FRST.txt

Gameharbor samczynnie sie wlacza

Siemanko przy wlaczaniu komputera otwiera mi sie firefox i ta strona : gameharbor.org wyczytalem ze to wirus wiec prosze o porade :)


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-10-2014 01
Ran by Milka (administrator) on MILKA-KOMPUTER on 08-10-2014 20:21:06
Running from C:\Users\Milka\Downloads
Loaded Profile: Milka (Available profiles: Milka)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Polski (Polska)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(BitTorrent Inc.) C:\Users\Milka\AppData\Roaming\uTorrent\uTorrent.exe
(GG Network S.A.) C:\Users\Milka\AppData\Local\GG\Application\gghub.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(GG Network S.A.) C:\Users\Milka\AppData\Local\GG\Application\ggapp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(TeamSpeak Systems GmbH) D:\Programy\TS3\ts3client_win64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] = & gt; C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] = & gt; C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] = & gt; C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] = & gt; C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] = & gt; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [hpqSRMon] = & gt; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] = & gt; C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [KiesTrayAgent] = & gt; C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [GrooveMonitor] = & gt; C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [uTorrent] = & gt; C:\Users\Milka\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-09-27] (BitTorrent Inc.)
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [DAEMON Tools Lite] = & gt; D:\Programy\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [Akamai NetSession Interface] = & gt; " C:\Users\Milka\AppData\Local\Akamai\netsession_win.exe "
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [GG] = & gt; C:\Users\Milka\AppData\Local\GG\Application\gghub.exe [4023360 2014-09-04] (GG Network S.A.)
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [KiesPreload] = & gt; C:\Program Files (x86)\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [KiesAirMessage] = & gt; C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [CMD] = & gt; cmd.exe /c start http://adverttraff.org & & exit & lt; ===== ATTENTION
HKU\S-1-5-21-3131631985-524455086-708686687-1000\...\Run: [CCleaner Monitoring] = & gt; C:\Program Files\CCleaner\CCleaner64.exe [6480664 2014-09-25] (Piriform Ltd)
AppInit_DLLs: C:\ProgramData\Fast And = & gt; C:\ProgramData\Fast And File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk - & gt; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] - & gt; {472083B0-C522-11CF-8763-00608CC02F24} = & gt; No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO-x32: HP Print Enhancer - & gt; {0347C33E-8762-4905-BF09-768834316C61} - & gt; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; D:\Programy\Java\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; D:\Programy\Java\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class - & gt; {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - & gt; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.20

