[removed]
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Windows\System32\srvany.exe
() C:\Windows\KMService.exe
() C:\Windows\System32\PnkBstrA.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-06-24] (Avast Software s.r.o.)
HKLM\…\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM\…\Run: [] => [X]
HKU\S-1-5-21-375955020-2390351569-884364006-1000\…\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKU\S-1-5-21-375955020-2390351569-884364006-1000\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-06-24] (Avast Software s.r.o.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-375955020-2390351569-884364006-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-25] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-06-24] (Avast Software s.r.o.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-25] (Oracle Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{0CB11609-494A-4BCC-B05A-F146CF418A33}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{1EF3960A-4905-4683-ACEF-4773FF41DFED}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2DA6A26E-3758-4C11-BE24-F305300C9BC8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{623A9E5B-17FF-481D-8B0F-414285B9A160}: [NameServer] 192.168.1.1,192.168.1.2
Tcpip\..\Interfaces\{7E6A4819-65BC-41EA-A24C-A2CE437DB98D}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{93248D76-F1B7-4826-BFE9-08EB22E04885}: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-25] (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-375955020-2390351569-884364006-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-18] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-375955020-2390351569-884364006-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2015-03-31]
FF HKU\S-1-5-21-375955020-2390351569-884364006-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-25]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-25]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-25]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-25]
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-07-25]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-25]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-25]
CHR HKLM\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-21]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-06-24] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3207800 2015-06-24] (Avast Software)
R2 KMService; C:\Windows\system32\srvany.exe [8192 2010-06-16] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2015-07-13] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-06-24] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [74976 2015-06-24] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-06-24] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-06-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787760 2015-06-24] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [428120 2015-06-26] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-06-24] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209048 2015-06-24] ()
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [113984 2014-10-25] (Power Software Ltd)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2015-02-21] () [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-06-24] (Avast Software)
U3 ap4kvxh4; C:\Windows\system32\Drivers\ap4kvxh4.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 XDva424; \??\C:\Windows\system32\XDva424.sys [X]
S3 XDva511; \??\C:\Windows\system32\XDva511.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-25 13:21 - 2015-08-25 13:21 - 00000000 ____D C:\Users\User\Downloads\FRST-OlderVersion
2015-08-23 16:46 - 2015-08-23 16:36 - 00001642 _____ C:\Users\User\Documents\New Text Document - Copy.txt
2015-08-23 16:36 - 2015-08-23 20:09 - 00003470 _____ C:\Users\User\Documents\New Text Document.txt
2015-08-23 15:47 - 2015-08-23 15:47 - 00000000 _____ C:\Users\User\Desktop\New Text Document.txt
2015-08-20 20:08 - 2015-08-20 20:08 - 00000036 _____ C:\Windows\megastark.dat
2015-08-20 20:08 - 2015-08-20 20:08 - 00000000 ____D C:\Programme
2015-08-20 19:55 - 2015-08-20 19:55 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Star Trek Elite Force II
2015-08-19 21:22 - 2015-08-20 15:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty with United Offensive expansion
2015-08-19 15:40 - 2001-05-24 15:00 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2015-08-17 15:18 - 2015-08-17 15:19 - 00000000 ____D C:\Program Files\WWE RAW 2009
2015-08-16 20:17 - 2015-08-16 20:17 - 00001369 _____ C:\Users\User\Desktop\EF2.lnk
2015-08-16 20:10 - 2015-08-20 22:29 - 00000000 ____D C:\Program Files\Activision
2015-08-16 20:10 - 2015-08-20 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Trek Elite Force II
2015-08-16 19:59 - 2015-08-16 19:59 - 00000000 ____D C:\Program Files\BlackBean
2015-08-16 19:45 - 2015-08-16 19:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Patriots
2015-08-08 15:35 - 2015-08-08 16:09 - 00000000 ____D C:\Users\User\Documents\Cross Fire
2015-08-08 15:33 - 2015-08-08 15:33 - 00000722 _____ C:\Users\User\Desktop\Crossfire Europe.lnk
2015-08-08 15:33 - 2015-08-08 15:33 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossfire Europe
2015-08-08 15:33 - 2015-08-08 15:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossfire Europe
2015-08-08 14:28 - 2015-08-08 14:28 - 02156048 _____ (Reloaded Technologies) C:\Users\User\Downloads\Crossfire_downloader.exe
2015-08-07 13:58 - 2015-08-07 13:58 - 05565454 _____ C:\Users\User\Downloads\mari0-win.zip
2015-08-07 13:58 - 2015-08-07 13:58 - 00000000 ____D C:\Users\User\AppData\Roaming\LOVE
2015-08-07 13:49 - 2015-08-20 22:21 - 00001256 _____ C:\Windows\PFRO.log
2015-08-04 14:37 - 2015-08-25 13:21 - 00011000 _____ C:\Users\User\Downloads\FRST.txt
2015-08-04 14:37 - 2015-08-04 14:38 - 00030160 _____ C:\Users\User\Downloads\Addition.txt
2015-08-04 14:36 - 2015-08-25 13:21 - 01690112 _____ (Farbar) C:\Users\User\Downloads\FRST.exe
2015-08-04 14:36 - 2015-08-25 13:21 - 00000000 ____D C:\FRST
2015-08-03 14:29 - 2015-08-25 13:06 - 00004200 _____ C:\Windows\setupact.log
2015-08-03 14:29 - 2015-08-03 14:29 - 00000000 _____ C:\Windows\setuperr.log
2015-08-01 14:19 - 2015-08-01 14:20 - 04383777 _____ C:\Users\User\Downloads\tdsskiller (1).zip
2015-08-01 12:49 - 2015-08-01 12:49 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\User\Downloads\iExplore.exe
2015-08-01 03:26 - 2015-08-25 13:09 - 00273634 _____ C:\Windows\WindowsUpdate.log
2015-08-01 03:22 - 2015-08-01 03:22 - 00000448 _____ C:\Windows\system32\.crusader
2015-08-01 02:13 - 2015-08-01 02:13 - 00001893 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2015-08-01 01:49 - 2015-08-01 02:01 - 00000000 ____D C:\Program Files\HitmanPro
2015-08-01 01:45 - 2015-08-01 01:45 - 02248704 _____ C:\Users\User\Downloads\adwcleaner_4.208.exe
2015-08-01 01:14 - 2015-08-01 01:14 - 04383777 _____ C:\Users\User\Downloads\tdsskiller.zip
2015-07-31 22:22 - 2015-07-31 22:22 - 00000000 __SHD C:\Windows\ftpcache
2015-07-27 21:33 - 2015-07-27 21:33 - 00000000 ____D C:\Users\User\Documents\Paradox Interactive
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-25 13:13 - 2009-07-14 06:34 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-25 13:13 - 2009-07-14 06:34 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-25 13:09 - 2014-06-25 12:52 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-25 13:06 - 2014-06-25 12:52 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-25 13:06 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-22 00:00 - 2014-06-25 12:52 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-20 22:52 - 2015-02-25 23:51 - 00000319 _____ C:\Windows\game.ini
2015-08-20 15:56 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2015-08-19 21:23 - 2015-02-16 18:45 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-16 20:08 - 2015-02-21 18:17 - 00000000 ____D C:\Users\User\AppData\Roaming\DAEMON Tools Lite
2015-08-16 20:08 - 2015-02-17 17:07 - 00000000 ____D C:\Program Files\Common Files\InstallShield
