Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
- Ran by w7 at 2014-03-29 13:40:10
- Running from C:\Users\w7\Downloads
- Boot Mode: Normal
- ==========================================================
- ==================== Security Center ========================
- AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
- AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
- ==================== Installed Programs ======================
- 2007 Microsoft Office Suite Service Pack 2 (SP2) (x32 Version: - Microsoft) Hidden
- 2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
- ACDSee Pro 3 (HKLM-x32\...\{1B280FAF-AE10-4E31-A41A-DB3917D651DC}) (Version: 3.0.355 - ACD Systems International Inc.)
- Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
- AMD Catalyst Install Manager (HKLM\...\{AC2AAFF8-6719-A420-AB9F-7E5F5E6CA46A}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
- Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.110 - Atheros)
- avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2016 - Avast Software)
- Broadcom Card Reader Driver Installer (HKLM\...\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 15.0.7.2 - Broadcom Corporation)
- BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.53.1034 - Webteh, d.o.o.)
- Catalyst Control Center InstallProxy (x32 Version: 2012.0611.1251.21046 - Advanced Micro Devices, Inc.) Hidden
- CCleaner (HKLM\...\CCleaner) (Version: 3.20 - Piriform)
- Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.48.0 - Conexant)
- CyberLink PowerDVD (HKLM-x32\...\CyberLink PowerDVD) (Version: - )
- D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
- Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
- Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
- Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3006 - Intel Corporation)
- Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
- Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
- Java 7 Update 13 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417013FF}) (Version: 7.0.130 - Oracle)
- Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Malwarebytes Anti-Malware version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation)
- Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
- Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
- Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
- Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
- Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
- Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
- Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
- Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
- Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
- Mozilla Firefox 20.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 20.0 (x86 en-US)) (Version: 20.0 - Mozilla)
- Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 20.0 - Mozilla)
- MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
- MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
- NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
- Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.23.623.2010 - Realtek)
- Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
- Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29018 - Realtek Semiconductor Corp.)
- Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0013 - REALTEK Semiconductor Corp.)
- Skype™ 6.1 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.1.129 - Skype Technologies S.A.)
- TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.22298 - TeamViewer)
- Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
- Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2473228) (Version: 1 - Microsoft Corporation)
- Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
- Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
- Winamp (HKLM-x32\...\Winamp) (Version: 5.601 - Nullsoft, Inc)
- Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
- Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
- Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
- Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
- Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
- Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
- WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - )
- WinZip 15.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}) (Version: 15.0.9334 - WinZip Computing, S.L. )
- ==================== Restore Points =========================
- 29-03-2014 08:26:28 Scheduled Checkpoint
- ==================== Hosts content: ==========================
- 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
- ==================== Scheduled Tasks (whitelisted) =============
- Task: {1B70276C-C0BB-4CB7-BFB2-21AE786B4C19} - System32\Tasks\{BB872FAC-72FF-4E3A-BE98-8F3D09DEDFC9} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-01-08] (Skype Technologies S.A.)
- Task: {2A4C3787-47A3-41B0-96AA-DEFCE0A6D55C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-03] (Google Inc.)
- Task: {2EC21D08-9159-411B-9DB1-690C049BF252} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-03-28] (AVAST Software)
- Task: {4DCBC5AB-0593-4257-BFFA-E7DB6542AEE0} - System32\Tasks\{618608D7-4D63-457F-845A-918419725293} => Iexplore.exe http://ui.skype.com/ui/0/5.10.60.116/en/go/help.faq.installer?LastError=1618
- Task: {55FFAF8A-26D2-49E4-BB56-4F69A79DF669} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-06-22] (Piriform Ltd)
- Task: {618F97E0-A538-4D75-AD0E-E4F490F43A11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-03] (Google Inc.)