FireFox:
========
FF ProfilePath: C:\Users\Milka\AppData\Roaming\Mozilla\Firefox\Profiles\qphi29jp.default
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @esn/npbattlelog,version=2.5.1 - & gt; C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - & gt; C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - & gt; C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 - & gt; C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - & gt; D:\Programy\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - & gt; D:\Programy\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - & gt; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - & gt; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - & gt; C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - & gt; C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-07-09]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction & lt; ======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-10-01] ()
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-01] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation )
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [206080 2014-06-16] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2009-07-14] (Microsoft Corporation)
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-08 20:20 - 2014-10-08 20:21 - 00012427 _____ () C:\Users\Milka\Downloads\FRST.txt
2014-10-08 20:13 - 2014-10-08 20:21 - 00000000 ____D () C:\FRST
2014-10-08 20:12 - 2014-10-08 20:12 - 02109952 _____ (Farbar) C:\Users\Milka\Downloads\FRST64(1).exe
2014-10-08 20:07 - 2014-10-08 20:07 - 02109952 _____ (Farbar) C:\Users\Milka\Downloads\FRST64.exe
2014-10-08 20:07 - 2014-10-08 20:07 - 01375089 _____ () C:\Users\Milka\Downloads\AdwCleaner.exe
2014-10-08 20:06 - 2014-10-08 20:06 - 00000806 _____ () C:\Users\Milka\Desktop\fixlist.txt
2014-10-08 17:04 - 2014-10-08 17:04 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-10-08 17:03 - 2014-09-13 22:13 - 00613696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-10-08 17:01 - 2014-09-17 06:51 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-10-08 17:01 - 2014-09-17 06:51 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 31887680 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 24552592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 19954520 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 14026304 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 13939272 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 13157696 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-10-08 17:01 - 2014-09-14 01:48 - 11392576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 11330776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 04287296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 04008592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 01876296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434411.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 01539272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434411.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00957584 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00925896 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00919240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00894096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00867528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00501064 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00417096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00393024 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00352016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00348304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00303600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00174856 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-10-08 17:01 - 2014-09-14 01:48 - 00156840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-10-08 17:00 - 2014-09-14 01:48 - 20922512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-10-08 17:00 - 2014-09-14 01:48 - 17259664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-10-08 16:34 - 2014-09-04 21:14 - 00038048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-10-08 16:34 - 2014-09-04 21:14 - 00032416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-10-07 16:54 - 2014-10-07 17:00 - 00000000 ____D () C:\Users\Milka\Desktop\4444
2014-10-06 18:09 - 2014-10-06 18:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-10-06 18:08 - 2014-10-06 18:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-10-06 18:07 - 2014-10-06 18:07 - 00000000 ____D () C:\Windows\PCHEALTH
2014-10-06 18:07 - 2014-10-06 18:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2014-10-06 18:06 - 2014-10-06 18:06 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-10-06 18:05 - 2014-10-06 18:10 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-06 18:05 - 2014-10-06 18:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-10-06 18:05 - 2014-10-06 18:05 - 00000000 ____D () C:\Users\Milka\AppData\Local\Microsoft Help
2014-10-06 18:05 - 2014-10-06 18:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-10-06 18:04 - 2014-10-06 18:04 - 00000000 __RHD () C:\MSOCache
2014-10-04 18:09 - 2014-10-04 18:09 - 00000000 ____D () C:\Users\Milka\Documents\Ashampoo Burning Studio FREE
2014-10-04 18:09 - 2014-10-04 18:09 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\Ashampoo
2014-10-04 18:08 - 2014-10-04 18:08 - 00001228 _____ () C:\Users\Public\Desktop\CleverReach.com.lnk