2015-08-16 19:59 - 2015-02-25 23:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-08-07 23:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-07 18:10 - 2014-06-25 12:50 - 00107192 _____ C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-07 18:09 - 2009-07-14 06:33 - 00403976 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-07 17:52 - 2014-06-25 12:38 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-07 17:51 - 2014-06-25 12:39 - 00000000 ____D C:\Program Files\Microsoft.NET
2015-08-07 17:51 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-07 17:50 - 2010-11-21 02:46 - 00000000 ____D C:\Windows\ShellNew
2015-08-07 17:50 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\MSBuild
2015-08-07 17:49 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\System
2015-08-07 17:49 - 2009-07-14 04:04 - 00000422 _____ C:\Windows\win.ini
2015-08-07 12:59 - 2014-06-25 12:49 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-08-07 12:55 - 2014-06-25 12:49 - 00000000 ____D C:\ProgramData\Adobe
2015-08-07 12:55 - 2014-06-25 12:49 - 00000000 ____D C:\Program Files\Adobe
2015-08-07 12:54 - 2015-02-17 15:49 - 00000000 ____D C:\Games
2015-08-07 12:52 - 2015-07-10 03:21 - 00000000 ____D C:\Users\User\Documents\Euro Truck Simulator 2
2015-08-05 20:57 - 2015-04-14 18:44 - 00000000 ____D C:\Users\User\AppData\Roaming\Xfire
2015-08-02 21:01 - 2015-02-17 15:30 - 00000000 ____D C:\Users\User\AppData\Roaming\uTorrent
2015-08-01 14:42 - 2014-06-25 12:36 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-01 14:36 - 2015-03-09 00:59 - 00000000 ____D C:\Windows\pss
2015-08-01 14:35 - 2015-04-29 22:11 - 00000000 ____D C:\Program Files\Proun
2015-08-01 14:34 - 2015-05-11 22:59 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-08-01 14:34 - 2015-05-11 21:13 - 00000000 ____D C:\Program Files\Electronic Arts
2015-08-01 14:34 - 2009-07-14 06:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-08-01 14:22 - 2015-03-11 00:52 - 00000000 ____D C:\AdwCleaner
2015-08-01 13:51 - 2015-05-30 13:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-01 13:45 - 2009-07-14 06:53 - 00032652 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-01 02:07 - 2015-03-31 11:10 - 00000000 ____D C:\Users\User\AppData\Roaming\Yahoo!
2015-07-30 17:48 - 2015-07-01 21:47 - 00003242 _____ C:\Users\User\AppData\Roaming\glide_wrapper.zbag.ini
2015-07-27 22:29 - 2015-02-25 23:52 - 00141512 _____ C:\Windows\system32\Drivers\PnkBstrK.sys
2015-07-27 22:28 - 2015-03-01 18:46 - 00282504 _____ C:\Windows\system32\PnkBstrB.xtr
2015-07-27 22:28 - 2015-02-25 23:52 - 00282504 _____ C:\Windows\system32\PnkBstrB.exe
==================== Files in the root of some directories =======
2015-07-01 21:47 - 2015-07-30 17:48 - 0003242 _____ () C:\Users\User\AppData\Roaming\glide_wrapper.zbag.ini
2015-02-25 23:52 - 2015-02-25 23:52 - 0022328 _____ () C:\Users\User\AppData\Roaming\PnkBstrK.sys
2015-03-31 11:06 - 2015-03-31 11:11 - 0000816 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
C:\Users\User\AppData\Local\Temp\uninst1.exe
C:\Users\User\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-08-13 13:43
==================== End of FRST.txt ============================
Addition:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:24-08-2015
Ran by [removed] (2015-08-25 13:21:52)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-375955020-2390351569-884364006-500 - Administrator - Disabled)
Guest (S-1-5-21-375955020-2390351569-884364006-501 - Limited - Disabled)
User (S-1-5-21-375955020-2390351569-884364006-1000 - Administrator - Enabled) => C:\Users\User
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-375955020-2390351569-884364006-1000\…\uTorrent) (Version: 3.4.3.40760 - BitTorrent Inc.)
32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM\…\Adobe Shockwave Player) (Version: 10.2.0.22 - Adobe Systems, Inc.)
AMD Catalyst Install Manager (HKLM\…\{0BD03BF6-3A66-EC7F-5155-28A8D6C69409}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Auslogics Disk Defrag Professional (HKLM\…\{ADE1535C-C836-4F2E-BDA1-1C7C304743E3}_is1) (Version: 4.2 - Auslogics Software Pty Ltd)
Avast Free Antivirus (HKLM\…\Avast) (Version: 10.2.2218 - AVAST Software)
BS.Player PRO (HKLM\…\BSPlayerp) (Version: 2.67.1076 - AB Team, d.o.o.)