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- ==================== Loaded Modules (whitelisted) =============
- 2010-12-07 11:59 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
- 2014-03-28 22:24 - 2014-03-28 22:24 - 02189312 _____ () C:\Program Files\AVAST Software\Avast\defs\14032801\algo.dll
- 2014-03-29 13:33 - 2014-03-29 13:33 - 02189312 _____ () C:\Program Files\AVAST Software\Avast\defs\14032900\algo.dll
- 2014-03-28 16:29 - 2014-03-28 16:29 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
- 2012-11-02 10:07 - 2012-02-08 09:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
- 2014-03-15 18:40 - 2014-03-15 01:50 - 13637448 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll
- ==================== Alternate Data Streams (whitelisted) =========
- ==================== Safe Mode (whitelisted) ===================
- ==================== Disabled items from MSCONFIG ==============
- MSCONFIG\Services: !SASCORE => 2
- MSCONFIG\Services: AdobeARMservice => 2
- MSCONFIG\Services: AMD External Events Utility => 2
- MSCONFIG\Services: AMD FUEL Service => 2
- MSCONFIG\Services: MozillaMaintenance => 3
- MSCONFIG\Services: PanService => 2
- MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
- MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
- MSCONFIG\startupreg: NvMediaCenter => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
- MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
- MSCONFIG\startupreg: RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
- MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
- MSCONFIG\startupreg: TBHostSupport => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\w7\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin
- ==================== Faulty Device Manager Devices =============
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (03/28/2014 10:23:00 PM) (Source: Windows Search Service) (User: )
- Description: The index cannot be initialized.
- Details:
- The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
- Error: (03/28/2014 10:23:00 PM) (Source: Windows Search Service) (User: )
- Description: The application cannot be initialized.
- Context: Windows Application
- Details:
- The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
- Error: (03/28/2014 10:23:00 PM) (Source: Windows Search Service) (User: )
- Description: The gatherer object cannot be initialized.
- Context: Windows Application, SystemIndex Catalog
- Details:
- The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
- Error: (03/28/2014 10:23:00 PM) (Source: Windows Search Service) (User: )
- Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.
- Context: Windows Application, SystemIndex Catalog
- Details:
- Element not found. (HRESULT : 0x80070490) (0x80070490)
- Error: (03/28/2014 10:22:59 PM) (Source: Windows Search Service) (User: )
- Description: The plug-in in <Search.JetPropStore> cannot be initialized.
- Context: Windows Application, SystemIndex Catalog
- Details:
- The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
- Error: (03/28/2014 10:22:58 PM) (Source: Windows Search Service) (User: )
- Description: The Windows Search Service cannot load the property store information.
- Context: Windows Application, SystemIndex Catalog
- Details:
- The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800)
- Error: (03/28/2014 10:22:58 PM) (Source: Windows Search Service) (User: )
- Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.
- Details:
- The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
- Error: (03/28/2014 10:22:58 PM) (Source: Windows Search Service) (User: )
- Description: The search service has detected corrupted data files in the index {id=4700}. The service will attempt to automatically correct this problem by rebuilding the index.
- Details:
- The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
- Error: (03/28/2014 10:22:57 PM) (Source: Windows Search Service) (User: )
- Description: The Windows Search Service cannot open the Jet property store.
- Details:
- 0x%08x (0xc0041800 - The content index database is corrupt. (HRESULT : 0xc0041800))
- Error: (03/28/2014 10:22:57 PM) (Source: ESENT) (User: )
- Description: Windows (2500) Windows: Error -1811 occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS000ED.log.
- System errors:
- =============
- Error: (03/29/2014 09:23:46 AM) (Source: volsnap) (User: )
- Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 09:23:16 AM) (Source: atapi) (User: )
- Description: The driver detected a controller error on \Device\Ide\IdePort0.
- Error: (03/29/2014 07:17:26 AM) (Source: Microsoft-Windows-WHEA-Logger) (User: NT AUTHORITY)
- Description: A fatal hardware error has occurred.
- Component: AMD Northbridge
- Error Source: 3
- Error Type: 11
- Processor ID: 0
- The details view of this entry contains further information.
- Error: (03/28/2014 10:23:33 PM) (Source: Service Control Manager) (User: )
- Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
- %%1056
- Microsoft Office Sessions:
- =========================
- CodeIntegrity Errors:
- ===================================
- Date: 2014-03-28 21:33:52.582
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2014-03-28 21:33:05.479
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2014-03-28 16:46:39.204
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2014-03-28 16:42:44.694
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2014-03-28 16:41:58.791
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2014-03-28 16:40:52.863
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2014-03-28 16:40:48.154
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2013-12-15 22:12:45.303
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2013-12-15 22:12:44.308
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
- Date: 2011-04-02 16:17:04.742
- Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbehci.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
- ==================== Memory info ===========================
- Percentage of memory in use: 69%
- Total physical RAM: 1791.11 MB
- Available physical RAM: 549.53 MB
- Total Pagefile: 3582.23 MB
- Available Pagefile: 1697.99 MB
- Total Virtual: 8192 MB
- Available Virtual: 8191.82 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:162.34 GB) (Free:104.14 GB) NTFS
- Drive d: () (Fixed) (Total:135.16 GB) (Free:134.85 GB) NTFS
- Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
- Ran by w7 (administrator) on W7-PC on 29-03-2014 13:37:21
- Running from C:\Users\w7\Downloads
- Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
- Internet Explorer Version 10
- Boot Mode: Normal
- The only official download link for FRST:
- Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
- Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
- Download link from any site other than Bleeping Computer is unpermitted or outdated.
- See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
- (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
- (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
- (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- ==================== Registry (Whitelisted) ==================
- HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
- HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [15960096 2009-01-29] (NVIDIA Corporation)
- HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-28] (AVAST Software)
- Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
- ==================== Internet (Whitelisted) ====================
- HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ba/
- HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
- HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6E4F4E14C4BECB01
- HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
- BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
- BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
- BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
- BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
- BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
- BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
- BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
- BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
- Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
- Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
- Tcpip\Parameters: [DhcpNameServer] 217.23.207.3 217.23.192.14
- FireFox:
- ========
- FF ProfilePath: C:\Users\w7\AppData\Roaming\Mozilla\Firefox\Profiles\7ebpw71m.default
- FF user.js: detected! => C:\Users\w7\AppData\Roaming\Mozilla\Firefox\Profiles\7ebpw71m.default\user.js
- FF Plugin: @java.com/DTPlugin,version=10.13.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
- FF Plugin: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF Plugin: @microsoft.com/GENUINE - disabled No File
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
- FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
- FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
- FF Extension: Feedback - C:\Users\w7\AppData\Roaming\Mozilla\Firefox\Profiles\7ebpw71m.default\Extensions\[email protected] [2012-05-07]
- FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
- FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
- FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-03]
- FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
- Chrome:
- =======
- CHR Extension: (Google Docs) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-03]
- CHR Extension: (Google disk) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-03]
- CHR Extension: (YouTube) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-03]
- CHR Extension: (uTorrentControl_v6) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp [2013-11-09]
- CHR Extension: (Google pretraživanje) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-03]
- CHR Extension: (Google Novčanik) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-03]
- CHR Extension: (Gmail) - C:\Users\w7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-03]
- CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\w7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-10-21]
- CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\w7\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-10-21]
- ==================== Services (Whitelisted) =================
- R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-28] (AVAST Software)
- R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation)
- S4 MBAMScheduler; D:\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
- S2 MBAMService; D:\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
- R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-11-29] (Atheros)
- S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [X]
- ==================== Drivers (Whitelisted) ====================
- R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-03-28] (AVAST Software)
- R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-03-28] (AVAST Software)
- R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-03-28] ()
- R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-03-28] (AVAST Software)
- R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-03-28] (AVAST Software)
- R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-03-28] (AVAST Software)
- R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-03-28] ()
- R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET)
- S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-09-26] ()
- S3 L1C; C:\Windows\System32\DRIVERS\L1C60x64.sys [76912 2011-03-23] (Atheros Communications, Inc.)
- R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation)
- S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [262248 2012-04-12] (Realtek Semiconductor Corp.)
- S1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
- S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
- S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
- S3 VGPU; System32\drivers\rdvgkmd.sys [X]
- ==================== NetSvcs (Whitelisted) ===================
- ==================== One Month Created Files and Folders ========
- 2014-03-29 13:37 - 2014-03-29 13:38 - 00011119 _____ () C:\Users\w7\Downloads\FRST.txt
- 2014-03-29 13:36 - 2014-03-29 13:37 - 00000000 ____D () C:\FRST
- 2014-03-29 13:34 - 2014-03-29 13:35 - 02157056 _____ (Farbar) C:\Users\w7\Downloads\FRST64.exe
- 2014-03-28 22:22 - 2014-03-29 07:16 - 00000168 _____ () C:\Windows\setupact.log
- 2014-03-28 22:22 - 2014-03-28 22:22 - 00282960 _____ () C:\Windows\Minidump\032814-24398-01.dmp
- 2014-03-28 22:22 - 2014-03-28 22:22 - 00000000 _____ () C:\Windows\setuperr.log
- 2014-03-28 22:21 - 2014-03-29 06:57 - 00002274 _____ () C:\Windows\PFRO.log
- 2014-03-28 22:21 - 2014-03-28 22:21 - 356039275 _____ () C:\Windows\MEMORY.DMP
- 2014-03-28 20:08 - 2014-03-28 20:09 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
- 2014-03-28 20:07 - 2014-03-28 20:07 - 00000613 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- 2014-03-28 20:07 - 2014-03-28 20:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
- 2014-03-28 20:07 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
- 2014-03-28 20:07 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
- 2014-03-28 20:07 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
- 2014-03-28 20:04 - 2014-03-28 20:06 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\w7\Downloads\mbam-setup-2.0.0.1000.exe
- 2014-03-28 18:02 - 2014-03-28 18:02 - 00000000 ____D () C:\Users\w7\AppData\Roaming\AVAST Software
- 2014-03-28 16:29 - 2014-03-28 16:29 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
- 2014-03-28 16:29 - 2014-03-28 16:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
- 2014-03-27 23:34 - 2014-03-27 23:34 - 01819786 _____ () C:\Users\w7\Downloads\slajdovi_mm1 (2).zip
- 2014-03-27 23:34 - 2014-03-27 23:34 - 01267824 _____ () C:\Users\w7\Downloads\vezbe_mm1 (2).zip
- 2014-03-27 23:32 - 2014-03-27 23:33 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo (3).7z
- 2014-03-27 23:30 - 2014-03-27 23:30 - 00061440 _____ () C:\Users\w7\Downloads\Domaci_12_A456b.xls
- 2014-03-27 23:27 - 2014-03-27 23:27 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo (2).7z
- 2014-03-27 23:24 - 2014-03-27 23:25 - 00205824 _____ () C:\Users\w7\Downloads\PrezentacijaDMS.ppt
- 2014-03-27 23:24 - 2014-03-27 23:24 - 00086247 _____ () C:\Users\w7\Downloads\domaci.exe
- 2014-03-26 17:23 - 2014-03-26 17:24 - 01819786 _____ () C:\Users\w7\Downloads\slajdovi_mm1 (1).zip
- 2014-03-26 17:23 - 2014-03-26 17:24 - 01267824 _____ () C:\Users\w7\Downloads\vezbe_mm1 (1).zip
- 2014-03-26 00:48 - 2014-03-26 00:48 - 00459344 _____ () C:\Users\w7\Downloads\MA1_test_drugi_deo.zip
- 2014-03-23 12:45 - 2014-03-23 12:45 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo.7z
- 2014-03-23 12:45 - 2014-03-23 12:45 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo (1).7z
- 2014-03-23 12:45 - 2014-03-23 12:45 - 00255803 _____ () C:\Users\w7\Downloads\D1P.rar
- 2014-03-23 12:43 - 2014-03-23 12:43 - 01267824 _____ () C:\Users\w7\Downloads\vezbe_mm1.zip
- 2014-03-23 12:40 - 2014-03-23 12:40 - 01819786 _____ () C:\Users\w7\Downloads\slajdovi_mm1.zip
- 2014-03-23 12:25 - 2014-03-23 12:25 - 00290606 _____ () C:\Users\w7\Downloads\spiskovi-2013.rar
- 2014-03-23 12:24 - 2014-03-23 12:24 - 03285172 _____ () C:\Users\w7\Downloads\PK.rar
- 2014-03-19 23:33 - 2014-03-28 22:22 - 00000000 ____D () C:\Windows\Minidump
- 2014-03-19 14:39 - 2014-03-19 14:39 - 04947968 _____ () C:\Users\w7\Downloads\00222_20140303_Prva_sedmica_2012.ppt
- 2014-03-19 14:34 - 2014-03-19 14:35 - 02445110 _____ () C:\Users\w7\Downloads\OM14-P1.pptx
- ==================== One Month Modified Files and Folders =======
- 2014-03-29 13:38 - 2014-03-29 13:37 - 00011119 _____ () C:\Users\w7\Downloads\FRST.txt
- 2014-03-29 13:37 - 2014-03-29 13:36 - 00000000 ____D () C:\FRST
- 2014-03-29 13:35 - 2014-03-29 13:34 - 02157056 _____ (Farbar) C:\Users\w7\Downloads\FRST64.exe
- 2014-03-29 13:33 - 2013-10-03 21:52 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- 2014-03-29 13:33 - 2012-11-02 10:56 - 01277228 _____ () C:\Windows\WindowsUpdate.log
- 2014-03-29 07:55 - 2009-07-14 05:45 - 00010208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2014-03-29 07:55 - 2009-07-14 05:45 - 00010208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2014-03-29 07:17 - 2013-10-03 21:52 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- 2014-03-29 07:17 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
- 2014-03-29 07:16 - 2014-03-28 22:22 - 00000168 _____ () C:\Windows\setupact.log
- 2014-03-29 06:57 - 2014-03-28 22:21 - 00002274 _____ () C:\Windows\PFRO.log
- 2014-03-28 22:24 - 2013-10-03 22:42 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
- 2014-03-28 22:22 - 2014-03-28 22:22 - 00282960 _____ () C:\Windows\Minidump\032814-24398-01.dmp
- 2014-03-28 22:22 - 2014-03-28 22:22 - 00000000 _____ () C:\Windows\setuperr.log
- 2014-03-28 22:22 - 2014-03-19 23:33 - 00000000 ____D () C:\Windows\Minidump
- 2014-03-28 22:21 - 2014-03-28 22:21 - 356039275 _____ () C:\Windows\MEMORY.DMP
- 2014-03-28 22:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
- 2014-03-28 22:02 - 2010-12-07 12:17 - 00000000 ____D () C:\Users\w7\AppData\Roaming\Skype
- 2014-03-28 20:09 - 2014-03-28 20:08 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
- 2014-03-28 20:07 - 2014-03-28 20:07 - 00000613 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- 2014-03-28 20:07 - 2014-03-28 20:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
- 2014-03-28 20:06 - 2014-03-28 20:04 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\w7\Downloads\mbam-setup-2.0.0.1000.exe
- 2014-03-28 19:48 - 2013-09-04 12:16 - 00000000 ____D () C:\Users\w7\AppData\Local\CrashDumps
- 2014-03-28 19:01 - 2010-12-07 11:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
- 2014-03-28 18:45 - 2010-12-07 11:21 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer
- 2014-03-28 18:02 - 2014-03-28 18:02 - 00000000 ____D () C:\Users\w7\AppData\Roaming\AVAST Software
- 2014-03-28 16:29 - 2014-03-28 16:29 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
- 2014-03-28 16:29 - 2014-03-28 16:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
- 2014-03-28 16:29 - 2013-10-03 22:42 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
- 2014-03-28 16:29 - 2013-10-03 22:42 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
- 2014-03-28 16:25 - 2013-10-03 22:39 - 00000000 ____D () C:\ProgramData\AVAST Software
- 2014-03-28 16:24 - 2013-10-03 22:42 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
- 2014-03-27 23:34 - 2014-03-27 23:34 - 01819786 _____ () C:\Users\w7\Downloads\slajdovi_mm1 (2).zip
- 2014-03-27 23:34 - 2014-03-27 23:34 - 01267824 _____ () C:\Users\w7\Downloads\vezbe_mm1 (2).zip
- 2014-03-27 23:33 - 2014-03-27 23:32 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo (3).7z
- 2014-03-27 23:30 - 2014-03-27 23:30 - 00061440 _____ () C:\Users\w7\Downloads\Domaci_12_A456b.xls
- 2014-03-27 23:27 - 2014-03-27 23:27 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo (2).7z
- 2014-03-27 23:25 - 2014-03-27 23:24 - 00205824 _____ () C:\Users\w7\Downloads\PrezentacijaDMS.ppt
- 2014-03-27 23:24 - 2014-03-27 23:24 - 00086247 _____ () C:\Users\w7\Downloads\domaci.exe
- 2014-03-26 21:29 - 2013-08-29 12:03 - 00520192 _____ () C:\Users\w7\Documents\bbbbbbbbbbb.accdb
- 2014-03-26 17:24 - 2014-03-26 17:23 - 01819786 _____ () C:\Users\w7\Downloads\slajdovi_mm1 (1).zip
- 2014-03-26 17:24 - 2014-03-26 17:23 - 01267824 _____ () C:\Users\w7\Downloads\vezbe_mm1 (1).zip
- 2014-03-26 00:48 - 2014-03-26 00:48 - 00459344 _____ () C:\Users\w7\Downloads\MA1_test_drugi_deo.zip
- 2014-03-23 12:45 - 2014-03-23 12:45 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo.7z
- 2014-03-23 12:45 - 2014-03-23 12:45 - 00502919 _____ () C:\Users\w7\Downloads\M1-Ideo (1).7z
- 2014-03-23 12:45 - 2014-03-23 12:45 - 00255803 _____ () C:\Users\w7\Downloads\D1P.rar
- 2014-03-23 12:43 - 2014-03-23 12:43 - 01267824 _____ () C:\Users\w7\Downloads\vezbe_mm1.zip
- 2014-03-23 12:40 - 2014-03-23 12:40 - 01819786 _____ () C:\Users\w7\Downloads\slajdovi_mm1.zip
- 2014-03-23 12:25 - 2014-03-23 12:25 - 00290606 _____ () C:\Users\w7\Downloads\spiskovi-2013.rar
- 2014-03-23 12:24 - 2014-03-23 12:24 - 03285172 _____ () C:\Users\w7\Downloads\PK.rar
- 2014-03-19 14:39 - 2014-03-19 14:39 - 04947968 _____ () C:\Users\w7\Downloads\00222_20140303_Prva_sedmica_2012.ppt
- 2014-03-19 14:35 - 2014-03-19 14:34 - 02445110 _____ () C:\Users\w7\Downloads\OM14-P1.pptx
- 2014-03-15 18:41 - 2013-10-03 22:00 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
- 2014-03-13 07:12 - 2009-07-14 06:08 - 00032614 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
- 2014-03-06 16:23 - 2014-02-12 00:24 - 00000000 ____D () C:\Users\w7\AppData\Local\Microsoft Games
- 2014-03-05 09:26 - 2014-03-28 20:07 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
- 2014-03-05 09:26 - 2014-03-28 20:07 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
- 2014-03-05 09:26 - 2014-03-28 20:07 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
- Some content of TEMP:
- ====================
- C:\Users\w7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp65c8bx.dll
- ==================== Bamital & volsnap Check =================
- C:\Windows\System32\winlogon.exe => MD5 is legit
- C:\Windows\System32\wininit.exe => MD5 is legit
- C:\Windows\SysWOW64\wininit.exe => MD5 is legit
- C:\Windows\explorer.exe => MD5 is legit
- C:\Windows\SysWOW64\explorer.exe => MD5 is legit
- C:\Windows\System32\svchost.exe => MD5 is legit
- C:\Windows\SysWOW64\svchost.exe => MD5 is legit
- C:\Windows\System32\services.exe => MD5 is legit
- C:\Windows\System32\User32.dll => MD5 is legit
- C:\Windows\SysWOW64\User32.dll => MD5 is legit
- C:\Windows\System32\userinit.exe => MD5 is legit
- C:\Windows\SysWOW64\userinit.exe => MD5 is legit
- C:\Windows\System32\rpcss.dll => MD5 is legit
- C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement