08-02 12:09 - 2012-11-20 12:24 - 07946240 ____N (C-Media Corporation) C:\Windows\SysWOW64\CmiCnfgp.dll
2014-08-02 12:09 - 2012-10-05 10:37 - 00465408 ____N (C-Media Electronics Inc.) C:\Windows\system32\cmasiopx.dll
2014-08-02 12:09 - 2012-10-05 10:37 - 00303104 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\cmasiop.dll
2014-08-02 12:09 - 2012-09-16 23:23 - 00293376 ____N () C:\Windows\system32\CmiCnfgP.cpl
2014-08-02 12:09 - 2012-06-06 10:56 - 00143360 ____N () C:\Windows\SysWOW64\VmixP8.dll
2014-08-02 12:09 - 2012-01-06 10:30 - 00212992 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\HsSrv2.dll
2014-08-02 12:09 - 2012-01-06 10:30 - 00122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv642.dll
2014-08-02 12:09 - 2012-01-06 10:30 - 00122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv64.dll
2014-08-02 12:09 - 2010-07-15 17:12 - 00000062 ____N () C:\Windows\system32\cmasiopx.ini
2014-08-02 12:09 - 2010-07-15 17:12 - 00000057 ____N () C:\Windows\SysWOW64\cmasiop.ini
2014-08-02 12:09 - 2008-07-11 16:04 - 00200704 ____N () C:\Windows\SysWOW64\HsMgr.exe
2014-08-02 12:09 - 2008-07-11 16:03 - 00282112 ____N () C:\Windows\system\HsMgr64.exe
2014-08-02 12:09 - 2007-12-13 18:12 - 00122880 ____N (CMedia Electronics Inc.) C:\Windows\SysWOW64\Cm_Oal.dll
2014-08-02 12:09 - 2007-12-13 18:12 - 00122880 ____N (CMedia Electronics Inc.) C:\Windows\system32\Cm_Oal.dll
2014-08-02 12:09 - 2006-09-13 11:21 - 00200704 ____N (C-Media) C:\Windows\SysWOW64\Cmpaoxy.dll
2014-08-02 12:08 - 2014-08-02 12:08 - 07415039 _____ (CarvedInside ) C:\Users\andrei\Downloads\UNi Xonar 1821 v1.71 r2.exe
2014-08-02 12:08 - 2013-04-11 19:21 - 02734080 _____ (C-Media Inc) C:\Windows\system32\Drivers\cmudaxp.sys
2014-08-02 12:08 - 2013-04-11 19:21 - 00315392 _____ (C-Media Electronics Inc.) C:\Windows\SysWOW64\CmiFltr.dll
2014-08-02 12:08 - 2013-04-11 19:21 - 00315392 _____ (C-Media Electronics Inc.) C:\Windows\system\CmiFltr.dll
2014-08-02 12:08 - 2013-04-11 19:21 - 00032768 _____ (C-Media Electronics Inc.) C:\Windows\system32\cmudaxp.dll
2014-08-02 11:44 - 2014-08-02 11:44 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\ASUS
2014-08-02 11:43 - 2014-08-02 11:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Xonar DG Audio
2014-08-02 11:43 - 2014-08-02 11:43 - 00000000 ____D () C:\Program Files\ASUS Xonar DG Audio
2014-08-02 11:43 - 2013-03-21 10:11 - 00827904 ____N () C:\Windows\system32\Cmeauoxy.exe
2014-08-02 11:43 - 2007-11-05 01:30 - 01144983 ____N () C:\Windows\KB936225x64.msu
2014-08-02 11:37 - 2014-08-02 11:37 - 00000004 _____ () C:\Windows\SysWOW64\8Äl
2014-08-02 11:36 - 2014-08-02 12:09 - 00000858 _____ () C:\Windows\Cmicnfgp.ini.imi
2014-08-02 11:36 - 2014-08-02 12:09 - 00000797 _____ () C:\Windows\system\Cmicnfgp.ini
2014-08-02 11:36 - 2014-08-02 12:09 - 00000140 _____ () C:\Windows\system\Dlap.pfx
2014-08-02 11:36 - 2014-08-02 11:36 - 00000000 ____D () C:\Users\andrei\Downloads\DG_7_0_8_1821_Win7_WHQL
2014-08-02 11:36 - 2013-03-07 22:08 - 00005874 ____N () C:\Windows\cmudaxp.ini
2014-08-02 11:36 - 2012-11-05 20:06 - 00005120 ____N () C:\Windows\Cmicnfgp.ini.cfg
2014-08-02 11:36 - 2012-01-06 09:30 - 00212992 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\HsSrv.dll
2014-08-02 11:36 - 2009-08-19 01:00 - 00359424 ____N () C:\Windows\system32\CmiInstallResAll64.dll
2014-08-02 11:35 - 2014-08-02 11:35 - 12197495 _____ () C:\Users\andrei\Downloads\DG_7_0_8_1821_Win7_WHQL.rar
2014-08-02 11:35 - 2014-08-02 11:35 - 10552296 _____ (Akamai Technologies, Inc.) C:\Users\andrei\Downloads\AsusInstaller.exe
2014-07-26 22:15 - 2014-07-26 22:15 - 00001011 _____ () C:\Users\andrei\Desktop\TransMac.lnk
2014-07-26 22:15 - 2014-07-26 22:15 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
2014-07-26 22:15 - 2014-07-26 22:15 - 00000000 ____D () C:\Users\andrei\AppData\Local\TransMac
2014-07-26 22:15 - 2014-07-26 22:15 - 00000000 ____D () C:\Program Files (x86)\TransMac
2014-07-26 15:10 - 2014-07-26 15:10 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\PowerISO
2014-07-25 23:19 - 2014-07-25 23:19 - 15729731 _____ () C:\Users\andrei\Downloads\post.wav
2014-07-25 23:19 - 2014-07-25 23:19 - 15703855 _____ () C:\Users\andrei\Downloads\Simple Symphony  op. 4 - Boisterous Bourree.wav
2014-07-25 20:13 - 2014-08-03 18:38 - 00006827 _____ () C:\Windows\setupact.log
2014-07-25 20:13 - 2014-07-25 20:13 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-24 22:25 - 2014-07-24 22:25 - 00002524 _____ () C:\Users\andrei\Documents\cc_20140724_222538.reg
2014-07-23 05:09 - 2014-07-23 05:16 - 00000000 ____D () C:\Users\andrei\Desktop\paste
