Hi, everybody! Recently, something strange began to occur with my computer. Every morning, when I start-up, my computer freezes and then crashes in 2-5 mins. However, after second start-up, it works normally during the day. Avast detected no viruses. My FRST log is below. Any ideas/comments would be appreciated.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by ANATOLII (administrator) on ANATOLII-PC on 18-04-2015 11:30:32
Running from C:\Users\ANATOLII\Desktop
Loaded Profiles: ANATOLII (Available profiles: ANATOLII)
Platform: Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Systweak) C:\Program Files\Right Backup\RBClientService.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Cognizance Corporation) C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
() C:\Program Files\ATKOSD2\ATKOSD2.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
() C:\Windows\ASScrPro.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [ASUS Camera ScreenSaver] => C:\Windows\ASScrProlog.exe [37232 2008-07-05] ()
HKLM\...\Run: [ASUS Screen Saver Protector] => C:\Windows\ASScrPro.exe [33136 2008-07-05] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-11-30] (RealNetworks, Inc.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation)
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [Device Doctor Pro] => C:\Program Files\Device Doctor Pro\DDProLauncher.exe [133744 2013-11-26] (Device Doctor Software Inc.)
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [Google Update] => C:\Users\ANATOLII\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-02-04] (Google Inc.)
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: G - G:\FIR.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: H - H:\FIR.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: {291acd35-aed5-11e0-b15f-001e8c24f077} - F:\FIR.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: {9d6f65a6-0514-11e2-be05-001e8c24f077} - H:\FIR.exe
AppInit_DLLs: APSHook.dll => C:\Windows\system32\APSHook.dll [56832 2006-07-12] (Cognizance Corporation)
Lsa: [Notification Packages] scecli ASWLNPkg
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com.ua/
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = www.bing.com
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {0A54AA4E-04EB-43CB-A863-9818C7867182} URL = http://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {0A569F7C-2438-44BB-A3C9-3B0D81EE4F5A} URL = http://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {5EC95614-A7BC-4CBD-8721-3E4380481552} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {F05D5B23-87AF-40C7-9013-BA72571D3042} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {F90101D9-2CB1-4B19-B3A5-644C661881D6} URL = http://websearch.ask.com/redirect?c...pn_sauid=7432B3C1-0468-4909-B3B5-53DEB3A1847B
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-01-15] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: ASUS Security Protect Manager -> {DF21F1DB-80C6-11D3-9483-B03D0EC10000} -> c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll [2006-11-21] (Bioscrypt Inc.)
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\ANATOLII\AppData\Roaming\Mozilla\Firefox\Profiles\yj8tseze.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-11-30] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-11-30] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-09-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\ANATOLII\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @talk.google.com/O1DPlugin -> C:\Users\ANATOLII\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @tools.google.com/Google Update;version=3 -> C:\Users\ANATOLII\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @tools.google.com/Google Update;version=9 -> C:\Users\ANATOLII\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-02-16] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\ANATOLII\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\ANATOLII\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF SearchPlugin: C:\Users\ANATOLII\AppData\Roaming\Mozilla\Firefox\Profiles\yj8tseze.default\searchplugins\google-avast.xml [2015-01-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-05]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-17]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-30]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSearchURL: Default -> http://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}
CHR DefaultSuggestURL: Default -> http://api.bing.com/osjson.aspx?query={searchTerms}&language={language}&form=UP97DF&PC=UP97
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-17]
CHR Extension: (RealDownloader) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-04-18]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-15]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASBroker; c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll [74240 2007-02-07] (Cognizance Corporation) [File not signed]
R2 ASChannel; c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll [131584 2006-06-21] (Cognizance Corporation) [File not signed]
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-15] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3192344 2015-01-15] (Avast Software)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [45568 2012-07-31] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [55808 2012-07-31] (Hewlett-Packard) [File not signed]
R2 RBClientService; C:\Program Files\Right Backup\RBClientService.exe [48472 2014-06-05] (Systweak)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-05-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3290304 2012-11-22] (Skype Technologies S.A.)
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-04] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-25] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2015-01-15] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2015-01-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55240 2015-01-15] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2015-01-15] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2015-01-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2015-01-15] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57928 2015-01-15] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2015-01-15] ()
R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [146824 2007-06-17] (AuthenTec, Inc.)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [72704 2007-11-26] (JMicron Technology Corp.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [5632 2007-01-24] ( )
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [721904 2011-09-02] () [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [218192 2015-01-15] (Avast Software)
U3 a2yjj6vw; C:\Windows\system32\Drivers\a2yjj6vw.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
S3 cpuz134; \??\C:\Users\ANATOLII\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-18 11:30 - 2015-04-18 11:31 - 00022725 _____ () C:\Users\ANATOLII\Desktop\FRST.txt
2015-04-18 11:30 - 2015-04-18 11:30 - 00000000 ____D () C:\FRST
2015-04-18 11:29 - 2015-04-18 11:29 - 01137152 _____ (Farbar) C:\Users\ANATOLII\Desktop\FRST.exe
2015-04-18 10:37 - 2015-02-04 12:23 - 00875688 _____ (Microsoft Corporation) C:\Windows\system32\TBD2ABB.tmp
2015-04-17 09:58 - 2015-03-09 09:01 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-17 09:58 - 2015-03-05 10:24 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-17 09:56 - 2015-03-05 10:32 - 00244152 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-17 09:56 - 2015-03-05 10:23 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-17 09:54 - 2015-03-14 10:21 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-17 09:54 - 2015-03-13 09:51 - 03604920 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-17 09:54 - 2015-03-13 09:51 - 03552184 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-16 08:49 - 2015-04-16 08:49 - 00000000 ___RD () C:\Program Files\Skype
2015-04-16 08:49 - 2015-04-16 08:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-16 08:49 - 2015-04-16 08:49 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-04-15 18:48 - 2015-04-16 15:07 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Colorado
2015-04-15 12:57 - 2015-03-10 07:06 - 12377600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 12:57 - 2015-03-10 07:03 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 12:57 - 2015-03-10 07:02 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 12:57 - 2015-03-10 07:00 - 09747968 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 12:57 - 2015-03-10 06:57 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 12:57 - 2015-03-10 06:57 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 01803264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 12:57 - 2015-03-10 06:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 12:57 - 2015-03-10 06:55 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 12:57 - 2015-03-10 06:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-04-15 12:57 - 2015-03-10 06:55 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-04-13 18:09 - 2015-04-17 15:19 - 00000000 ____D () C:\Users\ANATOLII\Desktop\MDM
2015-04-03 20:51 - 2015-04-18 10:56 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4154192477-2723174026-2473658507-1000UA.job
2015-04-03 20:51 - 2015-04-17 20:56 - 00000868 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4154192477-2723174026-2473658507-1000Core.job
2015-03-30 14:44 - 2015-03-30 14:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-23 18:11 - 2015-03-23 18:11 - 00000000 __SHD () C:\found.001
2015-03-22 21:16 - 2015-03-22 21:16 - 00000197 _____ () C:\Windows\system32\2015-03-22-13-16-36.052-AvastVBoxSVC.exe-1704.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-18 11:10 - 2014-01-21 11:09 - 00000000 ____D () C:\Users\ANATOLII\AppData\Local\CrashDumps
2015-04-18 11:01 - 2012-06-21 11:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-18 10:47 - 2011-07-16 16:34 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-18 10:44 - 2008-07-05 04:08 - 01922725 _____ () C:\Windows\WindowsUpdate.log
2015-04-18 10:27 - 2011-07-16 16:34 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-18 10:27 - 2006-11-02 19:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-18 10:24 - 2006-11-02 21:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-18 10:24 - 2006-11-02 20:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-18 10:24 - 2006-11-02 20:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-18 10:14 - 2006-11-02 18:33 - 00757474 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-18 00:09 - 2008-07-05 04:08 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-04-18 00:09 - 2006-11-02 21:01 - 00032644 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-17 20:54 - 2013-05-17 11:43 - 00001938 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-17 18:59 - 2011-07-16 21:41 - 00000000 ____D () C:\Users\ANATOLII\Documents\BabasChess
2015-04-17 17:27 - 2014-03-16 20:52 - 00000000 ____D () C:\Users\ANATOLII\AppData\Roaming\Skype
2015-04-17 15:36 - 2014-05-30 17:26 - 00002337 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-17 09:58 - 2008-07-05 04:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 17:04 - 2013-05-24 14:55 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Library 2006_2014
2015-04-16 11:49 - 2011-07-15 21:36 - 00202240 _____ () C:\Users\ANATOLII\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-16 11:43 - 2011-07-15 21:28 - 00000000 ____D () C:\Users\ANATOLII\Documents\MATLAB
2015-04-16 08:49 - 2011-07-16 16:33 - 00000000 ____D () C:\ProgramData\Skype
2015-04-16 08:49 - 2006-11-02 18:23 - 00000254 _____ () C:\Windows\win.ini
2015-04-15 10:01 - 2012-06-21 11:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 10:01 - 2011-07-21 16:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-14 20:26 - 2014-12-03 19:27 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Giant permittivity paper
2015-04-14 20:17 - 2012-01-30 16:40 - 00000000 ____D () C:\Users\ANATOLII\Documents\Outlook Files
2015-04-13 00:13 - 2013-04-06 20:28 - 00000096 _____ () C:\Users\ANATOLII\psv.ini
2015-04-13 00:13 - 2011-07-15 16:53 - 00000000 ____D () C:\Users\ANATOLII
2015-04-12 23:09 - 2014-06-06 14:56 - 00000000 ____D () C:\Users\ANATOLII\AppData\Roaming\Device Doctor Pro
2015-04-11 09:40 - 2014-06-26 11:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-08 16:57 - 2013-05-24 14:31 - 00000000 ____D () C:\Users\ANATOLII\AppData\Roaming\Mozilla
2015-04-03 20:51 - 2011-07-16 16:34 - 00000000 ____D () C:\Users\ANATOLII\AppData\Local\Google
2015-03-29 23:22 - 2011-07-15 21:33 - 00000000 ____D () C:\Users\ANATOLII\Documents\Private3
2015-03-28 23:54 - 2015-01-19 11:20 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Chess
2015-03-24 10:21 - 2006-11-02 20:47 - 00436464 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-23 20:56 - 2013-10-15 12:49 - 00000000 ____D () C:\Users\ANATOLII\Desktop\ENZ_3d OME12
2015-03-23 18:15 - 2013-10-09 14:00 - 00905012 _____ () C:\Windows\PFRO.log
2015-03-23 18:15 - 2011-07-16 16:33 - 00000000 ____D () C:\Program Files\Google
2015-03-23 11:21 - 2014-04-17 13:37 - 00000000 ____D () C:\Users\ANATOLII\Desktop\New
2015-03-23 10:51 - 2011-12-20 15:17 - 00001356 _____ () C:\Users\ANATOLII\AppData\Local\d3d9caps.dat
2015-03-22 23:54 - 2015-01-10 17:19 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-22 23:52 - 2011-08-04 03:44 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-03-22 23:50 - 2011-07-16 16:33 - 00000000 ____D () C:\ProgramData\Google
2015-03-22 23:22 - 2011-09-16 14:11 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared
2015-03-22 23:22 - 2011-09-16 14:09 - 00000000 ____D () C:\Program Files\DivX
2015-03-22 23:22 - 2011-09-16 14:07 - 00000000 ____D () C:\ProgramData\DivX
2015-03-22 23:18 - 2015-02-08 11:01 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-22 22:50 - 2011-08-04 03:40 - 00000000 ____D () C:\ProgramData\Apple
2015-03-21 13:16 - 2014-04-24 11:35 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Absorption problem
==================== Files in the root of some directories =======
2011-12-20 15:17 - 2015-03-23 10:51 - 0001356 _____ () C:\Users\ANATOLII\AppData\Local\d3d9caps.dat
2011-07-15 21:36 - 2015-04-16 11:49 - 0202240 _____ () C:\Users\ANATOLII\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-08-12 04:40 - 2012-12-05 18:42 - 0002268 _____ () C:\ProgramData\hpzinstall.log
Files to move or delete:
====================
C:\Users\ANATOLII\iTunesSetup.exe
Some content of TEMP:
====================
C:\Users\ANATOLII\AppData\Local\Temp\DivXSetup.exe
C:\Users\ANATOLII\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuo_wjy.dll
C:\Users\ANATOLII\AppData\Local\Temp\lowproc.exe
C:\Users\ANATOLII\AppData\Local\Temp\ReimagePackage.exe
C:\Users\ANATOLII\AppData\Local\Temp\stubhelper.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-18 10:44
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by ANATOLII (administrator) on ANATOLII-PC on 18-04-2015 11:30:32
Running from C:\Users\ANATOLII\Desktop
Loaded Profiles: ANATOLII (Available profiles: ANATOLII)
Platform: Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Systweak) C:\Program Files\Right Backup\RBClientService.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Cognizance Corporation) C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
() C:\Program Files\ATKOSD2\ATKOSD2.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
() C:\Windows\ASScrPro.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [ASUS Camera ScreenSaver] => C:\Windows\ASScrProlog.exe [37232 2008-07-05] ()
HKLM\...\Run: [ASUS Screen Saver Protector] => C:\Windows\ASScrPro.exe [33136 2008-07-05] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-11-30] (RealNetworks, Inc.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation)
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [Device Doctor Pro] => C:\Program Files\Device Doctor Pro\DDProLauncher.exe [133744 2013-11-26] (Device Doctor Software Inc.)
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\Run: [Google Update] => C:\Users\ANATOLII\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-02-04] (Google Inc.)
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: G - G:\FIR.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: H - H:\FIR.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: {291acd35-aed5-11e0-b15f-001e8c24f077} - F:\FIR.exe
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\...\MountPoints2: {9d6f65a6-0514-11e2-be05-001e8c24f077} - H:\FIR.exe
AppInit_DLLs: APSHook.dll => C:\Windows\system32\APSHook.dll [56832 2006-07-12] (Cognizance Corporation)
Lsa: [Notification Packages] scecli ASWLNPkg
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com.ua/
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
HKU\S-1-5-21-4154192477-2723174026-2473658507-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = www.bing.com
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {0A54AA4E-04EB-43CB-A863-9818C7867182} URL = http://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {0A569F7C-2438-44BB-A3C9-3B0D81EE4F5A} URL = http://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {5EC95614-A7BC-4CBD-8721-3E4380481552} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {F05D5B23-87AF-40C7-9013-BA72571D3042} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> {F90101D9-2CB1-4B19-B3A5-644C661881D6} URL = http://websearch.ask.com/redirect?c...pn_sauid=7432B3C1-0468-4909-B3B5-53DEB3A1847B
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-01-15] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: ASUS Security Protect Manager -> {DF21F1DB-80C6-11D3-9483-B03D0EC10000} -> c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll [2006-11-21] (Bioscrypt Inc.)
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
Toolbar: HKU\S-1-5-21-4154192477-2723174026-2473658507-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\ANATOLII\AppData\Roaming\Mozilla\Firefox\Profiles\yj8tseze.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-11-30] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-11-30] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-09-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\ANATOLII\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @talk.google.com/O1DPlugin -> C:\Users\ANATOLII\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @tools.google.com/Google Update;version=3 -> C:\Users\ANATOLII\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-4154192477-2723174026-2473658507-1000: @tools.google.com/Google Update;version=9 -> C:\Users\ANATOLII\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-02-16] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\ANATOLII\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\ANATOLII\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF SearchPlugin: C:\Users\ANATOLII\AppData\Roaming\Mozilla\Firefox\Profiles\yj8tseze.default\searchplugins\google-avast.xml [2015-01-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-05]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-17]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-30]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSearchURL: Default -> http://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}
CHR DefaultSuggestURL: Default -> http://api.bing.com/osjson.aspx?query={searchTerms}&language={language}&form=UP97DF&PC=UP97
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-17]
CHR Extension: (RealDownloader) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-04-18]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\ANATOLII\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-15]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASBroker; c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll [74240 2007-02-07] (Cognizance Corporation) [File not signed]
R2 ASChannel; c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll [131584 2006-06-21] (Cognizance Corporation) [File not signed]
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-15] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3192344 2015-01-15] (Avast Software)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [45568 2012-07-31] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [55808 2012-07-31] (Hewlett-Packard) [File not signed]
R2 RBClientService; C:\Program Files\Right Backup\RBClientService.exe [48472 2014-06-05] (Systweak)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-05-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3290304 2012-11-22] (Skype Technologies S.A.)
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-04] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-25] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2015-01-15] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2015-01-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55240 2015-01-15] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2015-01-15] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2015-01-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2015-01-15] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57928 2015-01-15] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2015-01-15] ()
R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [146824 2007-06-17] (AuthenTec, Inc.)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [72704 2007-11-26] (JMicron Technology Corp.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [5632 2007-01-24] ( )
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [721904 2011-09-02] () [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [218192 2015-01-15] (Avast Software)
U3 a2yjj6vw; C:\Windows\system32\Drivers\a2yjj6vw.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
S3 cpuz134; \??\C:\Users\ANATOLII\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-18 11:30 - 2015-04-18 11:31 - 00022725 _____ () C:\Users\ANATOLII\Desktop\FRST.txt
2015-04-18 11:30 - 2015-04-18 11:30 - 00000000 ____D () C:\FRST
2015-04-18 11:29 - 2015-04-18 11:29 - 01137152 _____ (Farbar) C:\Users\ANATOLII\Desktop\FRST.exe
2015-04-18 10:37 - 2015-02-04 12:23 - 00875688 _____ (Microsoft Corporation) C:\Windows\system32\TBD2ABB.tmp
2015-04-17 09:58 - 2015-03-09 09:01 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-17 09:58 - 2015-03-05 10:24 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-17 09:56 - 2015-03-05 10:32 - 00244152 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-17 09:56 - 2015-03-05 10:23 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-17 09:54 - 2015-03-14 10:21 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-17 09:54 - 2015-03-13 09:51 - 03604920 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-17 09:54 - 2015-03-13 09:51 - 03552184 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-16 08:49 - 2015-04-16 08:49 - 00000000 ___RD () C:\Program Files\Skype
2015-04-16 08:49 - 2015-04-16 08:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-16 08:49 - 2015-04-16 08:49 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-04-15 18:48 - 2015-04-16 15:07 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Colorado
2015-04-15 12:57 - 2015-03-10 07:06 - 12377600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 12:57 - 2015-03-10 07:03 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 12:57 - 2015-03-10 07:02 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 12:57 - 2015-03-10 07:00 - 09747968 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 12:57 - 2015-03-10 06:57 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 12:57 - 2015-03-10 06:57 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 01803264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 12:57 - 2015-03-10 06:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-04-15 12:57 - 2015-03-10 06:56 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 12:57 - 2015-03-10 06:55 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 12:57 - 2015-03-10 06:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-04-15 12:57 - 2015-03-10 06:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-04-15 12:57 - 2015-03-10 06:55 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-04-13 18:09 - 2015-04-17 15:19 - 00000000 ____D () C:\Users\ANATOLII\Desktop\MDM
2015-04-03 20:51 - 2015-04-18 10:56 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4154192477-2723174026-2473658507-1000UA.job
2015-04-03 20:51 - 2015-04-17 20:56 - 00000868 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4154192477-2723174026-2473658507-1000Core.job
2015-03-30 14:44 - 2015-03-30 14:45 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-23 18:11 - 2015-03-23 18:11 - 00000000 __SHD () C:\found.001
2015-03-22 21:16 - 2015-03-22 21:16 - 00000197 _____ () C:\Windows\system32\2015-03-22-13-16-36.052-AvastVBoxSVC.exe-1704.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-18 11:10 - 2014-01-21 11:09 - 00000000 ____D () C:\Users\ANATOLII\AppData\Local\CrashDumps
2015-04-18 11:01 - 2012-06-21 11:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-18 10:47 - 2011-07-16 16:34 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-18 10:44 - 2008-07-05 04:08 - 01922725 _____ () C:\Windows\WindowsUpdate.log
2015-04-18 10:27 - 2011-07-16 16:34 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-18 10:27 - 2006-11-02 19:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-18 10:24 - 2006-11-02 21:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-18 10:24 - 2006-11-02 20:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-18 10:24 - 2006-11-02 20:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-18 10:14 - 2006-11-02 18:33 - 00757474 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-18 00:09 - 2008-07-05 04:08 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-04-18 00:09 - 2006-11-02 21:01 - 00032644 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-17 20:54 - 2013-05-17 11:43 - 00001938 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-17 18:59 - 2011-07-16 21:41 - 00000000 ____D () C:\Users\ANATOLII\Documents\BabasChess
2015-04-17 17:27 - 2014-03-16 20:52 - 00000000 ____D () C:\Users\ANATOLII\AppData\Roaming\Skype
2015-04-17 15:36 - 2014-05-30 17:26 - 00002337 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-17 09:58 - 2008-07-05 04:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 17:04 - 2013-05-24 14:55 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Library 2006_2014
2015-04-16 11:49 - 2011-07-15 21:36 - 00202240 _____ () C:\Users\ANATOLII\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-16 11:43 - 2011-07-15 21:28 - 00000000 ____D () C:\Users\ANATOLII\Documents\MATLAB
2015-04-16 08:49 - 2011-07-16 16:33 - 00000000 ____D () C:\ProgramData\Skype
2015-04-16 08:49 - 2006-11-02 18:23 - 00000254 _____ () C:\Windows\win.ini
2015-04-15 10:01 - 2012-06-21 11:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 10:01 - 2011-07-21 16:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-14 20:26 - 2014-12-03 19:27 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Giant permittivity paper
2015-04-14 20:17 - 2012-01-30 16:40 - 00000000 ____D () C:\Users\ANATOLII\Documents\Outlook Files
2015-04-13 00:13 - 2013-04-06 20:28 - 00000096 _____ () C:\Users\ANATOLII\psv.ini
2015-04-13 00:13 - 2011-07-15 16:53 - 00000000 ____D () C:\Users\ANATOLII
2015-04-12 23:09 - 2014-06-06 14:56 - 00000000 ____D () C:\Users\ANATOLII\AppData\Roaming\Device Doctor Pro
2015-04-11 09:40 - 2014-06-26 11:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-08 16:57 - 2013-05-24 14:31 - 00000000 ____D () C:\Users\ANATOLII\AppData\Roaming\Mozilla
2015-04-03 20:51 - 2011-07-16 16:34 - 00000000 ____D () C:\Users\ANATOLII\AppData\Local\Google
2015-03-29 23:22 - 2011-07-15 21:33 - 00000000 ____D () C:\Users\ANATOLII\Documents\Private3
2015-03-28 23:54 - 2015-01-19 11:20 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Chess
2015-03-24 10:21 - 2006-11-02 20:47 - 00436464 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-23 20:56 - 2013-10-15 12:49 - 00000000 ____D () C:\Users\ANATOLII\Desktop\ENZ_3d OME12
2015-03-23 18:15 - 2013-10-09 14:00 - 00905012 _____ () C:\Windows\PFRO.log
2015-03-23 18:15 - 2011-07-16 16:33 - 00000000 ____D () C:\Program Files\Google
2015-03-23 11:21 - 2014-04-17 13:37 - 00000000 ____D () C:\Users\ANATOLII\Desktop\New
2015-03-23 10:51 - 2011-12-20 15:17 - 00001356 _____ () C:\Users\ANATOLII\AppData\Local\d3d9caps.dat
2015-03-22 23:54 - 2015-01-10 17:19 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-22 23:52 - 2011-08-04 03:44 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-03-22 23:50 - 2011-07-16 16:33 - 00000000 ____D () C:\ProgramData\Google
2015-03-22 23:22 - 2011-09-16 14:11 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared
2015-03-22 23:22 - 2011-09-16 14:09 - 00000000 ____D () C:\Program Files\DivX
2015-03-22 23:22 - 2011-09-16 14:07 - 00000000 ____D () C:\ProgramData\DivX
2015-03-22 23:18 - 2015-02-08 11:01 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-22 22:50 - 2011-08-04 03:40 - 00000000 ____D () C:\ProgramData\Apple
2015-03-21 13:16 - 2014-04-24 11:35 - 00000000 ____D () C:\Users\ANATOLII\Desktop\Absorption problem
==================== Files in the root of some directories =======
2011-12-20 15:17 - 2015-03-23 10:51 - 0001356 _____ () C:\Users\ANATOLII\AppData\Local\d3d9caps.dat
2011-07-15 21:36 - 2015-04-16 11:49 - 0202240 _____ () C:\Users\ANATOLII\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-08-12 04:40 - 2012-12-05 18:42 - 0002268 _____ () C:\ProgramData\hpzinstall.log
Files to move or delete:
====================
C:\Users\ANATOLII\iTunesSetup.exe
Some content of TEMP:
====================
C:\Users\ANATOLII\AppData\Local\Temp\DivXSetup.exe
C:\Users\ANATOLII\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuo_wjy.dll
C:\Users\ANATOLII\AppData\Local\Temp\lowproc.exe
C:\Users\ANATOLII\AppData\Local\Temp\ReimagePackage.exe
C:\Users\ANATOLII\AppData\Local\Temp\stubhelper.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-18 10:44
==================== End Of Log ============================