Notawiz
2014-07-30, 21:48
My PC occasionally "freezes" for about 0.5-3 seconds at a time. During such a freeze, I can move the mouse and see the cursor moving, but if I mouse over a button, the button isn't highlighted. If I type, I'll only see the text I typed after the freeze ends. It happens often enough to be a nuisance, especially in games. I disabled as much bloat as possible, defragmented, scanned with MSE and spybot, and didn't manage to get rid of it. It wasn't happening when the PC was new, so I suspect a virus.
The log files are too large to post, so I attached a zip.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by ndjokic (administrator) on NDJOKIC-PC on 30-07-2014 19:12:15
Running from C:\Users\ndjokic\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(http://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-04] (Synaptics Incorporated)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {6a70d0d2-ff26-11e1-b4b9-806e6f6e6963} - F:\SWSETUP\APPINSTL\hpsoftwaresetup.exe
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {daf1934d-3319-11e2-b636-930c393050a1} - H:\Setup.exe
ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0623424AC3A4CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871
FF Homepage: hxxp://www.google.co.uk/
FF NetworkProxy: "autoconfig_url", "http://r-1.ch/twitch.pac"
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\ndjokic\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\ndjokic\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\ndjokic\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\ndjokic\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\ndjokic\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Users\ndjokic\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\ndjokic\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: FoxyProxy Standard - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\foxyproxy@eric.h.jung [2014-02-04]
FF Extension: Classic Theme Restorer - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-02]
FF Extension: YouTube Center - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2013-09-15]
FF Extension: Adblock Plus - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-19]
FF Extension: Team Liquid Streams - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{db09811d-efff-4339-a548-8550c7238a30}.xpi [2013-11-08]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-08-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-28] (Hewlett-Packard Company)
S4 ImDskSvc; C:\Windows\system32\imdsksvc.exe [11264 2012-07-30] (Olof Lagerkvist) [File not signed]
S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-12-13] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-10] ()
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2009-10-20] (CACE Technologies, Inc.)
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S4 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH) [File not signed]
S4 VMAuthdService; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [79872 2012-08-15] (VMware, Inc.) [File not signed]
S2 SkypeUpdate; "C:\Program Files (x86)\Skype\Updater\Updater.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AWEAlloc; C:\Windows\System32\DRIVERS\awealloc.sys [18384 2012-02-16] (Olof Lagerkvist)
R2 ImDisk; C:\Windows\System32\DRIVERS\imdisk.sys [38416 2012-07-30] (Olof Lagerkvist)
R0 johci; C:\Windows\System32\DRIVERS\johci.sys [26712 2011-01-18] (JMicron Technology Corp.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [47632 2009-10-20] (CACE Technologies, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826048 2010-12-21] ()
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [105816 2012-09-13] (Oracle Corporation)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31384 2012-08-15] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.)
S3 ALSysIO; \??\C:\Users\ndjokic\AppData\Local\Temp\ALSysIO64.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-30 19:12 - 2014-07-30 19:13 - 00016948 _____ () C:\Users\ndjokic\Desktop\FRST.txt
2014-07-30 19:10 - 2014-07-30 19:12 - 00000000 ____D () C:\FRST
2014-07-30 19:10 - 2014-07-30 19:10 - 02093568 _____ (Farbar) C:\Users\ndjokic\Desktop\FRST64.exe
2014-07-30 19:09 - 2014-07-30 19:09 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-NDJOKIC-PC-Microsoft-Windows-7-Professional-(64-bit).dat
2014-07-30 19:08 - 2014-07-30 19:08 - 00000000 ____D () C:\RegBackup
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Registry Backup
2014-07-29 22:10 - 2014-07-29 22:10 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\LOVE
2014-07-29 22:02 - 2014-07-29 22:02 - 00000000 ____D () C:\Users\ndjokic\Desktop\mari0
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\movies
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\food
2014-07-27 11:54 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-27 11:54 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-27 11:54 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-27 11:54 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-07-27 11:54 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-07-27 11:54 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-07-27 11:54 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-07-27 11:54 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-07-27 11:54 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-07-27 11:54 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-07-27 11:54 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-07-27 11:54 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-07-27 11:54 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-07-27 11:53 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-27 11:53 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-27 11:53 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-27 11:53 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-27 11:53 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-07-27 11:53 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-07-27 11:53 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-07-27 11:53 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-07-27 11:53 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-07-27 11:53 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-07-27 11:53 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-07-27 11:53 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-07-27 11:53 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-07-27 11:53 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-07-27 11:53 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-07-27 11:52 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-27 11:52 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-27 11:52 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-27 11:52 