2014-07-23 05:08 - 2014-07-23 05:08 - 00499706 _____ () C:\Users\andrei\Documents\G(29.50 GB) Lost File Recovery 2014-07-23 at 05.08.37.res
2014-07-23 03:21 - 2014-07-23 03:25 - 00000000 ____D () C:\Users\andrei\poze
2014-07-23 02:34 - 2014-07-23 03:35 - 00000000 ____D () C:\Users\andrei\Documents\Rm undelete
2014-07-23 01:49 - 2014-07-23 01:49 - 00000000 ____D () C:\Users\andrei\Documents\R-TT
2014-07-23 01:49 - 2014-07-23 01:49 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\R-TT
2014-07-23 01:46 - 2014-07-23 01:46 - 00000000 ____D () C:\Users\andrei\Desktop\New folder
2014-07-22 21:55 - 2014-07-22 21:55 - 00001218 _____ () C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\Users\andrei\AppData\Local\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\ProgramData\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\Program Files (x86)\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\Program Files (x86)\Temp
2014-07-22 21:54 - 2014-07-22 21:54 - 00000000 ____D () C:\Program Files (x86)\Wondershare Software Co.,Ltd
2014-07-17 23:34 - 2014-07-17 23:34 - 00001218 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
2014-07-17 23:34 - 2014-07-17 23:34 - 00001206 _____ () C:\Users\Public\Desktop\HD VDeck.lnk
2014-07-17 23:34 - 2012-05-04 14:33 - 02959984 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIAPropPageExt.dll
2014-07-17 23:34 - 2012-05-04 14:33 - 02196592 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\viahduaa.sys
2014-07-17 23:34 - 2012-05-04 14:33 - 01161328 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaKaraokeApo.dll
2014-07-17 23:34 - 2012-05-04 14:33 - 01119344 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaMicArrayAPO.dll
2014-07-17 23:34 - 2012-05-04 14:33 - 00680560 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIASysFx.dll
2014-07-17 23:34 - 2012-05-04 14:33 - 00116848 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaKaraokePropPageExt.dll
2014-07-17 23:34 - 2012-05-04 14:33 - 00094832 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaMicArrayPropPageExt.dll
2014-07-17 23:34 - 2012-05-04 14:33 - 00027760 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViakaraokeSrv.exe
2014-07-17 23:34 - 2011-09-27 13:13 - 00879616 _____ (Creative Technology Ltd.) C:\Windows\system32\VMAPO64.DLL
2014-07-17 23:34 - 2011-09-27 13:13 - 00739328 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMAPO32.DLL
2014-07-17 23:34 - 2011-09-27 13:13 - 00057856 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPLD64.DLL
2014-07-17 23:34 - 2011-06-08 13:19 - 00085504 _____ (QSound Labs, Inc.) C:\Windows\system32\nQPropPageExt.dll
2014-07-17 23:34 - 2011-06-08 13:19 - 00083968 _____ (QSound Labs, Inc.) C:\Windows\system32\nQAPO.dll
2014-07-17 23:34 - 2010-10-26 13:54 - 00053760 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPCN64.DLL
2014-07-17 23:30 - 2014-07-17 23:30 - 00000000 ____D () C:\Users\andrei\Downloads\v10500d
2014-07-16 07:53 - 2014-07-16 07:53 - 00000000 ____D () C:\Users\andrei\AppData\Local\Adobe
2014-07-12 00:03 - 2014-07-12 00:03 - 00002528 _____ () C:\Users\andrei\Desktop\Windows 7 USB DVD Download Tool.lnk
2014-07-12 00:03 - 2014-07-12 00:03 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2014-07-12 00:03 - 2014-07-12 00:03 - 00000000 ____D () C:\Users\andrei\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2014-07-11 22:24 - 2014-07-11 22:24 - 00000583 _____ () C:\Users\Public\Desktop\WRC 4 FIA World Rally Championship.lnk
2014-07-11 22:24 - 2014-07-11 22:24 - 00000583 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WRC 4 FIA World Rally Championship.lnk
2014-07-06 16:30 - 2014-07-10 21:41 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-07-06 16:30 - 2014-07-06 16:30 - 00000000 ____D () C:\Users\andrei\AppData\Local\PunkBuster
2014-07-06 16:28 - 2014-07-10 21:41 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-06 16:28 - 2014-07-09 22:26 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-07-06 16:28 - 2014-07-06 16:28 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-05 23:34 - 2014-07-05 23:34 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Macromedia
2014-07-05 23:32 - 2014-08-03 13:37 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-05 23:32 - 2014-07-09 01:37 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-05 23:32 - 2014-07-09 01:37 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-05 23:32 - 2014-07-09 01:37 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-05 23:32 - 2014-07-05 23:32 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-05 23:32 - 2014-07-05 23:32 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-05 17:57 - 2014-07-05 17:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-04 21:54 - 2014-07-04 21:54 - 00000619 _____ () C:\Users\Public\Desktop\Sniper Elite 3.lnk
2014-07-04 21:54 - 2014-07-04 21:54 - 00000619 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3.lnk
2014-07-04 00:11 - 2014-07-04 00:11 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\DarkSoulsII
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-03 18:44 - 2014-08-03 18:44 - 00010088 _____ () C:\Users\andrei\Downloads\FRST.txt
2014-08-03 18:44 - 2014-08-03 18:43 - 00000000 ____D () C:\FRST
2014-08-03 18:43 - 2014-08-03 18:43 - 02094080 _____ (Farbar) C:\Users\andrei\Downloads\FRST64.exe
2014-08-03 18:42 - 2010-05-27 10:36 - 00746991 _____ () C:\Windows\WindowsUpdate.log
2014-08-03 18:41 - 2009-07-14 07:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-03 18:41 - 2009-07-14 07:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-03 18:39 - 2014-08-03 18:39 - 00000005 _____ () C:\Windows\SysWOW64\lMMLDeleteUserData42107612FX.tmp
2014-08-03 18:39 - 2014-08-03 16:30 - 00000000 ____D () C:\ProgramData\MCShield
2014-08-03 18:39 - 2014-08-02 23:19 - 00003026 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2014-08-03 18:39 - 2014-05-17 06:23 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\HTC
2014-08-03 18:39 - 2014-05-17 06:22 - 00000000 ____D () C:\ProgramData\HTC
2014-08-03 18:39 - 2014-05-17 06:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC
2014-08-03 18:39 - 2014-05-17 06:21 - 00000000 ____D () C:\Program Files (x86)\HTC
2014-08-03 18:38 - 2014-07-25 20:13 - 00006827 _____ () C:\Windows\setupact.log
2014-08-03 18:38 - 2014-05-17 17:27 - 00000000 ____D () C:\ProgramData\VMware
2014-08-03 18:38 - 2014-04-12 20:19 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-03 18:38 - 2009-07-14 08:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-03 16:33 - 2009-07-14 08:13 - 00785510 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-03 16:30 - 2014-08-03 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MCShield
2014-08-03 16:30 - 2014-08-03 16:30 - 00000000 ____D () C:\Program Files (x86)\MCShield
2014-08-03 16:28 - 2014-08-03 00:28 - 00088218 _____ () C:\Users\andrei\Downloads\OTL.Txt
2014-08-03 16:24 - 2014-08-03 16:24 - 02856736 _____ (MyCity) C:\Users\andrei\Desktop\MCShield-Setup.exe
2014-08-03 16:19 - 2014-08-03 16:19 - 00000000 ____D () C:\_OTL
2014-08-03 16:17 - 2014-08-02 23:15 - 00001606 _____ () C:\Windows\PFRO.log
2014-08-03 13:46 - 2014-04-12 20:19 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-03 13:37 - 2014-07-05 23:32 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-03 13:34 - 2014-08-03 11:41 - 00009496 _____ () C:\Windows\system32\Drivers\kgpcpy.cfg
2014-08-03 13:16 - 2014-08-03 12:42 - 00000016 _____ () C:\Windows\system32\config\software.szfi
2014-08-03 13:09 - 2014-08-03 13:08 - 00052373 _____ () C:\Users\andrei\Downloads\Pawn.Stars.Season.06.(Part.I)--- NoGrp.torrent
2014-08-03 12:12 - 2014-06-11 00:07 - 00000932 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001UA.job
2014-08-03 11:35 - 2014-08-03 11:35 - 00707664 _____ (iS3, Inc.) C:\Users\andrei\Downloads\SZSetup_AID10121_AV.exe
2014-08-03 11:21 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\PLA
2014-08-03 00:28 - 2014-08-03 00:28 - 00056686 _____ () C:\Users\andrei\Downloads\Extras.Txt
2014-08-03 00:27 - 2014-08-03 00:01 - 00000000 ____D () C:\Users\andrei\Desktop\mbar
2014-08-03 00:27 - 2014-08-03 00:01 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-03 00:12 - 2014-08-03 00:10 - 00602112 _____ (OldTimer Tools) C:\Users\andrei\Downloads\OTL.exe
2014-08-03 00:12 - 2014-06-11 00:07 - 00000910 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001Core.job
2014-08-03 00:00 - 2014-04-12 20:30 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\uTorrent
2014-08-02 23:59 - 2014-08-02 23:59 - 14349744 _____ (Malwarebytes Corp.) C:\Users\andrei\Downloads\mbar-1.07.0.1012.exe
2014-08-02 23:42 - 2014-08-02 23:29 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-02 23:40 - 2014-08-02 23:40 - 00001876 _____ () C:\Windows\system32\.crusader
2014-08-02 23:39 - 2014-08-02 23:38 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\andrei\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-02 23:28 - 2014-08-02 23:28 - 11188736 _____ (SurfRight B.V.) C:\Users\andrei\Downloads\HitmanPro_x64.exe
2014-08-02 23:27 - 2014-08-02 23:27 - 00000000 ____D () C:\Program Files (x86)\Hitman Pro 3.5
2014-08-02 23:23 - 2014-08-02 23:23 - 00029160 _____ () C:\Windows\SysWOW64\Drivers\TrueSight.sys