BufferChm (Version: 140.0.212.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.05 - Piriform)
Copy (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Crossfire Europe (HKLM\…\Crossfire Europe) (Version: 1.172 - SG Europe)
Destinations (Version: 140.0.77.000 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 140.0.212.000 - Hewlett-Packard) Hidden
DJ_AIO_06_F2400_SW_Min (Version: 140.0.690.000 - Hewlett-Packard) Hidden
DXGL Wrapper (HKLM\…\GLWRAPPER) (Version: - )
F2400 (Version: 140.0.690.000 - Hewlett-Packard) Hidden
Fraps (HKLM\…\Fraps) (Version: - )
FreeArc 0.666 (HKLM\…\FreeArc) (Version: 0.666 - Bulat Ziganshin)
Google Chrome (HKLM\…\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Earth (HKLM\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
GPBaseService2 (Version: 140.0.211.000 - Hewlett-Packard) Hidden
HitmanPro 3.7 (HKLM\…\HitmanPro37) (Version: 3.7.9.242 - SurfRight B.V.)
HP Customer Participation Program 14.0 (HKLM\…\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Deskjet F2400 All-in-One Driver Software 14.0 Rel. 6 (HKLM\…\{819CA3BC-2FF8-4811-B42F-421F7BFD3559}) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\…\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photo Creations (HKLM\…\HP Photo Creations) (Version: 1.0.0.2024 - HP Photo Creations Powered by RocketLife)
HP Smart Web Printing 4.60 (HKLM\…\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 14.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPPhotoGadget (Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 140.0.212.000 - Hewlett-Packard) Hidden
HPSSupply (Version: 140.0.211.000 - Hewlett-Packard) Hidden
IrfanView (remove only) (HKLM\…\IrfanView) (Version: 4.38 - Irfan Skiljan)
Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
K-Lite Codec Pack 10.5.5 Full (HKLM\…\KLiteCodecPack_is1) (Version: 10.5.5 - )
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM\…\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
PowerISO (HKLM\…\PowerISO) (Version: 6.1 - Power Software Ltd)
Revo Uninstaller 1.95 (HKLM\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Scan (Version: 140.0.80.000 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 14.0 - HP)
Skype™ 7.3 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
SmartWebPrinting (Version: 140.0.186.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 140.0.213.000 - Hewlett-Packard) Hidden
Status (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Toolbox (Version: 140.0.428.000 - Hewlett-Packard) Hidden
TrayApp (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Unity Web Player (HKU\S-1-5-21-375955020-2390351569-884364006-1000\…\UnityWebPlayer) (Version: 4.6.3f1 - Unity Technologies ApS)
WebReg (Version: 140.0.212.017 - Hewlett-Packard) Hidden
Winamp (HKLM\…\Winamp) (Version: 5.666 - Nullsoft, Inc)
WinRAR 5.21 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xfire (HKLM\…\Xfire) (Version: - )
zeckensack's Glide wrapper (remove only) (HKLM\…\GlidewrapZbag) (Version: - )