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-27 11:52 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-27 11:52 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-27 11:52 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-27 11:52 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-27 11:52 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-27 11:52 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-27 11:52 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-27 11:52 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-27 11:52 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-27 11:52 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-27 11:52 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-27 11:52 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-27 11:52 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-27 11:52 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-27 11:52 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-27 11:52 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-27 11:52 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-27 11:52 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-27 11:52 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-27 11:52 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-27 11:52 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-27 11:52 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-27 11:52 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-27 11:52 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-27 11:52 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-27 11:52 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-27 11:52 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-27 11:52 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-27 11:52 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-27 11:52 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-27 11:52 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-27 11:52 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-27 11:52 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-27 11:52 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-27 11:52 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-27 11:52 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-27 11:52 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-27 11:52 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-27 11:52 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-27 11:52 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-27 11:52 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-27 11:52 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-27 11:52 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-27 11:52 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-27 11:52 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-27 11:52 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-27 11:52 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-27 11:52 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-27 11:52 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-27 11:52 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-27 11:52 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-27 11:52 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-27 11:52 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-27 11:52 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-27 11:52 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-27 11:52 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-27 11:52 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-27 11:52 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-07-27 11:52 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-07-27 11:52 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-07-27 11:52 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-07-27 11:52 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-07-27 11:52 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-07-27 11:52 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-07-27 11:52 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-07-27 08:31 - 2014-07-27 08:46 - 00000169 _____ () C:\Users\ndjokic\Desktop\useless.txt
2014-07-26 07:28 - 2014-07-30 17:57 - 00000467 _____ () C:\Users\ndjokic\Desktop\db.txt
2014-07-25 07:27 - 2014-07-25 07:27 - 00002376 _____ () C:\Users\ndjokic\Documents\MumbleAutomaticCertificateBackup.p12
2014-07-25 07:22 - 2014-07-25 07:57 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Mumble
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-07-24 22:20 - 2014-07-24 23:01 - 00000007 _____ () C:\Users\ndjokic\Desktop\New Text Document.txt
2014-07-24 15:05 - 2014-07-24 15:08 - 00000073 _____ () C:\Users\ndjokic\Desktop\acm reimb.txt
2014-07-23 15:36 - 2014-07-23 15:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-22 19:00 - 2014-07-27 13:53 - 00000000 ____D () C:\Users\ndjokic\Desktop\bill
2014-07-22 12:12 - 2014-07-30 06:09 - 00000840 _____ () C:\Windows\setupact.log
2014-07-20 18:06 - 2014-07-20 18:06 - 00000000 ____D () C:\ProgramData\ATI
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\ProgramData\AMD
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-07-20 18:00 - 2014-07-20 18:00 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201407201800525336.log
2014-07-20 18:00 - 2014-07-20 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-07-20 17:54 - 2014-07-20 17:54 - 00000000 ____D () C:\Program Files\AMD
2014-07-20 17:52 - 2014-07-20 17:52 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-07-20 00:48 - 2014-07-20 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2014-07-19 22:22 - 2014-07-19 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-07-18 01:09 - 2014-07-18 01:21 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\Hero_Siege
2014-07-17 23:07 - 2014-07-17 23:38 - 00000065 _____ () C:\Users\ndjokic\Desktop\hercules pw.txt
2014-07-14 19:26 - 2014-07-14 19:31 - 00000000 ____D () C:\Users\ndjokic\Desktop\hair progress
2014-07-12 00:24 - 2014-07-20 17:52 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\XGen Studios, Inc
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\XGen Studios, Inc
2014-07-11 22:46 - 2014-07-18 00:13 - 00000657 _____ () C:\Users\ndjokic\Desktop\local contest tasks.txt
2014-07-03 21:29 - 2014-07-18 01:08 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-03 21:29 - 2014-07-03 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-03 00:10 - 2014-07-03 00:10 - 00000000 ____D () C:\ProgramData\WaLMaRT
2014-07-02 22:37 - 2014-07-02 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trendy Entertainment
2014-07-02 14:20 - 2014-07-02 14:20 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-30 19:13 - 2014-07-30 19:12 - 00016948 _____ () C:\Users\ndjokic\Desktop\FRST.txt