2014-08-02 23:23 - 2014-08-02 23:23 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-08-02 23:13 - 2014-08-02 23:11 - 00000000 ____D () C:\AdwCleaner
2014-08-02 23:11 - 2014-08-02 23:11 - 04806744 _____ () C:\Users\andrei\Downloads\RogueKiller.exe
2014-08-02 23:09 - 2014-08-02 23:09 - 01361309 _____ () C:\Users\andrei\Downloads\adwcleaner_3.302.exe
2014-08-02 23:05 - 2014-08-02 23:05 - 00854410 _____ () C:\Users\andrei\Downloads\SecurityCheck.exe
2014-08-02 22:46 - 2014-04-12 20:28 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-02 21:26 - 2014-08-02 21:26 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2014-08-02 21:19 - 2014-08-02 21:19 - 03797776 _____ (foobar2000.org) C:\Users\andrei\Downloads\foobar2000_v1.3.3.exe
2014-08-02 12:18 - 2014-08-02 12:18 - 10067700 _____ () C:\Users\andrei\Downloads\dolby_game.rar
2014-08-02 12:18 - 2014-08-02 12:18 - 03814867 _____ () C:\Users\andrei\Downloads\dolby_argon.rar
2014-08-02 12:18 - 2014-08-02 12:18 - 00000000 ____D () C:\Users\andrei\Downloads\dolby_argon
2014-08-02 12:18 - 2014-04-13 00:04 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\vlc
2014-08-02 12:09 - 2014-08-02 12:09 - 00045397 _____ () C:\Windows\Cmicnfgp.ini.cfl
2014-08-02 12:09 - 2014-08-02 12:09 - 00000126 _____ () C:\Users\andrei\Downloads\installsettings.ini
2014-08-02 12:09 - 2014-08-02 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UNi Xonar Audio
2014-08-02 12:09 - 2014-08-02 12:09 - 00000000 ____D () C:\Program Files\UNi Xonar Audio
2014-08-02 12:09 - 2014-08-02 11:36 - 00000858 _____ () C:\Windows\Cmicnfgp.ini.imi
2014-08-02 12:09 - 2014-08-02 11:36 - 00000797 _____ () C:\Windows\system\Cmicnfgp.ini
2014-08-02 12:09 - 2014-08-02 11:36 - 00000140 _____ () C:\Windows\system\Dlap.pfx
2014-08-02 12:09 - 2014-06-25 20:49 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-08-02 12:09 - 2014-06-25 20:49 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-08-02 12:09 - 2014-06-25 20:49 - 00123480 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-08-02 12:09 - 2014-06-25 20:49 - 00109144 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-08-02 12:09 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\system
2014-08-02 12:08 - 2014-08-02 12:08 - 07415039 _____ (CarvedInside ) C:\Users\andrei\Downloads\UNi Xonar 1821 v1.71 r2.exe
2014-08-02 11:45 - 2009-07-14 07:45 - 00376464 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-02 11:44 - 2014-08-02 11:44 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\ASUS
2014-08-02 11:43 - 2014-08-02 11:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Xonar DG Audio
2014-08-02 11:43 - 2014-08-02 11:43 - 00000000 ____D () C:\Program Files\ASUS Xonar DG Audio
2014-08-02 11:37 - 2014-08-02 11:37 - 00000004 _____ () C:\Windows\SysWOW64\8Äl
2014-08-02 11:37 - 2014-06-25 20:49 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-08-02 11:37 - 2014-04-12 20:18 - 00090008 _____ () C:\Users\andrei\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-02 11:36 - 2014-08-02 11:36 - 00000000 ____D () C:\Users\andrei\Downloads\DG_7_0_8_1821_Win7_WHQL
2014-08-02 11:35 - 2014-08-02 11:35 - 12197495 _____ () C:\Users\andrei\Downloads\DG_7_0_8_1821_Win7_WHQL.rar
2014-08-02 11:35 - 2014-08-02 11:35 - 10552296 _____ (Akamai Technologies, Inc.) C:\Users\andrei\Downloads\AsusInstaller.exe
2014-07-27 22:04 - 2014-04-12 20:38 - 00000219 _____ () C:\Users\andrei\Desktop\Dota 2.url
2014-07-27 01:36 - 2014-05-17 17:32 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\VMware
2014-07-27 01:36 - 2014-05-17 17:32 - 00000000 ____D () C:\Users\andrei\AppData\Local\VMware
2014-07-26 22:15 - 2014-07-26 22:15 - 00001011 _____ () C:\Users\andrei\Desktop\TransMac.lnk
2014-07-26 22:15 - 2014-07-26 22:15 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
2014-07-26 22:15 - 2014-07-26 22:15 - 00000000 ____D () C:\Users\andrei\AppData\Local\TransMac
2014-07-26 22:15 - 2014-07-26 22:15 - 00000000 ____D () C:\Program Files (x86)\TransMac
2014-07-26 15:10 - 2014-07-26 15:10 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\PowerISO
2014-07-25 23:19 - 2014-07-25 23:19 - 15729731 _____ () C:\Users\andrei\Downloads\post.wav
2014-07-25 23:19 - 2014-07-25 23:19 - 15703855 _____ () C:\Users\andrei\Downloads\Simple Symphony  op. 4 - Boisterous Bourree.wav
2014-07-25 20:13 - 2014-07-25 20:13 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-24 22:27 - 2014-06-21 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GTV Solutions, Inc. Messaging System
2014-07-24 22:27 - 2014-06-21 23:00 - 00000000 ____D () C:\Program Files (x86)\Sonork
2014-07-24 22:25 - 2014-07-24 22:25 - 00002524 _____ () C:\Users\andrei\Documents\cc_20140724_222538.reg
