Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-01-2013
Ran by SYSTEM at 09-01-2013 09:06:32
Running from G:\
Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [10959464 2012-01-15] (Realtek Semiconductor)
HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Pavel\...\Run: [Akamai NetSession Interface] "C:\Users\Pavel\AppData\Local\Akamai\netsession_win.exe" [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKU\Pavel\...\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED
HKU\Pavel\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17877168 2012-11-09] (Skype Technologies S.A.)
HKU\Pavel\...\Run: [Advanced SystemCare 6] "C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart [490880 2012-09-24] (IObit)
HKU\UpdatusUser\...\Run: [SansaDispatch] C:\Users\UpdatusUser\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
HKU\UpdatusUser\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2009-07-13] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [Akamai NetSession Interface] "C:\Users\Pavel\AppData\Local\Akamai\netsession_win.exe" [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKLM\...\Runonce: []
HKLM\...\Runonce: [GrpConv] grpconv -o
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Google Calendar Sync.lnk
ShortcutTarget: Google Calendar Sync.lnk -> C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\Pavel\Start Menu\Programs\Startup\AutoHotkey.lnk
ShortcutTarget: AutoHotkey.lnk -> C:\Program Files\AutoHotkey\AutoHotkey.exe ()
==================== Services (Whitelisted) ===================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [660664 2009-11-12] (Acronis)
2 AdvancedSystemCareService6; C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe [464256 2012-10-31] (IObit)
2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [2480048 2010-06-12] (Acronis)
3 Amazon Download Agent; C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [401920 2009-10-23] (Amazon.com)
2 Diskeeper; "C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe" [1732960 2009-12-24] (Diskeeper Corporation)
3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [1044816 2012-05-12] (Flexera Software, Inc.)
2 LkCitadelServer; C:\Windows\system32\lkcitdl.exe [695136 2008-06-17] (National Instruments, Inc.)
2 lkClassAds; C:\Windows\system32\lkads.exe [40488 2008-06-17] (National Instruments Corporation)
2 lkTimeSync; C:\Windows\system32\lktsrv.exe [50736 2008-06-17] (National Instruments Corporation)
2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [398184 2012-12-14] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [682344 2012-12-14] (Malwarebytes Corporation)
2 MOBKbackup; "C:\Program Files\McAfee Online Backup\MOBKbackup.exe" [229688 2010-04-13] (McAfee, Inc.)
2 mxssvr; "C:\Program Files\National Instruments\MAX\nimxs.exe" [12696 2009-10-20] (National Instruments Corporation)
2 ni488enumsvc; C:\Windows\System32\nipalsm.exe [12696 2008-08-21] (National Instruments Corporation)
2 NIDomainService; "C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe" [213552 2008-06-17] (National Instruments Corporation)
2 niLXIDiscovery; "C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe" [131704 2009-03-05] (National Instruments Corporation)
2 nimDNSResponder; "C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" [193648 2009-06-04] (National Instruments Corporation)
2 nipxirmu; C:\Windows\System32\nipalsm.exe [12696 2008-08-21] (National Instruments Corporation)
2 niSvcLoc; C:\Windows\system32\nisvcloc.exe -s [13896 2009-06-04] (National Instruments Corporation)
2 QBVSS; "C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe" [1248256 2011-12-21] (Intuit Inc.)
3 RasMan; C:\Windows\System32\svchost.exe -k netsvcs [20992 2009-07-13] (Microsoft Corporation)
3 SensrSvc; C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [20992 2009-07-13] (Microsoft Corporation)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3290896 2012-12-13] (Skype Technologies S.A.)
3 WebClient; C:\Windows\System32\svchost.exe -k LocalService [20992 2009-07-13] (Microsoft Corporation)
3 WPDBusEnum; C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 mcpltsvc; "C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc
==================== Drivers (Whitelisted) ====================
2 cvintdrv; C:\Windows\System32\Drivers\cvintdrv.sys [4096 2009-08-03] ()
3 DKRtWrt; C:\Windows\System32\DRIVERS\DKRtWrt.sys [45616 2009-12-10] (Diskeeper Corporation)
3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147472 2012-05-28] (McAfee, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [21104 2012-12-14] (Malwarebytes Corporation)
3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [252200 2012-11-02] (McAfee, Inc.)
3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [81456 2012-11-02] (McAfee, Inc.)
1 MOBKFilter; C:\Windows\System32\DRIVERS\MOBK.sys [54776 2010-04-13] (Mozy, Inc.)
3 ni1006k; \??\C:\Windows\system32\drivers\ni1006k.sys [26192 2009-04-01] (National Instruments Corporation)
3 ni1045k; \??\C:\Windows\system32\drivers\ni1045kl.sys [11344 2009-06-17] (National Instruments Corporation)
3 ni1065k; \??\C:\Windows\system32\drivers\ni1065k.sys [22608 2009-04-01] (National Instruments Corporation)
3 ni488lock; \??\C:\Windows\system32\drivers\ni488lock.sys [17480 2009-12-15] (National Instruments Corporation)
3 nidimk; \??\C:\Windows\system32\drivers\nidimkl.sys [11360 2009-07-07] (National Instruments Corporation)
3 nimdbgk; \??\C:\Windows\system32\drivers\nimdbgkl.sys [11360 2009-07-07] (National Instruments Corporation)
3 nimxdfk; \??\C:\Windows\system32\drivers\nimxdfkl.sys [11344 2009-07-07] (National Instruments Corporation)
3 niorbk; \??\C:\Windows\system32\drivers\niorbkl.sys [11344 2009-06-14] (National Instruments Corporation)
3 nipalfwedl; C:\Windows\System32\drivers\nipalfwedl.sys [11904 2009-10-30] (National Instruments Corporation)
0 NIPALK; C:\Windows\System32\drivers\nipalk.sys [597592 2009-10-30] (National Instruments Corporation)
3 nipalusbedl; C:\Windows\System32\drivers\nipalusbedl.sys [11896 2009-10-30] (National Instruments Corporation)
0 nipbcfk; C:\Windows\System32\drivers\nipbcfk.sys [15448 2009-07-07] (National Instruments Corporation)
3 nipxigpk; \??\C:\Windows\system32\drivers\nipxigpk.sys [20568 2008-06-25] (National Instruments Corporation)
2 nipxirmk; \??\C:\Windows\system32\drivers\nipxirmkl.sys [11344 2009-07-07] (National Instruments Corporation)
3 NiViFWK; C:\Windows\System32\drivers\NiViFWKl.sys [11384 2009-03-05] (National Instruments Corporation)
3 NiViPciK; C:\Windows\System32\drivers\NiViPciKl.sys [11360 2009-06-21] (National Instruments Corporation)
2 NiViPxiK; C:\Windows\System32\drivers\NiViPxiKl.sys [11360 2009-06-21] (National Instruments Corporation)
0 tdrpman258; C:\Windows\System32\DRIVERS\tdrpm258.sys [911680 2010-06-12] (Acronis)
3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [195968 2011-02-03] (Jungo)
3 XilinxFirmwareLoader; C:\Windows\System32\Drivers\xusbdfwu.sys [17280 2011-02-03] (Xilinx, Inc.)
2 XilinxPC4Driver; C:\Windows\System32\drivers\xpc4drvr.sys [16000 2011-02-03] (Xilinx, Inc.)
3 catchme; \??\C:\Users\Pavel\AppData\Local\Temp\catchme.sys
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-01-08 22:53 - 2013-01-08 23:08 - 00026569 ____A C:\Users\Pavel\Desktop\attach.txt
2013-01-08 22:53 - 2013-01-08 23:08 - 00016556 ____A C:\Users\Pavel\Desktop\dds.txt
2013-01-08 22:44 - 2013-01-08 22:44 - 00000546 ____A C:\Windows\PFRO.log
2013-01-08 22:32 - 2013-01-08 22:32 - 00013873 ____A C:\ComboFix.txt
2013-01-08 22:18 - 2013-01-08 23:02 - 00002243 ____A C:\Windows\epplauncher.mif
2013-01-08 21:09 - 2012-12-07 04:26 - 00308736 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-08 21:09 - 2012-12-07 04:20 - 02576384 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-08 21:09 - 2012-12-07 02:46 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-08 21:09 - 2012-12-07 02:46 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-08 21:09 - 2012-11-29 20:53 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-08 21:09 - 2012-11-29 20:47 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-08 21:09 - 2012-11-29 20:47 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 18:55 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-08 21:09 - 2012-11-29 18:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 18:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 18:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 18:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-08 21:09 - 2012-11-29 15:17 - 00420064 ____A C:\Windows\System32\locale.nls
2013-01-08 21:09 - 2012-11-22 18:56 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-08 21:09 - 2012-11-21 20:45 - 00626688 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-08 21:09 - 2012-11-08 20:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-08 21:09 - 2012-10-31 20:47 - 01389568 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-08 21:08 - 2012-11-22 18:48 - 00049152 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2013-01-08 21:08 - 2012-11-19 20:51 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-01-08 21:00 - 2013-01-08 22:08 - 00000112 ____A C:\Windows\setupact.log
2013-01-08 21:00 - 2013-01-08 21:00 - 00000000 ____A C:\Windows\setuperr.log
2013-01-08 13:48 - 2013-01-08 23:03 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\IObit
2013-01-08 13:48 - 2013-01-08 13:48 - 00001230 ____A C:\Users\Public\Desktop\Uninstaller.lnk
2013-01-08 13:48 - 2013-01-08 13:48 - 00001179 ____A C:\Users\Public\Desktop\Advanced SystemCare 6.lnk
2013-01-08 13:48 - 2013-01-08 13:48 - 00000000 ____D C:\Users\All Users\IObit
2013-01-08 13:48 - 2013-01-08 13:48 - 00000000 ____D C:\Program Files\IObit
2013-01-07 01:14 - 2013-01-07 01:14 - 00003001 ____A C:\Users\Pavel\Desktop\RKreport[6]_D_01072013_02d0114.txt
2013-01-07 01:14 - 2013-01-07 01:14 - 00002973 ____A C:\Users\Pavel\Desktop\RKreport[7]_D_01072013_02d0114.txt
2013-01-07 01:13 - 2013-01-07 01:13 - 00002958 ____A C:\Users\Pavel\Desktop\RKreport[5]_S_01072013_02d0113.txt
2013-01-06 23:52 - 2013-01-06 23:52 - 00000000 ____D C:\Program Files\Intel
2013-01-06 23:52 - 2010-03-02 00:04 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\System32\CSVer.dll
2013-01-06 23:46 - 2013-01-06 23:46 - 00002858 ____A C:\Users\Pavel\Desktop\RKreport[4]_S_01062013_02d2346.txt
2013-01-06 23:46 - 2013-01-06 23:46 - 00002823 ____A C:\Users\Pavel\Desktop\RKreport[3]_D_01062013_02d2346.txt
2013-01-06 23:45 - 2013-01-06 23:45 - 00003643 ____A C:\Users\Pavel\Desktop\RKreport[1]_S_01062013_02d2345.txt
2013-01-06 23:45 - 2013-01-06 23:45 - 00003542 ____A C:\Users\Pavel\Desktop\RKreport[2]_D_01062013_02d2345.txt
2013-01-06 23:33 - 2013-01-07 01:08 - 00000000 ____D C:\zz_drive_clean
2013-01-06 22:50 - 2013-01-06 22:50 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2013-01-06 14:10 - 2013-01-06 16:51 - 00000000 ____D C:\Users\Pavel\Downloads\Lord.of.the.rings-Return.of.the.King.DVDrip[vice]
2013-01-04 22:12 - 2013-01-04 22:13 - 00000000 ____D C:\Users\Pavel\Downloads\Lincoln.2012.DVDSCR.XViD.AC3-FooKaS
2013-01-04 22:00 - 2013-01-04 22:00 - 00000000 ____D C:\Users\Pavel\Downloads\Zero Dark Thirty
2013-01-04 09:39 - 2013-01-04 09:39 - 00000000 ____D C:\Users\Pavel\AppData\Local\McAfee File Lock
2013-01-03 23:50 - 2012-05-28 10:28 - 00147472 ____A (McAfee, Inc.) C:\Windows\System32\Drivers\HipShieldK.sys
2012-12-25 14:27 - 2012-12-25 14:27 - 00000020 __ASH C:\Users\TEMP\ntuser.ini
2012-12-25 14:27 - 2012-08-23 00:58 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\Macromedia
2012-12-25 14:27 - 2012-04-05 21:53 - 00120720 ____A C:\Users\TEMP\AppData\Local\GDIPFONTCACHEV1.DAT
2012-12-25 14:27 - 2012-04-05 21:53 - 00000000 ____D C:\Users\TEMP\Documents\Visual Studio 2010
2012-12-25 14:27 - 2010-06-06 17:04 - 00000000 ____D C:\Users\TEMP\AppData\Local\Microsoft Help
2012-12-22 03:00 - 2012-12-16 06:13 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-22 03:00 - 2012-12-16 06:13 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-14 05:23 - 2012-12-14 05:23 - 00262144 ____A C:\Windows\System32\config\ELAM
2012-12-13 03:07 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-13 03:07 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-13 03:07 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-13 03:07 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-13 03:07 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-13 03:07 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-13 03:07 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-13 03:07 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-13 03:07 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-13 03:07 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-13 03:07 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-13 03:07 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-13 03:07 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-13 03:07 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-13 03:07 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-13 03:07 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-12 06:51 - 2012-11-01 21:11 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-12 06:50 - 2012-11-08 20:42 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
==================== One Month Modified Files and Folders ========
2013-01-08 23:08 - 2013-01-08 22:53 - 00026569 ____A C:\Users\Pavel\Desktop\attach.txt
2013-01-08 23:08 - 2013-01-08 22:53 - 00016556 ____A C:\Users\Pavel\Desktop\dds.txt
2013-01-08 23:03 - 2013-01-08 13:48 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\IObit
2013-01-08 23:02 - 2013-01-08 23:02 - 00000000 ____D C:\466c6e99da8f25e1421e05305b216a
2013-01-08 23:02 - 2013-01-08 22:18 - 00002243 ____A C:\Windows\epplauncher.mif
2013-01-08 22:44 - 2013-01-08 22:44 - 00000546 ____A C:\Windows\PFRO.log
2013-01-08 22:32 - 2013-01-08 22:32 - 00013873 ____A C:\ComboFix.txt
2013-01-08 22:32 - 2012-08-23 19:31 - 00000000 ____D C:\Qoobox
2013-01-08 22:31 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini
2013-01-08 22:11 - 2010-06-06 10:05 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Skype
2013-01-08 22:11 - 2010-06-05 21:15 - 01772539 ____A C:\Windows\WindowsUpdate.log
2013-01-08 22:11 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-08 22:11 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-08 22:11 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-01-08 22:10 - 2011-04-10 22:51 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-08 22:09 - 2009-07-13 20:33 - 00447048 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-08 22:08 - 2013-01-08 21:00 - 00000112 ____A C:\Windows\setupact.log
2013-01-08 22:08 - 2010-06-05 21:40 - 00000000 ____D C:\Users\All Users\NVIDIA
2013-01-08 22:08 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-08 21:54 - 2012-04-13 19:07 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-01-08 21:54 - 2010-06-05 21:17 - 00776562 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-08 21:52 - 2010-06-05 21:45 - 00000000 ____D C:\Users\All Users\Microsoft Help
2013-01-08 21:46 - 2010-06-05 21:25 - 65273848 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-01-08 21:36 - 2011-04-10 22:51 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-08 21:32 - 2012-08-22 19:32 - 00000000 ____D C:\Users\Pavel\Desktop\new_installs
2013-01-08 21:02 - 2011-12-20 05:24 - 00000000 ____D C:\Users\All Users\McAfee
2013-01-08 21:00 - 2013-01-08 21:00 - 00000000 ____A C:\Windows\setuperr.log
2013-01-08 14:14 - 2012-08-29 23:18 - 00000000 ____D C:\FRST
2013-01-08 13:52 - 2010-10-24 08:19 - 00000000 ____D C:\Windows\Minidump
2013-01-08 13:48 - 2013-01-08 13:48 - 00001230 ____A C:\Users\Public\Desktop\Uninstaller.lnk
2013-01-08 13:48 - 2013-01-08 13:48 - 00001179 ____A C:\Users\Public\Desktop\Advanced SystemCare 6.lnk
2013-01-08 13:48 - 2013-01-08 13:48 - 00000000 ____D C:\Users\All Users\IObit
2013-01-08 13:48 - 2013-01-08 13:48 - 00000000 ____D C:\Program Files\IObit
2013-01-07 10:15 - 2012-06-06 21:03 - 00000000 __RSD C:\Users\Pavel\Documents\McAfee Vaults
2013-01-07 01:14 - 2013-01-07 01:14 - 00003001 ____A C:\Users\Pavel\Desktop\RKreport[6]_D_01072013_02d0114.txt
2013-01-07 01:14 - 2013-01-07 01:14 - 00002973 ____A C:\Users\Pavel\Desktop\RKreport[7]_D_01072013_02d0114.txt
2013-01-07 01:13 - 2013-01-07 01:13 - 00002958 ____A C:\Users\Pavel\Desktop\RKreport[5]_S_01072013_02d0113.txt
2013-01-07 01:08 - 2013-01-06 23:33 - 00000000 ____D C:\zz_drive_clean
2013-01-06 23:52 - 2013-01-06 23:52 - 00000000 ____D C:\Program Files\Intel
2013-01-06 23:52 - 2010-09-05 18:19 - 00000000 ____D C:\Program Files\Realtek
2013-01-06 23:52 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\DriverStore
2013-01-06 23:46 - 2013-01-06 23:46 - 00002858 ____A C:\Users\Pavel\Desktop\RKreport[4]_S_01062013_02d2346.txt
2013-01-06 23:46 - 2013-01-06 23:46 - 00002823 ____A C:\Users\Pavel\Desktop\RKreport[3]_D_01062013_02d2346.txt
2013-01-06 23:45 - 2013-01-06 23:45 - 00003643 ____A C:\Users\Pavel\Desktop\RKreport[1]_S_01062013_02d2345.txt
2013-01-06 23:45 - 2013-01-06 23:45 - 00003542 ____A C:\Users\Pavel\Desktop\RKreport[2]_D_01062013_02d2345.txt
2013-01-06 22:50 - 2013-01-06 22:50 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2013-01-06 22:11 - 2012-08-22 19:21 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-01-06 22:11 - 2012-08-22 19:21 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-01-06 16:57 - 2010-06-19 10:33 - 00000000 ____D C:\Users\Pavel\Desktop\pics
2013-01-06 16:53 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\NDF
2013-01-06 16:51 - 2013-01-06 14:10 - 00000000 ____D C:\Users\Pavel\Downloads\Lord.of.the.rings-Return.of.the.King.DVDrip[vice]
2013-01-04 22:13 - 2013-01-04 22:12 - 00000000 ____D C:\Users\Pavel\Downloads\Lincoln.2012.DVDSCR.XViD.AC3-FooKaS
2013-01-04 22:00 - 2013-01-04 22:00 - 00000000 ____D C:\Users\Pavel\Downloads\Zero Dark Thirty
2013-01-04 09:39 - 2013-01-04 09:39 - 00000000 ____D C:\Users\Pavel\AppData\Local\McAfee File Lock
2013-01-01 21:41 - 2010-06-06 16:10 - 00000000 ____D C:\Users\Pavel\Documents\Turbo Lister Backup
2012-12-30 16:52 - 2010-07-17 07:47 - 00000000 ____D C:\Users\Pavel\AppData\Local\CutePDF Writer
2012-12-30 11:19 - 2006-12-26 16:51 - 00000000 ____D C:\PKLife
2012-12-25 14:27 - 2012-12-25 14:27 - 00000020 __ASH C:\Users\TEMP\ntuser.ini
2012-12-21 00:17 - 2012-05-15 20:41 - 00000000 ____D C:\Users\Pavel\Desktop\investment
2012-12-19 22:56 - 2010-06-06 10:04 - 00000000 ____D C:\Users\All Users\Skype
2012-12-16 06:13 - 2012-12-22 03:00 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-16 06:13 - 2012-12-22 03:00 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-14 16:49 - 2012-08-22 19:21 - 00021104 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-12-14 09:29 - 2011-11-10 08:36 - 00000036 ___AH C:\Windows\System32\f9t.dat
2012-12-14 05:23 - 2012-12-14 05:23 - 00262144 ____A C:\Windows\System32\config\ELAM
2012-12-13 14:14 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2012-12-13 01:47 - 2010-08-15 17:42 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\FileZilla
2012-12-12 20:46 - 2009-07-13 20:53 - 00032592 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-12-11 14:54 - 2012-04-13 19:07 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-12-11 14:54 - 2011-08-28 08:40 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-01-08 21:46:29
==================== Memory info ===========================
Percentage of memory in use: 13%
Total physical RAM: 4094.49 MB
Available physical RAM: 3550.84 MB
Total Pagefile: 4092.78 MB
Available Pagefile: 3563.88 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.37 MB
==================== Partitions =============================
2 Drive c: () (Fixed) (Total:596.17 GB) (Free:488.16 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: () (Fixed) (Total:232.88 GB) (Free:120.89 GB) NTFS
4 Drive f: (GSP1RMCULFRER_EN_DVD) (CDROM) (Total:2.39 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:7.45 GB) (Free:4.81 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: () (Fixed) (Total:232.88 GB) (Free:35.41 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 Online 596 GB 0 B
Disk 2 Online 232 GB 1024 KB
Disk 3 Online 7633 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 232 GB 31 KB
=========================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y NTFS Partition 232 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 31 KB
=========================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 596 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 232 GB 31 KB
=========================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 232 GB Healthy
=========================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7633 MB 16 KB
=========================================================
Disk: 3
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7633 MB Healthy
=========================================================
Last Boot: 2013-01-04 00:20
==================== End Of Log ============================