2014-07-30 19:12 - 2014-07-30 19:10 - 00000000 ____D () C:\FRST
2014-07-30 19:10 - 2014-07-30 19:10 - 02093568 _____ (Farbar) C:\Users\ndjokic\Desktop\FRST64.exe
2014-07-30 19:10 - 2013-02-02 21:17 - 00000000 ____D () C:\Users\ndjokic\Desktop\dls
2014-07-30 19:09 - 2014-07-30 19:09 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-NDJOKIC-PC-Microsoft-Windows-7-Professional-(64-bit).dat
2014-07-30 19:08 - 2014-07-30 19:08 - 00000000 ____D () C:\RegBackup
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Registry Backup
2014-07-30 18:56 - 2014-01-27 21:49 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-30 18:26 - 2014-06-29 22:21 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-132009455-2026092721-3990303557-1000UA.job
2014-07-30 17:57 - 2014-07-26 07:28 - 00000467 _____ () C:\Users\ndjokic\Desktop\db.txt
2014-07-30 17:49 - 2013-12-19 10:13 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\Battle.net
2014-07-30 16:52 - 2012-09-15 13:19 - 02006456 _____ () C:\Windows\WindowsUpdate.log
2014-07-30 09:33 - 2014-01-27 21:49 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-30 09:30 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-30 09:30 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-30 09:25 - 2013-08-30 23:00 - 00003348 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-30 09:25 - 2013-08-30 23:00 - 00003218 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-30 09:24 - 2012-12-31 19:09 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\TSVNCache
2014-07-30 06:09 - 2014-07-22 12:12 - 00000840 _____ () C:\Windows\setupact.log
2014-07-30 06:09 - 2012-10-11 14:18 - 00000000 ____D () C:\ProgramData\VMware
2014-07-30 06:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-29 22:30 - 2014-06-29 22:21 - 00000864 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-132009455-2026092721-3990303557-1000Core.job
2014-07-29 22:10 - 2014-07-29 22:10 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\LOVE
2014-07-29 22:02 - 2014-07-29 22:02 - 00000000 ____D () C:\Users\ndjokic\Desktop\mari0
2014-07-28 20:54 - 2012-09-18 08:37 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Skype
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\movies
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\food
2014-07-28 18:52 - 2014-06-18 20:37 - 00000134 _____ () C:\Users\ndjokic\Desktop\spb stuff.txt
2014-07-28 18:52 - 2014-02-17 15:18 - 00000000 ____D () C:\Users\ndjokic\Desktop\stuff
2014-07-28 18:52 - 2013-12-13 18:48 - 00000000 ____D () C:\Users\ndjokic\Desktop\games
2014-07-27 13:53 - 2014-07-22 19:00 - 00000000 ____D () C:\Users\ndjokic\Desktop\bill
2014-07-27 13:21 - 2012-10-11 21:28 - 00000000 ____D () C:\Users\ndjokic\.VirtualBox
2014-07-27 12:13 - 2013-09-28 18:09 - 00000000 ____D () C:\Windows\pss
2014-07-27 12:13 - 2012-12-02 18:20 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\LogMeIn Hamachi
2014-07-27 12:06 - 2009-07-14 06:45 - 00268856 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-27 12:04 - 2014-05-06 06:14 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-27 12:04 - 2009-07-14 09:47 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-27 12:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-27 12:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-27 12:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-27 12:01 - 2013-07-22 03:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-27 11:28 - 2014-04-23 06:45 - 00003240 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-27 11:27 - 2014-04-23 06:45 - 00003370 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-27 08:46 - 2014-07-27 08:31 - 00000169 _____ () C:\Users\ndjokic\Desktop\useless.txt
2014-07-26 16:02 - 2014-02-22 21:52 - 00000691 _____ () C:\Users\ndjokic\Desktop\6sm skipped.txt
2014-07-25 23:04 - 2013-11-06 21:10 - 00001162 _____ () C:\Users\ndjokic\Desktop\blu.txt
2014-07-25 07:57 - 2014-07-25 07:22 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Mumble
2014-07-25 07:27 - 2014-07-25 07:27 - 00002376 _____ () C:\Users\ndjokic\Documents\MumbleAutomaticCertificateBackup.p12
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-07-25 00:17 - 2013-12-19 10:12 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-24 23:01 - 2014-07-24 22:20 - 00000007 _____ () C:\Users\ndjokic\Desktop\New Text Document.txt
2014-07-24 15:08 - 2014-07-24 15:05 - 00000073 _____ () C:\Users\ndjokic\Desktop\acm reimb.txt
2014-07-24 03:38 - 2012-09-15 13:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-23 15:37 - 2014-07-23 15:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-21 23:27 - 2013-10-04 22:23 - 00002108 _____ () C:\Users\ndjokic\Desktop\iou.txt
2014-07-21 21:54 - 2013-02-01 13:30 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-20 22:40 - 2013-07-11 18:26 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\vlc
2014-07-20 20:41 - 2012-09-18 10:23 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\uTorrent
2014-07-20 19:37 - 2012-09-22 19:40 - 00000000 ____D () C:\movies
2014-07-20 18:06 - 2014-07-20 18:06 - 00000000 ____D () C:\ProgramData\ATI
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\ProgramData\AMD
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-07-20 18:00 - 2014-07-20 18:00 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201407201800525336.log
2014-07-20 18:00 - 2014-07-20 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-07-20 18:00 - 2013-12-22 14:40 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-07-20 17:54 - 2014-07-20 17:54 - 00000000 ____D () C:\Program Files\AMD
2014-07-20 17:52 - 2014-07-20 17:52 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-07-20 17:52 - 2014-07-12 00:24 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-20 17:44 - 2013-12-22 14:24 - 00000000 ____D () C:\AMD
2014-07-20 00:48 - 2014-07-20 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2014-07-20 00:41 - 2012-09-15 16:09 - 00000000 ____D () C:\games
2014-07-19 22:22 - 2014-07-19 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-07-18 01:21 - 2014-07-18 01:09 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\Hero_Siege
2014-07-18 01:08 - 2014-07-03 21:29 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-18 00:13 - 2014-07-11 22:46 - 00000657 _____ () C:\Users\ndjokic\Desktop\local contest tasks.txt
2014-07-17 23:38 - 2014-07-17 23:07 - 00000065 _____ () C:\Users\ndjokic\Desktop\hercules pw.txt
2014-07-17 22:32 - 2012-11-20 23:07 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-16 16:01 - 2009-07-14 07:13 - 00786766 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-14 19:31 - 2014-07-14 19:26 - 00000000 ____D () C:\Users\ndjokic\Desktop\hair progress
2014-07-13 13:58 - 2014-05-15 02:45 - 00000225 _____ () C:\Users\ndjokic\Desktop\topc.txt