2014-07-24 22:25 - 2014-05-27 20:57 - 00000000 ____D () C:\Windows\Minidump
2014-07-23 05:16 - 2014-07-23 05:09 - 00000000 ____D () C:\Users\andrei\Desktop\paste
2014-07-23 05:08 - 2014-07-23 05:08 - 00499706 _____ () C:\Users\andrei\Documents\G(29.50 GB) Lost File Recovery 2014-07-23 at 05.08.37.res
2014-07-23 03:35 - 2014-07-23 02:34 - 00000000 ____D () C:\Users\andrei\Documents\Rm undelete
2014-07-23 03:25 - 2014-07-23 03:21 - 00000000 ____D () C:\Users\andrei\poze
2014-07-23 03:21 - 2014-04-12 20:14 - 00000000 ____D () C:\Users\andrei
2014-07-23 01:49 - 2014-07-23 01:49 - 00000000 ____D () C:\Users\andrei\Documents\R-TT
2014-07-23 01:49 - 2014-07-23 01:49 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\R-TT
2014-07-23 01:46 - 2014-07-23 01:46 - 00000000 ____D () C:\Users\andrei\Desktop\New folder
2014-07-22 21:55 - 2014-07-22 21:55 - 00001218 _____ () C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\Users\andrei\AppData\Local\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\ProgramData\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\Program Files (x86)\Wondershare
2014-07-22 21:55 - 2014-07-22 21:55 - 00000000 ____D () C:\Program Files (x86)\Temp
2014-07-22 21:54 - 2014-07-22 21:54 - 00000000 ____D () C:\Program Files (x86)\Wondershare Software Co.,Ltd
2014-07-22 00:00 - 2014-07-03 21:39 - 00000000 ____D () C:\Users\andrei\Documents\Fișiere Outlook
2014-07-21 23:11 - 2014-04-21 18:40 - 00000000 ____D () C:\Users\andrei\Documents\SelfMV
2014-07-19 22:08 - 2014-04-12 20:20 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-17 23:34 - 2014-07-17 23:34 - 00001218 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
2014-07-17 23:34 - 2014-07-17 23:34 - 00001206 _____ () C:\Users\Public\Desktop\HD VDeck.lnk
2014-07-17 23:34 - 2014-04-12 20:38 - 00000000 ____D () C:\Program Files (x86)\VIA
2014-07-17 23:30 - 2014-07-17 23:30 - 00000000 ____D () C:\Users\andrei\Downloads\v10500d
2014-07-17 20:55 - 2014-07-03 21:10 - 00001613 _____ () C:\Users\andrei\Desktop\Continue Odin v3.09.lnk
2014-07-16 07:58 - 2014-05-11 00:27 - 00000000 ____D () C:\ruu_log
2014-07-16 07:53 - 2014-07-16 07:53 - 00000000 ____D () C:\Users\andrei\AppData\Local\Adobe
2014-07-12 00:03 - 2014-07-12 00:03 - 00002528 _____ () C:\Users\andrei\Desktop\Windows 7 USB DVD Download Tool.lnk
2014-07-12 00:03 - 2014-07-12 00:03 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2014-07-12 00:03 - 2014-07-12 00:03 - 00000000 ____D () C:\Users\andrei\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2014-07-11 22:48 - 2014-05-27 23:12 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Milestone
2014-07-11 22:24 - 2014-07-11 22:24 - 00000583 _____ () C:\Users\Public\Desktop\WRC 4 FIA World Rally Championship.lnk
2014-07-11 22:24 - 2014-07-11 22:24 - 00000583 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WRC 4 FIA World Rally Championship.lnk
2014-07-10 21:41 - 2014-07-06 16:30 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-07-10 21:41 - 2014-07-06 16:28 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-09 22:26 - 2014-07-06 16:28 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-07-09 01:37 - 2014-07-05 23:32 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 01:37 - 2014-07-05 23:32 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 01:37 - 2014-07-05 23:32 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-06 16:30 - 2014-07-06 16:30 - 00000000 ____D () C:\Users\andrei\AppData\Local\PunkBuster
2014-07-06 16:30 - 2014-05-31 01:14 - 00000000 ____D () C:\Users\andrei\Documents\My Games
2014-07-06 16:30 - 2014-05-31 01:14 - 00000000 ____D () C:\ProgramData\Orbit
2014-07-06 16:28 - 2014-07-06 16:28 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-06 16:28 - 2009-07-14 08:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-07-06 16:17 - 2014-04-12 20:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-05 23:34 - 2014-07-05 23:34 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\Macromedia
2014-07-05 23:32 - 2014-07-05 23:32 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-05 23:32 - 2014-07-05 23:32 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-05 18:17 - 2011-04-12 11:28 - 00000000 __SHD () C:\Windows\BitLockerDiscoveryVolumeContents
2014-07-05 17:57 - 2014-07-05 17:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-04 21:54 - 2014-07-04 21:54 - 00000619 _____ () C:\Users\Public\Desktop\Sniper Elite 3.lnk
2014-07-04 21:54 - 2014-07-04 21:54 - 00000619 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3.lnk
2014-07-04 00:11 - 2014-07-04 00:11 - 00000000 ____D () C:\Users\andrei\AppData\Roaming\DarkSoulsII
 