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-375955020-2390351569-884364006-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
==================== Restore Points =========================
28-06-2015 02:38:09 Checkpoint by HitmanPro
28-06-2015 02:38:55 Checkpoint by HitmanPro
28-06-2015 22:52:46 Removed Skype Click to Call
06-07-2015 19:25:09 Scheduled Checkpoint
10-07-2015 01:13:04 Installed System Requirements Lab Detection
12-07-2015 23:05:38 Installed Microsoft XNA Framework Redistributable 4.0
13-07-2015 19:56:10 Installed DirectX
25-07-2015 14:58:04 Scheduled Checkpoint
30-07-2015 17:17:52 Installed Joint Task Force
01-08-2015 00:56:20 Removed Joint Task Force
01-08-2015 01:19:17 Installed Microsoft Fix it 50267
01-08-2015 01:33:12 Checkpoint by HitmanPro
01-08-2015 01:35:16 Checkpoint by HitmanPro
01-08-2015 01:36:52 Checkpoint by HitmanPro
01-08-2015 01:37:31 Checkpoint by HitmanPro
01-08-2015 01:38:15 Checkpoint by HitmanPro
01-08-2015 02:07:05 Checkpoint by HitmanPro
01-08-2015 03:22:25 Checkpoint by HitmanPro
01-08-2015 04:25:18 Checkpoint by HitmanPro
01-08-2015 14:34:36 Removed System Requirements Lab Detection
01-08-2015 14:35:55 Removed System Requirements Lab
07-08-2015 17:48:53 Removed Microsoft Office Professional Plus 2010
16-08-2015 19:53:19 Installed Secret Weapons Over Normandy
16-08-2015 19:59:24 Installed LegionArena
16-08-2015 20:07:41 Removed LegionArena
20-08-2015 22:28:03 Installed Call of Duty(R) 4 - Modern Warfare(TM)
22-08-2015 11:11:07 Removed Call of Duty(R) 4 - Modern Warfare(TM)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0777F5E3-923A-4C8F-97C5-18D8D93842D4} - System32\Tasks\Auslogics\Disk Defrag Prof\Task {00000001-FC81-4F77-807C-0FBEEDB9780D} for User => C:\Program Files\Auslogics\Auslogics Disk Defrag Professional\DiskDefragPro.exe [2013-06-13] (Auslogics)
Task: {0B3FA2DA-F614-4E42-8A65-DFE330DCC586} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-24] (Avast Software s.r.o.)
Task: {20B8DAB6-C717-4DFC-93FA-3907A7C79DFA} - System32\Tasks\{E80F43B8-B79C-4ED2-AEEA-BE58200128F5} => C:\Users\User\Downloads\O390-A11.exe [2014-12-30] ()
Task: {266D47E9-57C1-446F-A9B3-FC04194A835F} - System32\Tasks\{DE0E5F05-CBD3-4604-B6BA-0B01B75DAE83} => C:\Program Files\Activision\EF2\EF2.exe
Task: {2802F59F-1C97-48E5-81E8-F36DC6AB0548} - System32\Tasks\{2313A546-D596-4BA4-B065-6C6AD1AEBF5B} => D:\igre\Half Life 2\hl2.exe
Task: {2CA188E7-081D-4E50-913C-B7BDC936D2FC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15] (Adobe Systems Incorporated)
Task: {35312FE8-A944-4BA6-9F6A-B822618C5659} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-06-25] (Google Inc.)
Task: {369F2D24-8FB8-4606-8514-C45FFDD4FD15} - System32\Tasks\{02928F06-3A76-4C77-884D-682F34B2F2EF} => pcalua.exe -a "D:\STAR TREK ARMADA\AUTORUN.EXE" -d "D:\STAR TREK ARMADA"
Task: {3D08B91F-1064-473A-A830-37AC58FB6322} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-06-25] (Google Inc.)
Task: {48197A5E-9CC0-4D53-BB37-AB7F344B7677} - System32\Tasks\Auslogics\Disk Defrag Prof\Task {00000001-CA4A-4C2B-B6B1-F84D725566A0} for User => C:\Program Files\Auslogics\Auslogics Disk Defrag Professional\DiskDefragPro.exe [2013-06-13] (Auslogics)
Task: {65629873-6EB7-42AF-B21F-3A95FCF48185} - System32\Tasks\{65C30767-648A-49B5-B878-B38D958AC39F} => pcalua.exe -a F:\autorun.exe -d F:\
Task: {7202C954-3717-46DC-B2D5-306DB2722363} - System32\Tasks\{5D1DFD1D-16BE-435B-B0DF-942A1A519727} => pcalua.exe -a E:\DrvoZnanja.exe -d E:\
Task: {7D0B5971-887D-483E-974B-65887A927950} - System32\Tasks\{58BE22AA-263A-4F41-8F89-74CA6650B2DF} => pcalua.exe -a C:\Users\User\AppData\Local\Temp\$PowerISO$\Setup.exe -d "E:\Star Trek Armada II"
Task: {82ED09DB-41EB-4431-952C-E1561FE93F6B} - System32\Tasks\{4649A3E2-9DB2-4E05-B5D9-14D62F9948B3} => D:\igre\Half Life 2\hl2.exe
Task: {992FDB8C-40BB-42EB-9B92-2BA56936D57C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {9C5F18FE-95A4-4579-A835-A7E1F49E224C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {9EA6155F-77FB-409B-B006-CC295D32FCDB} - System32\Tasks\{574EB3FC-ACB2-4124-8C73-D2FE1E165FF5} => C:\Program Files\Activision\EF2\EF2.exe
Task: {AE9506FD-0F84-4B49-907A-9B52B7E3B512} - System32\Tasks\{7B5D4FEA-9188-4473-A5EF-98415AA55ED2} => pcalua.exe -a "D:\STAR TREK EF\Setup.exe" -d "D:\STAR TREK EF"
Task: {F7DE4CD8-BFAD-432B-A39D-E3BFA95D1F1F} - System32\Tasks\Auslogics\Disk Defrag Prof\Task {00000001-EE3F-46FA-BA8A-8104A6F6DF25} for User => C:\Program Files\Auslogics\Auslogics Disk Defrag Professional\DiskDefragPro.exe [2013-06-13] (Auslogics)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-06-24 13:27 - 2015-06-24 13:27 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-06-24 13:27 - 2015-06-24 13:27 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-08-24 22:53 - 2015-08-24 22:53 - 02960896 _____ () C:\Program Files\AVAST Software\Avast\defs\15082404\algo.dll
2015-08-25 13:07 - 2015-08-25 13:07 - 02960896 _____ () C:\Program Files\AVAST Software\Avast\defs\15082500\algo.dll
2015-04-01 21:33 - 2010-06-16 01:44 - 00008192 _____ () C:\Windows\system32\srvany.exe
2015-04-01 21:33 - 2010-12-27 16:59 - 00163840 _____ () C:\Windows\KMService.exe
2015-02-25 23:51 - 2015-07-13 20:05 - 00075136 _____ () C:\Windows\system32\PnkBstrA.exe
2015-03-21 18:11 - 2015-03-21 18:12 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-08-22 00:00 - 2015-08-18 07:23 - 01405768 _____ () C:\Program Files\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-22 00:00 - 2015-08-18 07:23 - 00081224 _____ () C:\Program Files\Google\Chrome\Application\44.0.2403.157\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87647028.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\87647028.sys => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-375955020-2390351569-884364006-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EA Core => "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
MSCONFIG\startupreg: HP Software Update => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{8BDA9B7B-10F0-408C-9B5B-16A747C0EE3E}] => (Allow) C:\Program Files\Winamp\winamp.exe
FirewallRules: [{57DE4EA7-D7DA-45DC-97E4-6218A9344534}] => (Allow) C:\Program Files\Winamp\winamp.exe
FirewallRules: [{95113E63-C1A9-44CE-99B6-DDE7548AA451}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{557C2FA3-602C-471B-B8D9-3D50521205CD}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{932A7DC4-52D6-4833-BF9E-F47F36A1F052}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [{74E5DF9F-684B-4344-A84C-5C7C05D6F6AA}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D29E4C58-1560-4686-BF32-26AB00082827}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{82A1888C-9728-491D-B347-870494DB01A3}] => (Allow) C:\Windows\System32\PnkBstrA.exe
FirewallRules: [{44A71195-4DB6-4C38-9736-8DFCD80F46C0}] => (Allow) C:\Windows\System32\PnkBstrA.exe
FirewallRules: [{F55F4EB9-8C45-408B-A871-46C238DE1CF8}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{5375BA36-B55F-4231-B89D-863212C5393A}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [TCP Query User{74BA4BEA-C681-4C60-9190-A1600B7F157A}D:\igre\cod2\call of duty 2\cod2mp_s.exe] => (Allow) D:\igre\cod2\call of duty 2\cod2mp_s.exe
FirewallRules: [UDP Query User{8BDE9F20-1821-41A0-A589-183BB42547BD}D:\igre\cod2\call of duty 2\cod2mp_s.exe] => (Allow) D:\igre\cod2\call of duty 2\cod2mp_s.exe
FirewallRules: [{3B3CD1D0-4D71-4DAA-B7E7-D9E5E973861F}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{D1393F14-F6B8-41D4-9AB6-C788FE278156}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{154CC7C5-6DF3-4E92-9428-104D387398CB}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{82B640D8-2BD5-465C-A99A-F17F92BEF5E6}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{AD8CF9E2-0167-48A1-BF81-CBEE1BE1B8C8}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{B785CFEF-14AD-4F5E-9F44-68785818DDB5}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{597F144A-1C27-4989-B0C1-D36161D8D7C5}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{F2AD2C36-F02C-470B-ADF2-1CA7C2DEB5DB}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{340ECF8B-3470-4459-926B-C5DB847054F4}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{67043055-628C-4348-9EAE-E1022170E5C9}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{E4006E18-2C5C-4C6F-951F-A43C9C3B5E94}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{C84F9E2A-80FF-4CF2-8E88-5D8B6B2E2CBA}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{1980C063-7240-447A-855E-A5C5A2FFDB17}] => (Allow) C:\Program Files\HP\hp software update\hpwucli.exe
FirewallRules: [{DAA276D9-34FD-4766-8210-74569BB3FEC2}] => (Allow) C:\Program Files\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [TCP Query User{286C26E3-6608-48A7-97DE-E8886E590058}C:\program files\xfire\xfire.exe] => (Allow) C:\program files\xfire\xfire.exe
FirewallRules: [UDP Query User{67A0BAEB-9E36-4878-AB62-303FCDD70EEE}C:\program files\xfire\xfire.exe] => (Allow) C:\program files\xfire\xfire.exe
FirewallRules: [TCP Query User{09154BEC-AFEA-425E-9BE2-F18FE2B1FDED}C:\program files\proun\proun.exe] => (Block) C:\program files\proun\proun.exe
FirewallRules: [UDP Query User{459FC1C7-4412-4CDC-8A3E-CFE0281EC2C0}C:\program files\proun\proun.exe] => (Block) C:\program files\proun\proun.exe
FirewallRules: [{D2C42184-D531-45BF-8C0C-EC3A6AE07221}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{AA7FF680-B864-429A-9B10-77F9D229C64F}D:\igre\mortal kombat\mortal kombat complete edition\mkke.exe] => (Allow) D:\igre\mortal kombat\mortal kombat complete edition\mkke.exe
FirewallRules: [UDP Query User{47EE1309-909E-48DF-8A47-57DBEA810A2D}D:\igre\mortal kombat\mortal kombat complete edition\mkke.exe] => (Allow) D:\igre\mortal kombat\mortal kombat complete edition\mkke.exe
FirewallRules: [TCP Query User{292FE003-7515-47AA-8C6E-B9F80789E544}C:\program files\electronic arts\eadm\core.exe] => (Block) C:\program files\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{22AD1FD0-927A-4C9B-B68D-83E6E06F6E35}C:\program files\electronic arts\eadm\core.exe] => (Block) C:\program files\electronic arts\eadm\core.exe
FirewallRules: [{C9FAC349-9A05-4B33-B9F4-AE26DD98A6CC}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{5A7E878D-E2A2-4522-BD2A-55BF350AE648}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{3DAF9EE2-43D8-492A-AE3D-E9A909F7D512}] => (Allow) D:\igre\Half Life 2\hl2.exe
FirewallRules: [{CF84BE01-9D37-422B-AE18-A1D15EF48EFD}] => (Allow) D:\igre\Half Life 2\hl2.exe
FirewallRules: [TCP Query User{11D11225-86DF-4F8D-B12D-009855286B09}D:\igre\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe] => (Allow) D:\igre\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe
FirewallRules: [UDP Query User{1D88ECC1-68DD-47FD-8121-2F16E862CDE6}D:\igre\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe] => (Allow) D:\igre\red orchestra 2 heroes of stalingrad\binaries\win32\rogame.exe
FirewallRules: [TCP Query User{CC272F72-49A2-4649-A662-DAA3507F65C7}C:\program files\patriots\patriots.exe] => (Block) C:\program files\patriots\patriots.exe
FirewallRules: [UDP Query User{9D61BCBB-1770-4D6B-84E4-DB345BF81557}C:\program files\patriots\patriots.exe] => (Block) C:\program files\patriots\patriots.exe
FirewallRules: [TCP Query User{52B74637-44AC-40E1-800E-4D6F9550CCDA}C:\program files\activision\ef2\ef2.exe] => (Block) C:\program files\activision\ef2\ef2.exe
FirewallRules: [UDP Query User{0133CC89-EC74-4868-AF15-AF6FD1D8634E}C:\program files\activision\ef2\ef2.exe] => (Block) C:\program files\activision\ef2\ef2.exe
FirewallRules: [TCP Query User{3A7F09D3-36F1-4C92-B288-7CDCDDEF9BB3}C:\program files\call of duty\coduomp.exe] => (Allow) C:\program files\call of duty\coduomp.exe
FirewallRules: [UDP Query User{BC293EE3-A5B1-47D5-9727-1D43ADC54F4D}C:\program files\call of duty\coduomp.exe] => (Allow) C:\program files\call of duty\coduomp.exe
FirewallRules: [TCP Query User{13FE483F-7C57-4459-9943-6AA5AEC95F6B}D:\star trek ef\ef2.exe] => (Block) D:\star trek ef\ef2.exe
FirewallRules: [UDP Query User{46E5B918-5606-40D6-B568-B685CCB78DCC}D:\star trek ef\ef2.exe] => (Block) D:\star trek ef\ef2.exe
FirewallRules: [{BA85B7F1-451D-4315-907F-F4294A5B7102}] => (Allow) C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{969B6E31-6BB8-4C1C-8493-9662FFDA8FAA}] => (Allow) C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{E7D36E7D-716C-49D6-A34F-A399C0E88D58}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/25/2015 01:07:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/24/2015 02:02:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2015 10:45:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2015 12:15:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2015 01:46:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2015 11:11:07 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {09741daa-5423-458c-9095-45a53fa352e2}
Error: (08/22/2015 10:29:00 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/21/2015 12:51:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/21/2015 11:06:45 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/20/2015 10:28:02 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {0a3b3d0f-31f1-43a6-b4a0-a7c20ce492bd}
System errors:
=============
Error: (08/25/2015 01:09:01 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/25/2015 01:07:15 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/25/2015 01:06:58 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/25/2015 01:06:57 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/25/2015 01:06:42 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/25/2015 03:01:46 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/24/2015 06:55:11 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/24/2015 06:52:55 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/24/2015 06:52:54 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (08/24/2015 06:52:50 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Microsoft Office:
=========================
Error: (08/25/2015 01:07:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/24/2015 02:02:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2015 10:45:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/23/2015 12:15:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2015 01:46:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/22/2015 11:11:07 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {09741daa-5423-458c-9095-45a53fa352e2}
Error: (08/22/2015 10:29:00 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/21/2015 12:51:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/21/2015 11:06:45 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/20/2015 10:28:02 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {0a3b3d0f-31f1-43a6-b4a0-a7c20ce492bd}
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Percentage of memory in use: 32%
Total physical RAM: 3582.42 MB
Available physical RAM: 2418 MB
Total Virtual: 7163.13 MB
Available Virtual: 5724.03 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:157.86 GB) (Free:96.19 GB) NTFS
Drive d: () (Fixed) (Total:74.41 GB) (Free:54.09 GB) NTFS
Drive e: (COD4_MW_DVD_1) (CDROM) (Total:2.36 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=625 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=157.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=74.4 GB) - (Type=07 NTFS)
==================== End of FRST.txt ============================