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\XGen Studios, Inc
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\XGen Studios, Inc
2014-07-06 03:18 - 2013-06-18 14:40 - 00000688 _____ () C:\Users\ndjokic\contestapplet.conf
2014-07-06 03:14 - 2013-06-18 14:40 - 00000688 _____ () C:\Users\ndjokic\contestapplet.conf.bak
2014-07-03 21:29 - 2014-07-03 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-03 00:10 - 2014-07-03 00:10 - 00000000 ____D () C:\ProgramData\WaLMaRT
2014-07-02 23:20 - 2013-09-06 20:32 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\TS3Client
2014-07-02 22:40 - 2012-12-13 23:02 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\SKIDROW
2014-07-02 22:37 - 2014-07-02 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trendy Entertainment
2014-07-02 14:20 - 2014-07-02 14:20 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-07-02 14:20 - 2014-02-09 20:57 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-06-30 12:18 - 2014-05-12 21:58 - 00000046 _____ () C:\Users\ndjokic\jagex_cl_runescape_LIVE.dat
2014-06-30 12:18 - 2014-05-12 21:58 - 00000024 _____ () C:\Users\ndjokic\random.dat
2014-06-30 04:09 - 2014-07-27 11:54 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-27 11:54 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Files to move or delete:
====================
C:\ProgramData\hash.dat
C:\Users\ndjokic\jagex_cl_oldschool_LIVE.dat
C:\Users\ndjokic\jagex_cl_runescape_LIVE.dat
C:\Users\ndjokic\random.dat
Some content of TEMP:
====================
C:\Users\ndjokic\AppData\Local\Temp\917b0b87-3358-4e79-93de-3dfc2fc99ed0.exe
C:\Users\ndjokic\AppData\Local\Temp\catalyst_mobility_64-bit_util.exe
C:\Users\ndjokic\AppData\Local\Temp\jna5155314657774875577.dll
C:\Users\ndjokic\AppData\Local\Temp\lowproc.exe
C:\Users\ndjokic\AppData\Local\Temp\SIInvoker.exe
C:\Users\ndjokic\AppData\Local\Temp\SkypeSetup.exe
C:\Users\ndjokic\AppData\Local\Temp\SRLDetectionLibrary5122638381083391501.dll
C:\Users\ndjokic\AppData\Local\Temp\SRLDetectionLibrary6002148792366687404.dll
C:\Users\ndjokic\AppData\Local\Temp\stubhelper.dll
C:\Users\ndjokic\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\ndjokic\AppData\Local\Temp\Uninstall.exe
C:\Users\ndjokic\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\ndjokic\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-28 19:34
==================== End Of Log ============================
aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-07-30 19:28:26
-----------------------------
19:28:26.517 OS Version: Windows x64 6.1.7601 Service Pack 1
19:28:26.517 Number of processors: 4 586 0x2A07
19:28:26.517 ComputerName: NDJOKIC-PC UserName: ndjokic
19:28:28.005 Initialize success
19:28:28.050 VM: initialized successfully
19:28:28.073 VM: Intel CPU BiosDisabled
19:28:37.973 VM: supported disk I/O iaStor.sys
19:32:33.425 AVAST engine defs: 14073001
19:33:42.590 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:33:42.590 Disk 0 Vendor: TOSHIBA_ MH00 Size: 476940MB BusType: 3
19:33:44.135 Disk 0 MBR read successfully
19:33:44.135 Disk 0 MBR scan
19:33:44.135 Disk 0 Windows 7 default MBR code
19:33:44.135 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 300 MB offset 2048
19:33:44.135 Disk 0 default boot code
19:33:44.150 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 455269 MB offset 616448
19:33:44.197 Disk 0 Partition 3 00 07 HPFS/NTFS 16247 MB offset 933007360
19:33:44.197 Disk 0 Partition 4 00 0C FAT32 LBA 5115 MB offset 966281216
19:33:44.275 Disk 0 scanning C:\Windows\system32\drivers
19:34:03.985 Service scanning
19:34:47.861 Modules scanning
19:34:47.861 Disk 0 trace - called modules:
19:34:49.609 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys iaStor.sys hal.dll
19:34:49.610 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800971a060]
19:34:49.610 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa800956e870]
19:34:49.610 5 hpdskflt.sys[fffff88001861361] -> nt!IofCallDriver -> [0xfffffa8007bb5e40]
19:34:49.610 7 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007bbe050]
19:34:51.098 AVAST engine scan C:\Windows
19:34:54.612 AVAST engine scan C:\Windows\system32
19:39:06.443 AVAST engine scan C:\Windows\system32\drivers
19:39:29.664 AVAST engine scan C:\Users\ndjokic
19:57:48.401 AVAST engine scan C:\ProgramData
20:14:25.729 Scan finished successfully
20:21:50.361 Disk 0 MBR has been saved successfully to "C:\Users\ndjokic\Desktop\july 2014 virus\MBR.dat"
20:21:50.384 The log file has been saved successfully to "C:\Users\ndjokic\Desktop\july 2014 virus\aswMBR.txt"
The log files are too large to post, so I attached a zip.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by ndjokic (administrator) on NDJOKIC-PC on 30-07-2014 19:12:15
Running from C:\Users\ndjokic\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(http://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-04] (Synaptics Incorporated)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {6a70d0d2-ff26-11e1-b4b9-806e6f6e6963} - F:\SWSETUP\APPINSTL\hpsoftwaresetup.exe
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {daf1934d-3319-11e2-b636-930c393050a1} - H:\Setup.exe
ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0623424AC3A4CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871
FF Homepage: hxxp://www.google.co.uk/
FF NetworkProxy: "autoconfig_url", "http://r-1.ch/twitch.pac"
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\ndjokic\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\ndjokic\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\ndjokic\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\ndjokic\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\ndjokic\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Users\ndjokic\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\ndjokic\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: FoxyProxy Standard - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\foxyproxy@eric.h.jung [2014-02-04]
FF Extension: Classic Theme Restorer - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-02]
FF Extension: YouTube Center - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2013-09-15]
FF Extension: Adblock Plus - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-19]
FF Extension: Team Liquid Streams - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{db09811d-efff-4339-a548-8550c7238a30}.xpi [2013-11-08]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-08-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-28] (Hewlett-Packard Company)
S4 ImDskSvc; C:\Windows\system32\imdsksvc.exe [11264 2012-07-30] (Olof Lagerkvist) [File not signed]
S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-12-13] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-10] ()
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2009-10-20] (CACE Technologies, Inc.)