Some content of TEMP:
====================
C:\Users\andrei\AppData\Local\Temp\HitmanPro.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-07-29 06:48
 
==================== End Of Log ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-08-2014
Ran by andrei at 2014-08-03 18:44:42
Running from C:\Users\andrei\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.32 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0932-000001000000}) (Version: 9.32.00.0 - Igor Pavlov)
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Romanian (HKLM-x32\...\{AC76BA86-7AD7-1048-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Android Tool (HKLM-x32\...\{A56EFA10-A18F-493E-82EA-0AD60350F54C}) (Version: 1.1.0 - Your Company)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.01 - Ubisoft)
foobar2000 v1.3.3 (HKLM-x32\...\foobar2000) (Version: 1.3.3 - Peter Pawlowski)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GRID Autosport (HKLM-x32\...\R1JJREF1dG9zcG9ydA==_is1) (Version: 1 - )
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.10.0.001 - HTC Corporation)
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
LG United Mobile Driver (HKLM-x32\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics)
LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere)
MCShield ::Anti-Malware Tool:: (HKLM-x32\...\MCShield) (Version: 3.0.5.28 - MyCity)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden
Microsoft Access MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft DCF MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Excel MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Groove MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Lync MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Română (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft OneNote MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Word MUI (Romanian) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
MotoGP™13 (HKLM-x32\...\{4B784CE7-7CDB-4AF1-B636-2DC3EA51EA87}) (Version: 1.00.0000 - Milestone)
MotoGP™13 (x32 Version: 1.00.0000 - Milestone) Hidden
MSI Afterburner 3.0.1 (HKLM-x32\...\Afterburner) (Version: 3.0.1 - MSI Co., LTD)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MyFreeCodec (HKCU\...\MyFreeCodec) (Version:  - )
NVIDIA Control Panel 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden
NVIDIA Graphics Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
PowerISO (HKLM-x32\...\PowerISO) (Version: 5.9 - Power Software Ltd)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QMAT (HKLM-x32\...\QMAT) (Version:  - )
QPST (HKLM-x32\...\{31228E31-2BFF-11D2-8866-00805F0D9D40}) (Version:  - )
QPST 2.7 (HKLM-x32\...\{E5369F4D-3683-4CA2-9619-84506B182F1C}) (Version: 2.7.374 - Qualcomm)
Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0009 - Realtek)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.2.14014_7 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.2.14014_7 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14034.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14034.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.33.0 - SAMSUNG Electronics Co., Ltd.)
Sniper Elite 3 (HKLM-x32\...\U25pcGVyRWxpdGUz_is1) (Version: 1 - )
SopCast 2.0.4 (HKLM-x32\...\SopCast) (Version: 2.0.4 - SopCast.com)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
tools-freebsd (x32 Version: 9.6.0.1295980 - VMware, Inc.) Hidden
tools-linux (x32 Version: 9.6.0.1295980 - VMware, Inc.) Hidden
tools-netware (x32 Version: 9.6.0.1295980 - VMware, Inc.) Hidden
tools-solaris (x32 Version: 9.6.0.1295980 - VMware, Inc.) Hidden
tools-windows (x32 Version: 9.6.0.1295980 - VMware, Inc.) Hidden
tools-winPre2k (x32 Version: 9.6.0.1295980 - VMware, Inc.) Hidden
TransMac version 11.0 (HKLM-x32\...\TransMac_is1) (Version: 11.0 - Acute Systems)
UNi Xonar Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version:  - )
Universal Hard Reset Tool (HKLM-x32\...\{4F42CA34-A31B-4DB5-86E9-3286D61A2FD2}) (Version: 1.0.0 - Default Company Name)
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
VMware Workstation (HKLM-x32\...\VMware_Workstation) (Version: 10.0.0 - VMware, Inc)
VMware Workstation (Version: 10.0.0 - VMware, Inc.) Hidden
VROOT (HKLM-x32\...\{1295E43F-382A-4CB2-9E0F-079C0D7401BB}_is1) (Version: 1.7.3.4863 - Shenzhen Xinyi Network Co.,Ltd.)
WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version:  - Ubisoft)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (01/27/2014 9.0.0000.00000) (HKLM\...\9CA77E2A8332A0824C54DA611BBE4CA24AB1F750) (Version: 01/27/2014 9.0.0000.00000 - Google, Inc.)
WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Wondershare Data Recovery 4.5.0.16 (HKLM-x32\...\Wondershare Data Recovery 4.5.0.16) (Version:  - )
Wondershare Data Recovery(Build 4.5.0.16) (HKLM-x32\...\{FEA3976F-D621-45F3-AFBD-E812A1F2F00D}_is1) (Version: 4.5.0.16 - Wondershare Software Co.,Ltd.)
WRC 4 FIA World Rally Championship (HKLM-x32\...\V1JDNEZJQVdvcmxkUmFsbHlDaGFtcGlvbnNoaXA=_is1) (Version: 1 - )
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
27-07-2014 08:28:25 Scheduled Checkpoint
02-08-2014 08:35:03 Configured Platform
02-08-2014 08:36:31 Device Driver Package Install: ASUSTeK Sound, video and game controllers
02-08-2014 08:43:43 Device Driver Package Install: ASUSTeK Sound, video and game controllers
02-08-2014 09:08:58 Device Driver Package Install: ASUSTeK Sound, video and game controllers
02-08-2014 20:40:12 Checkpoint by HitmanPro
03-08-2014 08:38:41 Installed STOPzilla
03-08-2014 10:56:27 Removed STOPzilla
03-08-2014 13:20:10 OTL Restore Point - 8/3/2014 4:20:07 PM
03-08-2014 15:40:54 Configured Platform
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 05:34 - 2014-08-03 16:20 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {038FE625-8779-406B-9F67-A59D3DFFD2CB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {05AEC004-1AD3-4CAB-8ADD-736BE1CCE56C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-12] (Google Inc.)
Task: {06105206-841B-493F-884B-E58AA857EB82} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001Core => C:\Users\andrei\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-06-11] (Facebook Inc.)
Task: {23F1D5FB-C683-4189-BC8F-65D19E9BCCBB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-12] (Google Inc.)
Task: {64B31407-0BEB-42D9-B6FC-100DC1DC33A5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001UA => C:\Users\andrei\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-06-11] (Facebook Inc.)
Task: {7BED4E49-12D9-4721-8413-B8C83531263B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {8FB5F195-7D0B-4AD4-8B6D-D4F2D7F532C7} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {ACC338E2-F472-4982-8DA9-5A2CA43DFA18} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)
Task: {D4384AE5-40A1-4752-9620-669031CF442D} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2014-06-10] ()
Task: {DF5A125F-089C-42A2-A5CE-A4892FA9915A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001Core.job => C:\Users\andrei\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1376693644-3071282699-2049382522-1001UA.job => C:\Users\andrei\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-04-12 20:30 - 2014-03-04 16:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-10-18 01:27 - 2013-10-18 01:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2014-07-06 16:28 - 2014-07-06 16:28 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2013-08-27 22:42 - 2013-08-27 22:42 - 01260624 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll
2014-07-19 22:08 - 2014-07-15 12:24 - 00718664 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
2014-07-19 22:08 - 2014-07-15 12:24 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll
2014-07-19 22:08 - 2014-07-15 12:24 - 08537928 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll
2014-07-19 22:08 - 2014-07-15 12:24 - 00353096 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
2014-07-19 22:08 - 2014-07-15 12:24 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\.exe: exefile =>  <===== ATTENTION!
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\exefile:  <===== ATTENTION!
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Cmaudio8788 => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
MSCONFIG\startupreg: Cmaudio8788GX => C:\Windows\syswow64\HsMgr.exe Envoke
MSCONFIG\startupreg: Cmaudio8788GX64 => C:\Windows\system\HsMgr64.exe Envoke
MSCONFIG\startupreg: Facebook Update => "C:\Users\andrei\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: HDAudDeck => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files\PowerISO\PWRISOVM.EXE -startup
MSCONFIG\startupreg: uTorrent => "C:\Users\andrei\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: vmware-tray.exe => "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
 