2014-10-04 18:08 - 2014-10-04 18:08 - 00000772 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio FREE.lnk
2014-10-04 18:08 - 2014-10-04 18:08 - 00000214 _____ () C:\Users\Public\Desktop\Your Software Deals.url
2014-10-04 18:08 - 2014-10-04 18:08 - 00000000 ____D () C:\Users\Milka\AppData\Local\ashampoo
2014-10-04 18:08 - 2014-10-04 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-10-04 18:08 - 2014-10-04 18:08 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-10-04 18:07 - 2014-10-04 18:07 - 33551464 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Milka\Downloads\ashampoo_burning_studio_free_1.14.5_sm.exe
2014-10-02 16:10 - 2014-10-08 20:16 - 00001886 _____ () C:\Windows\setupact.log
2014-10-02 16:10 - 2014-10-08 20:11 - 00001134 _____ () C:\Windows\PFRO.log
2014-10-02 16:10 - 2014-10-02 16:10 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-01 21:17 - 2014-10-07 21:53 - 00348928 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-10-01 21:17 - 2014-10-01 21:25 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-10-01 21:17 - 2013-02-13 08:52 - 02580552 _____ () C:\Windows\SysWOW64\pbsvc.exe
2014-10-01 21:05 - 2014-10-01 21:05 - 01402920 _____ () C:\Users\Milka\Downloads\battlelog-web-plugins_2.5.1_149.exe
2014-09-29 08:13 - 2014-09-29 08:13 - 04964488 _____ (Piriform Ltd) C:\Users\Milka\Downloads\ccsetup418.exe
2014-09-28 17:43 - 2014-09-28 17:56 - 00000000 ____D () C:\Users\Milka\Desktop\33333
2014-09-25 16:27 - 2014-09-25 16:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-25 00:01 - 2014-09-25 00:01 - 00000000 ____D () C:\Users\Milka\Desktop\3333
2014-09-24 14:15 - 2014-09-24 14:15 - 00874236 _____ () C:\Users\Milka\Downloads\32 - In Loving Memory Of Francesco Potenza - Catch up with Joe.zip
2014-09-24 14:15 - 2014-09-24 14:15 - 00000000 ____D () C:\Users\Milka\Downloads\32 - In Loving Memory Of Francesco Potenza - Catch up with Joe
2014-09-24 14:15 - 2012-03-21 03:05 - 00757036 _____ () C:\Users\Milka\Downloads\sav700.dat
2014-09-24 14:15 - 2012-03-21 03:05 - 00012542 _____ () C:\Users\Milka\Downloads\profile.dat
2014-09-24 14:15 - 2012-03-21 03:00 - 00757379 _____ () C:\Users\Milka\Downloads\sav1.dat
2014-09-24 14:14 - 2014-09-27 21:00 - 00000000 ____D () C:\Users\Milka\Desktop\76561201696194287
2014-09-24 14:12 - 2014-09-24 14:12 - 00815249 _____ () C:\Users\Milka\Downloads\31 - Time Well Spent - Settle the score with O`Neill.zip
2014-09-24 14:12 - 2014-09-24 14:12 - 00000000 ____D () C:\Users\Milka\Downloads\31 - Time Well Spent - Settle the score with O`Neill
2014-09-24 00:03 - 2014-09-24 00:03 - 00000000 ____D () C:\Users\Milka\Documents\Stronghold Crusader 2
2014-09-24 00:03 - 2014-09-24 00:03 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\Steam
2014-09-24 00:02 - 2014-09-24 00:02 - 00000990 _____ () C:\Users\Public\Desktop\Stronghold Crusader 2.lnk
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stronghold Crusader 2
2014-09-22 23:10 - 2014-09-22 23:10 - 00000000 ____D () C:\Users\Milka\AppData\Local\SKIDROW
2014-09-22 23:10 - 2014-09-22 23:10 - 00000000 ____D () C:\Users\Milka\AppData\Local\2K Games
2014-09-22 20:50 - 2014-09-22 20:50 - 00000457 _____ () C:\Users\Milka\Desktop\Mafia II.lnk
2014-09-22 20:50 - 2014-09-22 20:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\O22y Inc
2014-09-18 21:27 - 2014-09-18 21:28 - 00000000 ____D () C:\Users\Milka\Desktop\tel
2014-09-17 21:19 - 2014-09-17 21:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-09-17 21:19 - 2014-06-14 16:03 - 00260696 _____ () C:\Windows\system32\unrar64.dll
2014-09-17 21:18 - 2014-09-17 21:19 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
2014-09-17 21:17 - 2014-09-17 21:17 - 31076799 _____ ( ) C:\Users\Milka\Downloads\K-Lite_Codec_Pack_1071_Full.exe
2014-09-17 21:16 - 2014-09-17 21:16 - 00747456 _____ ( ) C:\Users\Milka\Downloads\KLite-Codec-Pack(13137)-dp.exe
2014-09-09 08:34 - 2014-09-09 08:34 - 02435458 _____ () C:\Users\Milka\Downloads\Samsung 920nw.rar
2014-09-09 08:34 - 2011-11-24 17:03 - 00000000 ____D () C:\Users\Milka\Downloads\Samsung 920nw
2014-09-09 08:16 - 2014-09-09 08:16 - 00000000 ____D () C:\Users\Milka\Downloads\Phoenix13zip
2014-09-09 08:16 - 2007-05-03 17:19 - 00014032 _____ (EnTech Taiwan) C:\Windows\system32\Drivers\se64a.sys
2014-09-09 08:15 - 2014-09-09 08:15 - 01212232 _____ () C:\Users\Milka\Downloads\phoenixediddesigner-setup.exe
2014-09-09 08:15 - 2014-09-09 08:15 - 00453984 _____ (EnTech Taiwan) C:\Users\Milka\Downloads\moninfo.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-08 20:20 - 2014-06-01 13:44 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\TS3Client
2014-10-08 20:19 - 2014-05-29 21:42 - 00800756 _____ () C:\Windows\WindowsUpdate.log
2014-10-08 20:16 - 2014-07-31 20:28 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\GG
2014-10-08 20:16 - 2014-05-30 13:17 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\uTorrent
2014-10-08 20:16 - 2014-05-29 22:04 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-10-08 20:16 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-08 20:15 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-08 20:15 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-08 20:10 - 2014-05-30 00:14 - 00000000 ____D () C:\Users\Milka\AppData\Local\Battle.net
2014-10-08 20:03 - 2014-05-29 23:35 - 00000000 ____D () C:\ProgramData\Origin
2014-10-08 17:04 - 2014-05-29 22:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-10-08 17:04 - 2014-05-29 22:31 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-10-08 16:34 - 2014-05-29 22:20 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-10-08 16:16 - 2014-05-29 21:48 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-07 21:53 - 2014-05-31 00:05 - 00348928 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-10-07 21:53 - 2014-05-30 06:30 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-10-07 08:59 - 2014-05-29 22:19 - 00109224 _____ () C:\Users\Milka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-07 08:58 - 2009-07-14 06:45 - 00419112 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-06 18:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-10-06 18:07 - 2011-04-12 15:32 - 00000000 ____D () C:\Windows\ShellNew
2014-10-06 18:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-10-06 18:05 - 2009-07-14 04:34 - 00000513 _____ () C:\Windows\win.ini
2014-10-04 08:42 - 2014-06-02 19:44 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-10-04 08:42 - 2014-05-29 22:33 - 02197680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-10-04 08:41 - 2014-06-02 19:44 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-10-04 08:41 - 2014-05-29 22:33 - 02800296 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-10-03 16:22 - 2014-06-02 22:46 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-10-02 16:10 - 2014-05-31 00:04 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-10-01 21:04 - 2014-05-29 23:38 - 00000000 ____D () C:\Users\Milka\AppData\Local\Origin
2014-09-29 08:14 - 2014-06-24 10:41 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-09-29 08:14 - 2014-06-24 10:41 - 00000000 ____D () C:\Program Files\CCleaner
2014-09-26 11:12 - 2014-06-24 23:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-25 15:16 - 2014-05-29 21:48 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-25 15:16 - 2014-05-29 21:48 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-25 15:16 - 2014-05-29 21:48 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-23 16:01 - 2011-04-12 15:21 - 00749332 _____ () C:\Windows\system32\perfh015.dat
2014-09-23 16:01 - 2011-04-12 15:21 - 00160810 _____ () C:\Windows\system32\perfc015.dat
2014-09-23 16:01 - 2009-07-14 07:13 - 01696926 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-23 15:56 - 2014-06-01 23:26 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\DAEMON Tools Lite
2014-09-23 13:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-22 23:10 - 2014-05-30 00:14 - 00000000 ____D () C:\Users\Milka\AppData\Roaming\NVIDIA
2014-09-17 06:51 - 2014-05-29 22:27 - 01538880 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-09-14 01:48 - 2014-05-29 22:32 - 00073872 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-09-14 01:48 - 2014-05-29 22:32 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 20589536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 18106152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 16875856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 03223120 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 02838424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 00984424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-09-14 01:48 - 2014-05-29 22:27 - 00026956 _____ () C:\Windows\system32\nvinfo.pb
2014-09-13 23:53 - 2014-05-29 22:32 - 06890696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-09-13 23:53 - 2014-05-29 22:32 - 03529872 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-09-13 23:53 - 2014-05-29 22:32 - 02557640 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-09-13 23:53 - 2014-05-29 22:32 - 00934216 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-09-13 23:53 - 2014-05-29 22:32 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-09-13 23:53 - 2014-05-29 22:32 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-09-11 17:37 - 2014-05-29 22:32 - 03961833 _____ () C:\Windows\system32\nvcoproc.bin
2014-09-09 08:41 - 2014-08-11 22:42 - 00000000 ____D () C:\Program Files (x86)\MyFree Codec
2014-09-09 08:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources

Some content of TEMP:
====================
C:\Users\Milka\AppData\Local\Temp\aece01ab73217b28d0c53e6df4b8b815.dll
C:\Users\Milka\AppData\Local\Temp\ggdrive-menu.exe
C:\Users\Milka\AppData\Local\Temp\ggdrive-overlay.exe
C:\Users\Milka\AppData\Local\Temp\installstats.exe
C:\Users\Milka\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Milka\AppData\Local\Temp\nvStInst.exe
C:\Users\Milka\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe = & gt; File is digitally signed
C:\Windows\System32\wininit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\wininit.exe = & gt; File is digitally signed
C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\explorer.exe = & gt; File is digitally signed
C:\Windows\System32\svchost.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\svchost.exe = & gt; File is digitally signed
C:\Windows\System32\services.exe = & gt; File is digitally signed
C:\Windows\System32\User32.dll = & gt; MD5 is legit
C:\Windows\SysWOW64\User32.dll = & gt; MD5 is legit
C:\Windows\System32\userinit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\userinit.exe = & gt; File is digitally signed
C:\Windows\System32\rpcss.dll = & gt; File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys = & gt; File is digitally signed


LastRegBack: 2014-10-02 16:40

==================== End Of Log ============================


Download file - link to post