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S4 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH) [File not signed]
S4 VMAuthdService; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [79872 2012-08-15] (VMware, Inc.) [File not signed]
S2 SkypeUpdate; "C:\Program Files (x86)\Skype\Updater\Updater.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AWEAlloc; C:\Windows\System32\DRIVERS\awealloc.sys [18384 2012-02-16] (Olof Lagerkvist)
R2 ImDisk; C:\Windows\System32\DRIVERS\imdisk.sys [38416 2012-07-30] (Olof Lagerkvist)
R0 johci; C:\Windows\System32\DRIVERS\johci.sys [26712 2011-01-18] (JMicron Technology Corp.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [47632 2009-10-20] (CACE Technologies, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826048 2010-12-21] ()
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [105816 2012-09-13] (Oracle Corporation)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31384 2012-08-15] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.)
S3 ALSysIO; \??\C:\Users\ndjokic\AppData\Local\Temp\ALSysIO64.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-30 19:12 - 2014-07-30 19:13 - 00016948 _____ () C:\Users\ndjokic\Desktop\FRST.txt
2014-07-30 19:10 - 2014-07-30 19:12 - 00000000 ____D () C:\FRST
2014-07-30 19:10 - 2014-07-30 19:10 - 02093568 _____ (Farbar) C:\Users\ndjokic\Desktop\FRST64.exe
2014-07-30 19:09 - 2014-07-30 19:09 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-NDJOKIC-PC-Microsoft-Windows-7-Professional-(64-bit).dat
2014-07-30 19:08 - 2014-07-30 19:08 - 00000000 ____D () C:\RegBackup
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Registry Backup
2014-07-29 22:10 - 2014-07-29 22:10 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\LOVE
2014-07-29 22:02 - 2014-07-29 22:02 - 00000000 ____D () C:\Users\ndjokic\Desktop\mari0
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\movies
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\food
2014-07-27 11:54 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-27 11:54 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-27 11:54 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-27 11:54 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-07-27 11:54 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-07-27 11:54 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-07-27 11:54 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-07-27 11:54 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-07-27 11:54 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-07-27 11:54 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-07-27 11:54 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-07-27 11:54 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-07-27 11:54 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-07-27 11:53 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-27 11:53 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-27 11:53 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-27 11:53 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-27 11:53 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-27 11:53 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-27 11:53 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-07-27 11:53 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-07-27 11:53 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-07-27 11:53 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-07-27 11:53 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-07-27 11:53 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-07-27 11:53 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-07-27 11:53 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-07-27 11:53 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-07-27 11:53 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-07-27 11:53 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-07-27 11:53 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-07-27 11:52 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-27 11:52 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-27 11:52 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-27 11:52 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-27 11:52 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-27 11:52 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-27 11:52 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-27 11:52 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-27 11:52 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-27 11:52 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-27 11:52 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-27 11:52 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-27 11:52 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-27 11:52 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-27 11:52 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-27 11:52 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-27 11:52 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-27 11:52 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-27 11:52 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-27 11:52 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-27 11:52 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-27 11:52 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-27 11:52 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-27 11:52 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-27 11:52 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-27 11:52 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-27 11:52 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-27 11:52 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-27 11:52 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-27 11:52 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-27 11:52 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-27 11:52 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-27 11:52 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-27 11:52 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-27 11:52 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-27 11:52 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-27 11:52 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-27 11:52 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-27 11:52 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-27 11:52 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-27 11:52 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-27 11:52 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-27 11:52 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-27 11:52 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-27 11:52 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-27 11:52 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-27 11:52 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-27 11:52 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-27 11:52 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-27 11:52 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-27 11:52 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-27 11:52 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-27 11:52 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-27 11:52 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-27 11:52 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-27 11:52 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-27 11:52 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-27 11:52 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-27 11:52 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-27 11:52 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-27 11:52 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-27 11:52 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-07-27 11:52 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-07-27 11:52 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-07-27 11:52 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-07-27 11:52 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-07-27 11:52 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-07-27 11:52 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-07-27 11:52 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-07-27 08:31 - 2014-07-27 08:46 - 00000169 _____ () C:\Users\ndjokic\Desktop\useless.txt
2014-07-26 07:28 - 2014-07-30 17:57 - 00000467 _____ () C:\Users\ndjokic\Desktop\db.txt
2014-07-25 07:27 - 2014-07-25 07:27 - 00002376 _____ () C:\Users\ndjokic\Documents\MumbleAutomaticCertificateBackup.p12
2014-07-25 07:22 - 2014-07-25 07:57 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Mumble
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-07-24 22:20 - 2014-07-24 23:01 - 00000007 _____ () C:\Users\ndjokic\Desktop\New Text Document.txt
2014-07-24 15:05 - 2014-07-24 15:08 - 00000073 _____ () C:\Users\ndjokic\Desktop\acm reimb.txt
2014-07-23 15:36 - 2014-07-23 15:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-22 19:00 - 2014-07-27 13:53 - 00000000 ____D () C:\Users\ndjokic\Desktop\bill
2014-07-22 12:12 - 2014-07-30 06:09 - 00000840 _____ () C:\Windows\setupact.log
2014-07-20 18:06 - 2014-07-20 18:06 - 00000000 ____D () C:\ProgramData\ATI
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\ProgramData\AMD
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-07-20 18:00 - 2014-07-20 18:00 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201407201800525336.log
2014-07-20 18:00 - 2014-07-20 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-07-20 17:54 - 2014-07-20 17:54 - 00000000 ____D () C:\Program Files\AMD
2014-07-20 17:52 - 2014-07-20 17:52 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-07-20 00:48 - 2014-07-20 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2014-07-19 22:22 - 2014-07-19 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-07-18 01:09 - 2014-07-18 01:21 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\Hero_Siege
2014-07-17 23:07 - 2014-07-17 23:38 - 00000065 _____ () C:\Users\ndjokic\Desktop\hercules pw.txt
2014-07-14 19:26 - 2014-07-14 19:31 - 00000000 ____D () C:\Users\ndjokic\Desktop\hair progress
2014-07-12 00:24 - 2014-07-20 17:52 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\XGen Studios, Inc
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\XGen Studios, Inc
2014-07-11 22:46 - 2014-07-18 00:13 - 00000657 _____ () C:\Users\ndjokic\Desktop\local contest tasks.txt
2014-07-03 21:29 - 2014-07-18 01:08 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-03 21:29 - 2014-07-03 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-03 00:10 - 2014-07-03 00:10 - 00000000 ____D () C:\ProgramData\WaLMaRT
2014-07-02 22:37 - 2014-07-02 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trendy Entertainment
2014-07-02 14:20 - 2014-07-02 14:20 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-30 19:13 - 2014-07-30 19:12 - 00016948 _____ () C:\Users\ndjokic\Desktop\FRST.txt
2014-07-30 19:12 - 2014-07-30 19:10 - 00000000 ____D () C:\FRST
2014-07-30 19:10 - 2014-07-30 19:10 - 02093568 _____ (Farbar) C:\Users\ndjokic\Desktop\FRST64.exe
2014-07-30 19:10 - 2013-02-02 21:17 - 00000000 ____D () C:\Users\ndjokic\Desktop\dls
2014-07-30 19:09 - 2014-07-30 19:09 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-NDJOKIC-PC-Microsoft-Windows-7-Professional-(64-bit).dat
2014-07-30 19:08 - 2014-07-30 19:08 - 00000000 ____D () C:\RegBackup
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-30 19:07 - 2014-07-30 19:07 - 00000000 ____D () C:\Program Files (x86)\Registry Backup
2014-07-30 18:56 - 2014-01-27 21:49 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-30 18:26 - 2014-06-29 22:21 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-132009455-2026092721-3990303557-1000UA.job
2014-07-30 17:57 - 2014-07-26 07:28 - 00000467 _____ () C:\Users\ndjokic\Desktop\db.txt
2014-07-30 17:49 - 2013-12-19 10:13 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\Battle.net
2014-07-30 16:52 - 2012-09-15 13:19 - 02006456 _____ () C:\Windows\WindowsUpdate.log
2014-07-30 09:33 - 2014-01-27 21:49 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-30 09:30 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-30 09:30 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-30 09:25 - 2013-08-30 23:00 - 00003348 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-30 09:25 - 2013-08-30 23:00 - 00003218 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-30 09:24 - 2012-12-31 19:09 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\TSVNCache
2014-07-30 06:09 - 2014-07-22 12:12 - 00000840 _____ () C:\Windows\setupact.log
2014-07-30 06:09 - 2012-10-11 14:18 - 00000000 ____D () C:\ProgramData\VMware
2014-07-30 06:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-29 22:30 - 2014-06-29 22:21 - 00000864 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-132009455-2026092721-3990303557-1000Core.job
2014-07-29 22:10 - 2014-07-29 22:10 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\LOVE
2014-07-29 22:02 - 2014-07-29 22:02 - 00000000 ____D () C:\Users\ndjokic\Desktop\mari0
2014-07-28 20:54 - 2012-09-18 08:37 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Skype
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\movies
2014-07-28 18:52 - 2014-07-28 18:52 - 00000000 ____D () C:\Users\ndjokic\Desktop\food
2014-07-28 18:52 - 2014-06-18 20:37 - 00000134 _____ () C:\Users\ndjokic\Desktop\spb stuff.txt
2014-07-28 18:52 - 2014-02-17 15:18 - 00000000 ____D () C:\Users\ndjokic\Desktop\stuff
2014-07-28 18:52 - 2013-12-13 18:48 - 00000000 ____D () C:\Users\ndjokic\Desktop\games
2014-07-27 13:53 - 2014-07-22 19:00 - 00000000 ____D () C:\Users\ndjokic\Desktop\bill
2014-07-27 13:21 - 2012-10-11 21:28 - 00000000 ____D () C:\Users\ndjokic\.VirtualBox
2014-07-27 12:13 - 2013-09-28 18:09 - 00000000 ____D () C:\Windows\pss
2014-07-27 12:13 - 2012-12-02 18:20 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\LogMeIn Hamachi
2014-07-27 12:06 - 2009-07-14 06:45 - 00268856 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-27 12:04 - 2014-05-06 06:14 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-27 12:04 - 2009-07-14 09:47 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-27 12:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-27 12:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-27 12:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-27 12:01 - 2013-07-22 03:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-27 11:28 - 2014-04-23 06:45 - 00003240 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-27 11:27 - 2014-04-23 06:45 - 00003370 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2014-07-27 08:46 - 2014-07-27 08:31 - 00000169 _____ () C:\Users\ndjokic\Desktop\useless.txt
2014-07-26 16:02 - 2014-02-22 21:52 - 00000691 _____ () C:\Users\ndjokic\Desktop\6sm skipped.txt
2014-07-25 23:04 - 2013-11-06 21:10 - 00001162 _____ () C:\Users\ndjokic\Desktop\blu.txt
2014-07-25 07:57 - 2014-07-25 07:22 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Mumble
2014-07-25 07:27 - 2014-07-25 07:27 - 00002376 _____ () C:\Users\ndjokic\Documents\MumbleAutomaticCertificateBackup.p12
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-07-25 03:30 - 2014-07-25 03:30 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-07-25 00:17 - 2013-12-19 10:12 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-24 23:01 - 2014-07-24 22:20 - 00000007 _____ () C:\Users\ndjokic\Desktop\New Text Document.txt
2014-07-24 15:08 - 2014-07-24 15:05 - 00000073 _____ () C:\Users\ndjokic\Desktop\acm reimb.txt
2014-07-24 03:38 - 2012-09-15 13:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-23 15:37 - 2014-07-23 15:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-21 23:27 - 2013-10-04 22:23 - 00002108 _____ () C:\Users\ndjokic\Desktop\iou.txt
2014-07-21 21:54 - 2013-02-01 13:30 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-20 22:40 - 2013-07-11 18:26 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\vlc
2014-07-20 20:41 - 2012-09-18 10:23 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\uTorrent
2014-07-20 19:37 - 2012-09-22 19:40 - 00000000 ____D () C:\movies
2014-07-20 18:06 - 2014-07-20 18:06 - 00000000 ____D () C:\ProgramData\ATI
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\ProgramData\AMD
2014-07-20 18:01 - 2014-07-20 18:01 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-07-20 18:00 - 2014-07-20 18:00 - 00056100 _____ () C:\Windows\SysWOW64\CCCInstall_201407201800525336.log
2014-07-20 18:00 - 2014-07-20 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-07-20 18:00 - 2013-12-22 14:40 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-07-20 17:54 - 2014-07-20 17:54 - 00000000 ____D () C:\Program Files\AMD
2014-07-20 17:52 - 2014-07-20 17:52 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-07-20 17:52 - 2014-07-12 00:24 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-20 17:44 - 2013-12-22 14:24 - 00000000 ____D () C:\AMD
2014-07-20 00:48 - 2014-07-20 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2014-07-20 00:41 - 2012-09-15 16:09 - 00000000 ____D () C:\games
2014-07-19 22:22 - 2014-07-19 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-07-18 01:21 - 2014-07-18 01:09 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\Hero_Siege
2014-07-18 01:08 - 2014-07-03 21:29 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-18 00:13 - 2014-07-11 22:46 - 00000657 _____ () C:\Users\ndjokic\Desktop\local contest tasks.txt
2014-07-17 23:38 - 2014-07-17 23:07 - 00000065 _____ () C:\Users\ndjokic\Desktop\hercules pw.txt
2014-07-17 22:32 - 2012-11-20 23:07 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-16 16:01 - 2009-07-14 07:13 - 00786766 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-14 19:31 - 2014-07-14 19:26 - 00000000 ____D () C:\Users\ndjokic\Desktop\hair progress
2014-07-13 13:58 - 2014-05-15 02:45 - 00000225 _____ () C:\Users\ndjokic\Desktop\topc.txt
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\XGen Studios, Inc
2014-07-12 00:18 - 2014-07-12 00:18 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\XGen Studios, Inc
2014-07-06 03:18 - 2013-06-18 14:40 - 00000688 _____ () C:\Users\ndjokic\contestapplet.conf
2014-07-06 03:14 - 2013-06-18 14:40 - 00000688 _____ () C:\Users\ndjokic\contestapplet.conf.bak
2014-07-03 21:29 - 2014-07-03 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-03 00:10 - 2014-07-03 00:10 - 00000000 ____D () C:\ProgramData\WaLMaRT
2014-07-02 23:20 - 2013-09-06 20:32 - 00000000 ____D () C:\Users\ndjokic\AppData\Roaming\TS3Client
2014-07-02 22:40 - 2012-12-13 23:02 - 00000000 ____D () C:\Users\ndjokic\AppData\Local\SKIDROW
2014-07-02 22:37 - 2014-07-02 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trendy Entertainment
2014-07-02 14:20 - 2014-07-02 14:20 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-07-02 14:20 - 2014-02-09 20:57 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-06-30 12:18 - 2014-05-12 21:58 - 00000046 _____ () C:\Users\ndjokic\jagex_cl_runescape_LIVE.dat
2014-06-30 12:18 - 2014-05-12 21:58 - 00000024 _____ () C:\Users\ndjokic\random.dat
2014-06-30 04:09 - 2014-07-27 11:54 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-27 11:54 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Files to move or delete:
====================
C:\ProgramData\hash.dat
C:\Users\ndjokic\jagex_cl_oldschool_LIVE.dat
C:\Users\ndjokic\jagex_cl_runescape_LIVE.dat
C:\Users\ndjokic\random.dat
Some content of TEMP:
====================
C:\Users\ndjokic\AppData\Local\Temp\917b0b87-3358-4e79-93de-3dfc2fc99ed0.exe
C:\Users\ndjokic\AppData\Local\Temp\catalyst_mobility_64-bit_util.exe
C:\Users\ndjokic\AppData\Local\Temp\jna5155314657774875577.dll
C:\Users\ndjokic\AppData\Local\Temp\lowproc.exe
C:\Users\ndjokic\AppData\Local\Temp\SIInvoker.exe
C:\Users\ndjokic\AppData\Local\Temp\SkypeSetup.exe
C:\Users\ndjokic\AppData\Local\Temp\SRLDetectionLibrary5122638381083391501.dll
C:\Users\ndjokic\AppData\Local\Temp\SRLDetectionLibrary6002148792366687404.dll
C:\Users\ndjokic\AppData\Local\Temp\stubhelper.dll
C:\Users\ndjokic\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\ndjokic\AppData\Local\Temp\Uninstall.exe
C:\Users\ndjokic\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\ndjokic\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-28 19:34
==================== End Of Log ============================
aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-07-30 19:28:26
-----------------------------
19:28:26.517 OS Version: Windows x64 6.1.7601 Service Pack 1
19:28:26.517 Number of processors: 4 586 0x2A07
19:28:26.517 ComputerName: NDJOKIC-PC UserName: ndjokic
19:28:28.005 Initialize success
19:28:28.050 VM: initialized successfully
19:28:28.073 VM: Intel CPU BiosDisabled
19:28:37.973 VM: supported disk I/O iaStor.sys
19:32:33.425 AVAST engine defs: 14073001
19:33:42.590 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:33:42.590 Disk 0 Vendor: TOSHIBA_ MH00 Size: 476940MB BusType: 3
19:33:44.135 Disk 0 MBR read successfully
19:33:44.135 Disk 0 MBR scan
19:33:44.135 Disk 0 Windows 7 default MBR code
19:33:44.135 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 300 MB offset 2048
19:33:44.135 Disk 0 default boot code
19:33:44.150 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 455269 MB offset 616448
19:33:44.197 Disk 0 Partition 3 00 07 HPFS/NTFS 16247 MB offset 933007360
19:33:44.197 Disk 0 Partition 4 00 0C FAT32 LBA 5115 MB offset 966281216
19:33:44.275 Disk 0 scanning C:\Windows\system32\drivers
19:34:03.985 Service scanning
19:34:47.861 Modules scanning
19:34:47.861 Disk 0 trace - called modules:
19:34:49.609 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys iaStor.sys hal.dll
19:34:49.610 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800971a060]
19:34:49.610 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa800956e870]
19:34:49.610 5 hpdskflt.sys[fffff88001861361] -> nt!IofCallDriver -> [0xfffffa8007bb5e40]
19:34:49.610 7 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007bbe050]
19:34:51.098 AVAST engine scan C:\Windows
19:34:54.612 AVAST engine scan C:\Windows\system32
19:39:06.443 AVAST engine scan C:\Windows\system32\drivers
19:39:29.664 AVAST engine scan C:\Users\ndjokic
19:57:48.401 AVAST engine scan C:\ProgramData
20:14:25.729 Scan finished successfully
20:21:50.361 Disk 0 MBR has been saved successfully to "C:\Users\ndjokic\Desktop\july 2014 virus\MBR.dat"
20:21:50.384 The log file has been saved successfully to "C:\Users\ndjokic\Desktop\july 2014 virus\aswMBR.txt"