==================== Faulty Device Manager Devices =============
 
Name: PortableVBoxDRV
Description: PortableVBoxDRV
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: VBoxDRV
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: PortableVBoxUSBMon
Description: PortableVBoxUSBMon
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: VBoxUSBMon
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/03/2014 06:40:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/03/2014 04:24:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/03/2014 04:19:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/03/2014 00:02:13 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Program Files (x86)\STOPzilla!\SZScanner.exe Files (x86)\STOPzilla!\SZScanner.exe" ; Description = STOPzilla Restore Point.; Error = 0x80042319).
 
Error: (08/03/2014 11:31:31 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (08/03/2014 11:22:52 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/02/2014 11:45:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/02/2014 11:40:34 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001fc,(null),0,REG_BINARY,0000000001FBED60.72).  hr = 0x80070005, Access is denied.
.
 
Error: (08/02/2014 11:40:34 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000006b4,(null),0,REG_BINARY,00000000027CE5C0.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {a376971c-d5f7-4761-b1d1-04a69d066ce6}
 
Error: (08/02/2014 11:40:34 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000006b4,(null),0,REG_BINARY,00000000027CE5C0.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {a376971c-d5f7-4761-b1d1-04a69d066ce6}
 
 
System errors:
=============
Error: (08/03/2014 06:39:02 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The VMware Workstation Server service terminated with service-specific error %%-1.
 
Error: (08/03/2014 06:39:01 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (08/03/2014 06:38:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PortableVBoxUSBMon service failed to start due to the following error: 
%%3
 
Error: (08/03/2014 06:38:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PortableVBoxDRV service failed to start due to the following error: 
%%3
 
Error: (08/03/2014 06:38:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sbapifs service failed to start due to the following error: 
%%2
 
Error: (08/03/2014 04:22:44 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The VMware Workstation Server service terminated with service-specific error %%-1.
 
Error: (08/03/2014 04:22:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (08/03/2014 04:22:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PortableVBoxUSBMon service failed to start due to the following error: 
%%3
 
Error: (08/03/2014 04:22:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PortableVBoxDRV service failed to start due to the following error: 
%%3
 
Error: (08/03/2014 04:22:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sbapifs service failed to start due to the following error: 
%%2
 
 
Microsoft Office Sessions:
=========================
Error: (08/03/2014 06:40:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/03/2014 04:24:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/03/2014 04:19:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/03/2014 00:02:13 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Program Files (x86)\STOPzilla!\SZScanner.exe Files (x86)\STOPzilla!\SZScanner.exe" STOPzilla Restore Point.0x80042319
 
Error: (08/03/2014 11:31:31 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (08/03/2014 11:22:52 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/02/2014 11:45:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/02/2014 11:40:34 PM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001fc,(null),0,REG_BINARY,0000000001FBED60.72)0x80070005, Access is denied.
 
Error: (08/02/2014 11:40:34 PM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000006b4,(null),0,REG_BINARY,00000000027CE5C0.72)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {a376971c-d5f7-4761-b1d1-04a69d066ce6}
 
Error: (08/02/2014 11:40:34 PM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000006b4,(null),0,REG_BINARY,00000000027CE5C0.72)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {a376971c-d5f7-4761-b1d1-04a69d066ce6}
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-05-18 02:26:26.737
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\qcusbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-05-18 02:26:26.734
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\qcusbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-05-18 01:21:04.216
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\qcusbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-05-18 01:21:04.213
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\qcusbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 34%
Total physical RAM: 4095.27 MB
Available physical RAM: 2662.75 MB
Total Pagefile: 8188.75 MB
Available Pagefile: 6515.66 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:97.66 GB) (Free:53.22 GB) NTFS
Drive d: () (Fixed) (Total:368.01 GB) (Free:118.78 GB) NTFS
Drive f: () (Removable) (Total:28.92 GB) (Free:28.83 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 2AAB059D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=368 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 29 GB) (Disk ID: 6E697373)
No partition Table on disk 1.
 
==================== End Of Log ============================

  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer behaving ?
 
Also what antivirus are you using ?

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

2014-08-02 11:37 - 2014-08-02 11:37 - 00000004 _____ () C:\Windows\SysWOW64\8Äl
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\exefile: <===== ATTENTION!
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:


Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
  • 0

#14
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

Here is the log that takes about 2 seconds to complete ,The pc now run smoother and i didn;t notice any problems ao any lags.The logs are showing the right way ? :)

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-08-2014
Ran by andrei at 2014-08-03 19:39:53 Run:1
Running from C:\Users\andrei\Downloads
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
2014-08-02 11:37 - 2014-08-02 11:37 - 00000004 _____ () C:\Windows\SysWOW64\8Äl
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\exefile: <===== ATTENTION!
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:
*****************
 
C:\Windows\SysWOW64\8Äl => Moved successfully.
"HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\.exe" => Key deleted successfully.
"HKU\S-1-5-21-1376693644-3071282699-2049382522-1001\Software\Classes\exefile" => Key not found.
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
0 out of 0 jobs canceled.
 
========= End of CMD: =========
 
 
=========  DEL %TEMP%\*.* /F /S /Q =========
 
Deleted file - C:\Users\andrei\AppData\Local\Temp\adb.log
C:\Users\andrei\AppData\Local\Temp\FXSAPIDebugLogFile.txt
The process cannot access the file because it is being used by another process.
Deleted file - C:\Users\andrei\AppData\Local\Temp\HitmanPro.exe
Deleted file - C:\Users\andrei\AppData\Local\Temp\isE5EB.tmp
Deleted file - C:\Users\andrei\AppData\Local\Temp\MSIe32c.LOG
Deleted file - C:\Users\andrei\AppData\Local\Temp\vminst.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{197597A7-AD33-4898-9D8E-73066818B464}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{D102611A-6466-4101-A51D-51069303AC65}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmsetup.20140803190655.{FFD9383C-01D5-4897-A954-43AF599AED30}.uninstall.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\VMW2EAD.tmp
Deleted file - C:\Users\andrei\AppData\Local\Temp\_iu14D2N.tmp
Deleted file - C:\Users\andrei\AppData\Local\Temp\vmware-andrei\vmware-vix-4048.log
Deleted file - C:\Users\andrei\AppData\Local\Temp\~nsu.tmp\Au_.exe
 
========= End of CMD: =========
 
 
=========  RD /S /Q %TEMP% =========
 
C:\Users\andrei\AppData\Local\Temp\FXSAPIDebugLogFile.txt - The process cannot access the file because it is being used by another process.
 
========= End of CMD: =========
 
 
 
The system needed a reboot. 
 
==== End of Fixlog ====

  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
This was a fairly new piece of malware only two AV's detect it at the moment

Do you have an antivirus
  • 0






Similar Topics


Also tagged with one or more of these keywords: malware

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP