Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01 Ran by Dell (administrator) on DELL-PC on 19-07-2014 15:52:13 Running from H:\NAPRAWA Platform: Windows 7 Ultimate Service Pack 1 (X86) OS Language: Włoski (Włochy) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Iminent) C:\Program Files\Common Files\Umbrella\umbrella.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Nero AG) C:\Program Files\Nero\Update\NASvc.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [13543968 2008-06-09] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] => C:\Windows\system32\NvMcTray.dll [92704 2008-06-09] (NVIDIA Corporation) HKLM\...\Run: [NVHotkey] => C:\Windows\system32\nvHotkey.dll [96800 2008-06-09] (NVIDIA Corporation) HKU\S-1-5-21-2603858729-920865152-1564778799-1000\...\MountPoints2: {4ab4d250-5994-11e2-a33b-001d09db2db2} - G:\setup.exe HKU\S-1-5-21-2603858729-920865152-1564778799-1000\...\MountPoints2: {748ad6c2-4d6e-11e3-9087-001d09db2db2} - E:\HTC_Sync_Manager_PC.exe ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzutDtDtC0D0DzyyBtCtDyCyCzyyEtB0A0CtN0D0Tzu0CyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1228076797&ir= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://it.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBB17E1F708DECD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it-IT HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzutDtDtC0D0DzyyBtCtDyCyCzyyEtB0A0CtN0D0Tzu0CyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1228076797&ir= SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKCU - DefaultScope {520877B8-CE54-47F1-8998-134B082AF6BC} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd1202&cd=2XzuyEtN2Y1L1QzutDtDtC0D0DzyyBtCtDyCyCzyyEtB0A0CtN0D0Tzu0CyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1228076797&ir= SearchScopes: HKCU - D074F45D3C3C4D4B8887FDE0ED0258D5 URL = http://it.search.yahoo.com/search?fr=mcafee&p={SearchTerms} SearchScopes: HKCU - {520877B8-CE54-47F1-8998-134B082AF6BC} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd1202&cd=2XzuyEtN2Y1L1QzutDtDtC0D0DzyyBtCtDyCyCzyyEtB0A0CtN0D0Tzu0CyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1228076797&ir= BHO: 2YourFace Addon -> {1185823F-F22F-4027-80E5-4F68ACD5DE5E} -> C:\Users\Dell\AppData\Roaming\2YourFace\bho.dll () BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files\Iminent\Minibar.InternetExplorer.BHOx86.dll (SIEN) BHO: Wajam -> {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} -> C:\Program Files\Wajam\IE\priam_bho.dll (Wajam) BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Softonic Helper Object -> {E87806B5-E908-45FD-AF5E-957D83E58E68} -> C:\Program Files\Softonic\Softonic\1.8.16.10\bh\Softonic.dll (Softonic.com) BHO: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files\Mysearchdial\1.8.21.0\bh\mysearchdial.dll (Ironsource Israel (2011) LTD) BHO: WinToFlash Suggestor -> {FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD} -> C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll (Novicorp LLC) BHO: Yontoo -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC) Toolbar: HKLM - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\Softonic\1.8.16.10\SoftonicTlbr.dll (Softonic.com) Toolbar: HKLM - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll (Ironsource Israel (2011) LTD) DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.caminova.net/en/downloads/getmodule.aspx?lang=en Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll () Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @caminova.com/DjVuPlugin - C:\Program Files\Caminova\Document Express DjVu Plug-in\npdjvu.dll (Caminova, Inc.) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/Lync,version=15.0 - C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Dell\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Dell\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Dell\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Dell\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Dell\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Users\Dell\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Dell\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF HKLM\...\Firefox\Extensions: [support@2yourface.com] - C:\Users\Dell\AppData\Roaming\2YourFace\ffextension FF Extension: 2YourFace - C:\Users\Dell\AppData\Roaming\2YourFace\ffextension [2013-03-12] FF HKCU\...\Firefox\Extensions: [support@2yourface.com] - C:\Users\Dell\AppData\Roaming\2YourFace\ffextension Chrome: ======= CHR HomePage: hxxp://www.google.it/ CHR StartupUrls: "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP", "hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzutDtDtC0D0DzyyBtCtDyCyCzyyEtB0A0CtN0D0Tzu0CyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1228076797&ir=" CHR NewTab: "chrome-extension://pflphaooapbgpeakohlggbpidpppgdff/content/newtab/newtab.html" CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Extension: (WinToFlash Suggestor) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\acaoakiamfeidcmgooclgeleejkbaecf [2013-12-12] CHR Extension: (Google Drive) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-08] CHR Extension: (YouTube) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-08] CHR Extension: (Adblock Plus) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-01-15] CHR Extension: (Google Search) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-08] CHR Extension: (Kaspersky URL Advisor) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-25] CHR Extension: (Safe Money) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-25] CHR Extension: (Content Blocker) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-25] CHR Extension: (BonanzaDeals) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj [2014-01-20] CHR Extension: (Virtual Keyboard) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-25] CHR Extension: (Webcam Toy) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2013-01-15] CHR Extension: (Skype Click to Call) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-10] CHR Extension: (2YourFace) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmblfngognklgemafekefcdjcnkdhmdm [2013-03-12] CHR Extension: (Google Wallet) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01] CHR Extension: (MySearchDial) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff [2013-12-11] CHR Extension: (Gmail) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-08] CHR Extension: (Anti-Banner) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-25] CHR HKLM\...\Chrome\Extension: [acaoakiamfeidcmgooclgeleejkbaecf] - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.crx [2012-05-25] CHR HKLM\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files\Softonic\Softonic\1.8.16.10\Softonic.crx [2013-03-03] CHR HKLM\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Dell\AppData\Local\Wajam\Chrome\wajam.crx [2012-07-26] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03] CHR HKLM\...\Chrome\Extension: [lmblfngognklgemafekefcdjcnkdhmdm] - C:\Users\Dell\AppData\Roaming\2YourFace\2YourFace.crx [2011-12-14] CHR HKLM\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files\Yontoo\YontooLayers.crx [2013-01-08] CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Dell\AppData\Local\mysearchdial-speeddial.crx [2013-12-11] CHR HKCU\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Dell\AppData\Local\mysearchdial-speeddial.crx [2013-12-11] ========================== Services (Whitelisted) ================= S4 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S4 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation) S4 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [762192 2013-07-18] (Nero AG) S4 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [327680 2013-08-08] () [File not signed] R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [3052864 2014-04-13] (Iminent) S4 WajamUpdater; C:\Program Files\Wajam\Updater\WajamUpdater.exe [109064 2012-07-26] (Wajam) [File not signed] ==================== Drivers (Whitelisted) ==================== R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed] R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software) S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-19 15:16 - 2014-07-19 15:59 - 00000000 ____D () C:\FRST 2014-07-19 14:34 - 2014-07-19 14:34 - 450211767 _____ () C:\Windows\MEMORY.DMP 2014-07-19 14:34 - 2014-07-19 14:34 - 00143992 _____ () C:\Windows\Minidump\071914-21886-01.dmp 2014-07-19 13:43 - 2014-07-19 13:43 - 00000850 _____ () C:\Windows\PFRO.log 2014-07-19 12:17 - 2014-07-19 12:17 - 00000940 _____ () C:\Users\Dell\Desktop\Rkill.txt 2014-07-19 11:59 - 2014-07-19 11:59 - 00003536 ____N () C:\bootsqm.dat 2014-07-18 15:49 - 2014-07-19 15:32 - 00000504 _____ () C:\Windows\setupact.log 2014-07-18 15:49 - 2014-07-18 15:49 - 00000000 _____ () C:\Windows\setuperr.log ==================== One Month Modified Files and Folders ======= 2014-07-19 15:59 - 2014-07-19 15:16 - 00000000 ____D () C:\FRST 2014-07-19 15:49 - 2013-12-11 21:12 - 00000288 _____ () C:\Windows\Tasks\MySearchDial.job 2014-07-19 15:40 - 2009-07-14 06:34 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-19 15:39 - 2009-07-14 06:34 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-19 15:36 - 2013-01-08 16:29 - 00732260 _____ () C:\Windows\system32\perfh015.dat 2014-07-19 15:36 - 2013-01-08 16:29 - 00155838 _____ () C:\Windows\system32\perfc015.dat 2014-07-19 15:36 - 2010-11-21 15:00 - 00741410 _____ () C:\Windows\system32\perfh010.dat 2014-07-19 15:36 - 2010-11-21 15:00 - 00147432 _____ () C:\Windows\system32\perfc010.dat 2014-07-19 15:36 - 2010-11-20 23:01 - 02547864 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-19 15:33 - 2012-12-19 19:00 - 00063200 _____ () C:\ProgramData\nvModes.001 2014-07-19 15:32 - 2014-07-18 15:49 - 00000504 _____ () C:\Windows\setupact.log 2014-07-19 15:32 - 2013-01-08 16:25 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-19 15:32 - 2012-12-19 19:00 - 00063200 _____ () C:\ProgramData\nvModes.dat 2014-07-19 15:32 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-19 15:13 - 2013-01-08 11:25 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-19 15:02 - 2013-01-08 16:29 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2603858729-920865152-1564778799-1000UA.job 2014-07-19 14:36 - 2013-03-21 21:31 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2603858729-920865152-1564778799-1000UA.job 2014-07-19 14:34 - 2014-07-19 14:34 - 450211767 _____ () C:\Windows\MEMORY.DMP 2014-07-19 14:34 - 2014-07-19 14:34 - 00143992 _____ () C:\Windows\Minidump\071914-21886-01.dmp 2014-07-19 14:34 - 2013-06-27 12:31 - 00000000 ____D () C:\Windows\Minidump 2014-07-19 14:19 - 2013-01-08 16:25 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-19 13:43 - 2014-07-19 13:43 - 00000850 _____ () C:\Windows\PFRO.log 2014-07-19 12:17 - 2014-07-19 12:17 - 00000940 _____ () C:\Users\Dell\Desktop\Rkill.txt 2014-07-19 11:59 - 2014-07-19 11:59 - 00003536 ____N () C:\bootsqm.dat 2014-07-18 15:49 - 2014-07-18 15:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-18 15:33 - 2013-01-08 19:25 - 00000000 ____D () C:\Users\Dell\AppData\Roaming\uTorrent 2014-07-18 15:33 - 2013-01-08 18:27 - 00000000 ____D () C:\Users\Dell\AppData\Roaming\Winamp 2014-07-18 14:45 - 2012-12-19 19:00 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-18 14:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-07-18 12:24 - 2010-11-20 23:29 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2014-07-18 11:45 - 2013-12-08 18:47 - 00000774 _____ () C:\.dir 2014-07-18 11:09 - 2013-03-13 21:00 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-18 11:07 - 2014-01-20 21:35 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-18 11:06 - 2013-12-08 17:05 - 00000000 ____D () C:\Users\wangzhisong 2014-07-18 10:16 - 2013-03-13 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-18 08:58 - 2013-02-28 17:37 - 00000000 ____D () C:\Program Files\Common Files\Umbrella ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-02-01 15:33 ==================== End Of Log ============================