Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu, děkuji

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Prosím o kontrolu, děkuji

#1 Příspěvek od Barycz »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Barycz at 2015-07-06 18:32:53
Microsoft Windows 8.1
System drive C: has 296 GB (78%) free of 382 GB
Total RAM: 8078 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:33:04, on 6. 7. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\baidu\baidu.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Barycz.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeCEPServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Google Update] "C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Barycz\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_08DD334BC7EF08FD0A6DC6A4F779EFF4] "C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\baidu\baidu.exe
O4 - Global Startup: Bluetooth.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: Asus WebStorage Windows Service - ASUS Cloud Corporation - C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @oem23.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Programy\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9965 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
C:\Windows\system32\WLANExt.exe 483256530096
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-06e6a1d3-459f-47fc-ac63-d697ff0281fb -SystemEventPortName:HostProcess-7a9a7913-0010-401b-8119-9fc13e9b7506 -IoCancelEventPortName:HostProcess-fcf4fc70-d3f7-4625-b19d-f6051bc95141 -NonStateChangingEventPortName:HostProcess-f6dd74d3-02dd-4df3-8b4e-4e7b0ef3ea33 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:198cc9ee-e31f-4d41-8820-8ee2cfd6befe -DeviceGroupId:WpdFsGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\Explorer.EXE
igfxEM.exe
igfxHK.exe
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
taskhostex.exe
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
KBFiltr.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 10a88b0f-fc9c-4e1b-ba70-410df34d4691 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe 0x4
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Windows\system32\GWX\GWX.exe"
"D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe"
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2132.0.1900202741\1483823130" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,21,44 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3574 --ignored=" --type=renderer " /prefetch:822062411
szndesktop.exe default start
"C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.2.1918585646\1509563959" /prefetch:673131151
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.3.837656676\766897170" /prefetch:673131151
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.4.885390645\2098899705" /prefetch:673131151
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.5.328995719\165088173" /prefetch:673131151
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\baidu\baidu.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2132.10.1353590375\1712818489" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.13.1862778054\2085968198" /prefetch:673131151
/S

"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.24.859928605\1226911035" /prefetch:673131151
"C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_NonMonotonicity_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_04/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=2132 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="2132.27.420185937\1440980327" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe16_ Global\UsGthrCtrlFltPipeMssGthrPipe16 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
"C:\Users\Barycz\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job - C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu, děkuji

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Re: Prosím o kontrolu, děkuji

#3 Příspěvek od Barycz »

Děkuji, zde je log

# AdwCleaner v4.207 - Log vytvořen 07/07/2015 v 09:10:30
# Aktualizováno 21/06/2015 by Xplode
# Databáze : 2015-07-05.2 [Server]
# Operační system : Windows 8.1 (x64)
# Uživatelské jméno : Barycz - BARY
# Spuštěno z : C:\Users\Barycz\Desktop\adwcleaner_4.207.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\{ea98c939-5692-f2f6-ea98-8c93956924e5}
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\Users\Barycz\AppData\Local\globalUpdate
Složka Smazáno : C:\Users\Barycz\AppData\Roaming\Mozilla\Firefox\Profiles\p7hh0m73.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Soubor Smazáno : C:\Users\Barycz\AppData\Roaming\Mozilla\Firefox\Profiles\p7hh0m73.default\user.js

***** [ Naplánované úlohy ] *****

Úloha Smazáno : amiupdaterExd
Úloha Smazáno : amiupdaterExi

***** [ Zástupci ] *****

Zástupce Vyléčeno : C:\Users\Barycz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Zástupce Vyléčeno : C:\Users\Barycz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk

***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Klíč Smazáno : HKCU\Software\APN PIP
Klíč Smazáno : HKCU\Software\GlobalUpdate
Klíč Smazáno : HKLM\SOFTWARE\searchult
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v38.0.5 (x86 cs)


-\\ Google Chrome v

[C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] : hxxp://www.oursurfing.com/?type=hp&ts=14359181 ... J9EF968083

*************************

AdwCleaner[R0].txt - [2402 bytů] - [07/07/2015 09:06:55]
AdwCleaner[S0].txt - [2213 bytů] - [07/07/2015 09:10:30]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2271 bytů] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu, děkuji

#4 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Re: Prosím o kontrolu, děkuji

#5 Příspěvek od Barycz »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by Barycz (administrator) on BARY on 07-07-2015 09:36:43
Running from C:\Users\Barycz\Desktop
Loaded Profiles: Barycz (Available Profiles: Barycz)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\APRP\aprp.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Disc Soft Ltd) D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe
() C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
() C:\Program Files (x86)\baidu\baidu.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSPanel.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Barycz\Desktop\FRSTLauncher.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-05-23] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [63296 2014-08-20] ()
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039240 2013-05-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-03] (Avast Software s.r.o.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [Google Update] => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-12] (Google Inc.)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [DAEMON Tools Lite] => D:\Programy\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\baidu.exe [61440 2015-06-20] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {0d5a6f9f-f8b1-11e4-825e-5c93a2cc85ff} - "G:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {3b0f2dee-fe49-11e4-8264-5c93a2cc85ff} - "I:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fbbe0-02ae-11e5-8267-5c93a2cc85ff} - "J:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fc065-02ae-11e5-8267-5c93a2cc85ff} - "K:\autorun.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-12-20]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-03] (Avast Software s.r.o.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {14C69B97-2553-4896-8228-AB8912AB62B9} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {661A9F83-EBEC-45E1-B099-2ABC020F4BC3} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {9BEE27FE-2D06-4742-8EAF-404CDAF9638E} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {B73BC120-CA9F-4147-BCC2-059661FE69F8} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {C80E9446-C5FA-4AAD-A294-FFB3FB94A568} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {C97B95DC-7CD4-4F94-A949-F7E2EE501FF5} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {D91E8DA3-DC99-4588-9EA5-2623DDB34F11} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {DA4700A0-49EB-488C-B96E-E5EAF6235FBD} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {FE810CD8-965F-4E2C-BAE5-6EF6877B439E} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{E2B6E6C0-ADE0-4FC6-ABF1-B4B09AEADA44}: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\Barycz\AppData\Roaming\Mozilla\Firefox\Profiles\p7hh0m73.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-06-28] ()
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-28] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-12-18] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-12-18] ()
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\Programy\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> D:\Programy\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3355354101-3930625369-1265342347-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Barycz\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3355354101-3930625369-1265342347-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Barycz\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Extension: eye perform 1.0.1 - C:\Users\Barycz\AppData\Roaming\Mozilla\Firefox\Profiles\p7hh0m73.default\Extensions\{d11195b7-3360-435c-8dba-aca103f9bec5}.xpi [2015-07-04]
StartMenuInternet: FIREFOX.EXE - D:\Programy\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR Profile: C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-12]
CHR Extension: (Google Docs) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-12]
CHR Extension: (Google Drive) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-12]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-05-18]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-05-18]
CHR Extension: (YouTube) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-12]
CHR Extension: (Google Search) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-12]
CHR Extension: (Google Sheets) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-12]
CHR Extension: (AdBlock) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-05-12]
CHR Extension: (Google Wallet) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-16]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-05-18]
CHR Extension: (Gmail) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [71168 2014-08-20] (ASUS Cloud Corporation) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-03] (Avast Software s.r.o.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-23] (NVIDIA Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315376 2014-05-14] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
S2 MBAMService; D:\Programy\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-05-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23006864 2015-05-23] (NVIDIA Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-03] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-03] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-03] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-03] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-03] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-03] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-03] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-03] ()
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69904 2014-03-31] (ASUS Corporation)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-11-14] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7546544 2014-12-20] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30352 2015-05-12] (Disc Soft Ltd)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-24] (Huawei Technologies Co., Ltd.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-28] (Intel Corporation)
R3 mlkumidi; C:\Windows\system32\drivers\mlkumidi.sys [57408 2012-08-29] (MusicLab, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2015-04-03] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-10-21] (Microsoft Corporation)
S3 btwrchid; \SystemRoot\System32\drivers\btwrchid.sys [X]
U0 msahci; system32\drivers\msahci.sys
S3 WinRing0_1_2_0; \??\C:\Users\Barycz\AppData\Local\Temp\Rar$EXa0.038\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-07 09:36 - 2015-07-07 09:37 - 00022157 _____ C:\Users\Barycz\Desktop\FRST.txt
2015-07-07 09:36 - 2015-07-07 09:36 - 00000000 ____D C:\FRST
2015-07-07 09:35 - 2015-07-07 09:35 - 00112640 _____ (forum.viry.cz) C:\Users\Barycz\Desktop\FRSTLauncher.exe
2015-07-07 09:25 - 2015-07-07 09:25 - 02112512 _____ (Farbar) C:\Users\Barycz\Desktop\FRST64.exe
2015-07-07 09:11 - 2015-07-07 09:12 - 00000348 _____ C:\Windows\setupact.log
2015-07-07 09:11 - 2015-07-07 09:11 - 00000346 _____ C:\Windows\PFRO.log
2015-07-07 09:11 - 2015-07-07 09:11 - 00000000 _____ C:\Windows\setuperr.log
2015-07-07 09:06 - 2015-07-07 09:10 - 00000000 ____D C:\AdwCleaner
2015-07-07 09:04 - 2015-07-07 09:04 - 02244096 _____ C:\Users\Barycz\Desktop\adwcleaner_4.207.exe
2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\rsit
2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\Program Files\trend micro
2015-07-06 18:32 - 2015-07-06 18:32 - 01222144 _____ C:\Users\Barycz\Downloads\RSITx64.exe
2015-07-06 10:07 - 2015-07-06 10:07 - 00001080 _____ C:\Users\Barycz\Desktop\firefox.exe – zástupce.lnk
2015-07-06 09:40 - 2015-07-06 09:40 - 00028550 _____ C:\Users\Barycz\Documents\cc_20150706_094020.reg
2015-07-05 09:38 - 2015-07-05 09:59 - 1467600896 _____ C:\Users\Barycz\Downloads\Ovečka Shaun ve filmu Shaun the Sheep Movie (2015).avi
2015-07-05 08:49 - 2015-07-05 09:00 - 764308882 _____ C:\Users\Barycz\Downloads\Zvonilka a tvor Netvor (2014 CZ dab).avi
2015-07-04 19:50 - 2015-07-04 19:50 - 00079920 _____ C:\Users\Barycz\Downloads\Superfast-(0000255734).srt
2015-07-03 12:28 - 2015-07-03 12:28 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\AVAST Software
2015-07-03 12:27 - 2015-07-03 12:27 - 00001940 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-03 12:27 - 2015-07-03 12:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-03 12:26 - 2015-07-03 12:27 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-07-03 12:26 - 2015-07-03 12:26 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-07-03 12:26 - 2015-07-03 12:26 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-07-03 12:25 - 2015-07-03 12:25 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-03 12:25 - 2015-03-03 15:17 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 12:22 - 2015-07-03 12:22 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Barycz\Downloads\avast_free_antivirus_setup_online.exe
2015-07-03 12:22 - 2015-07-03 12:22 - 00000000 ____D C:\ProgramData\AVAST Software
2015-07-03 12:19 - 2015-07-03 12:20 - 00002364 _____ C:\Users\Barycz\Desktop\Google Chrome.lnk
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 ____D C:\Program Files (x86)\baidu
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 _____ C:\Windows\prleth.sys
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 _____ C:\Windows\hgfs.sys
2015-07-03 12:08 - 2015-07-03 12:13 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-07-03 12:00 - 2015-07-03 12:00 - 00632652 _____ C:\Users\Barycz\Downloads\Candy Crush Soda Saga HACK TOO Downloader.zip
2015-07-02 19:43 - 2015-07-03 12:23 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
2015-07-02 17:47 - 2015-07-02 17:48 - 05384466 _____ C:\Users\Barycz\Downloads\(Pentium.N3530.7z
2015-07-02 17:41 - 2015-07-02 17:41 - 00000000 ____D C:\ProgramData\Codemasters
2015-07-02 17:27 - 2015-07-02 17:27 - 00000000 ____D C:\Users\Barycz\AppData\Local\ali213GameLauncher
2015-07-02 15:08 - 2015-07-03 17:23 - 00000000 ___HD C:\Users\Barycz\AppData\Roaming\Origin
2015-07-01 20:26 - 2015-07-01 20:26 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\OpenOffice
2015-07-01 20:17 - 2015-07-01 20:17 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
2015-07-01 20:17 - 2015-07-01 20:17 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2015-07-01 20:16 - 2015-07-01 20:17 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2015-07-01 20:12 - 2015-07-01 20:13 - 128741109 _____ C:\Users\Barycz\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_cs.exe
2015-06-30 21:10 - 2015-06-30 21:10 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2015-06-30 16:16 - 2015-06-30 16:25 - 00000000 ___RD C:\Users\Barycz\Dropbox
2015-06-30 16:12 - 2015-06-30 16:12 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Dropbox
2015-06-30 16:08 - 2015-07-02 17:32 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-06-30 16:08 - 2015-06-30 17:12 - 00000000 ____D C:\Users\Barycz\AppData\Local\Dropbox
2015-06-30 16:08 - 2015-06-30 16:08 - 00660960 _____ (Dropbox, Inc.) C:\Users\Barycz\Downloads\DropboxInstaller.exe
2015-06-30 16:08 - 2015-06-30 16:08 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-29 19:51 - 2015-06-29 19:51 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Sony Creative Software Inc
2015-06-29 15:59 - 2015-06-29 15:59 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Publish Providers
2015-06-29 14:13 - 2015-06-29 15:58 - 00000000 ____D C:\Users\Barycz\AppData\Local\Sony
2015-06-29 14:13 - 2015-06-29 14:14 - 00006078 _____ C:\Windows\system32\--traceoff
2015-06-29 14:13 - 2015-06-29 14:13 - 00001056 _____ C:\Users\Public\Desktop\Vegas Pro 13.0 (64-bit).lnk
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\ProgramData\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\Program Files\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\Program Files (x86)\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 _____ C:\Windows\system32\--debugoff
2015-06-29 14:12 - 2015-06-29 18:57 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Sony
2015-06-29 07:55 - 2015-06-29 07:55 - 00000878 _____ C:\Users\Barycz\Desktop\Obrázky – zástupce.lnk
2015-06-28 11:57 - 2015-06-28 11:57 - 00000000 ____D C:\Users\Barycz\AppData\Local\Macromedia
2015-06-28 11:45 - 2015-06-28 11:45 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Mozilla
2015-06-28 11:45 - 2015-06-28 11:45 - 00000000 ____D C:\Users\Barycz\AppData\Local\Mozilla
2015-06-28 11:44 - 2015-06-28 11:44 - 40140168 _____ C:\Users\Barycz\Downloads\Firefox Setup 38.0.5.exe
2015-06-28 11:30 - 2015-06-28 11:30 - 00000000 ____D C:\Users\Barycz\Documents\My Cheat Tables
2015-06-28 11:30 - 2015-06-28 11:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2015-06-28 09:38 - 2015-07-02 19:13 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-06-26 07:59 - 2015-06-26 08:00 - 05091011 _____ C:\Users\Barycz\Downloads\79899.rar
2015-06-26 07:50 - 2015-06-26 07:50 - 00000000 ____D C:\Windows\system32\Plug-In Settings
2015-06-25 12:22 - 2015-06-25 12:22 - 22644048 _____ C:\Users\Barycz\Downloads\HuginSetup_2014.0.0_64bit_Windows.exe
2015-06-25 12:07 - 2015-06-25 12:07 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\GardenGnomeSoftware
2015-06-25 12:06 - 2015-06-25 12:06 - 24039376 _____ (Garden Gnome Software) C:\Users\Barycz\Downloads\pano2vr_install64_4_5_3.exe
2015-06-23 23:55 - 2015-07-07 09:16 - 00000000 ____D C:\Users\Barycz\AppData\Local\CrashDumps
2015-06-23 13:26 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 22947144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 17724600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 15866992 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 15224784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 13263056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 12855416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 11831856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-06-23 13:26 - 2015-06-17 11:10 - 02997544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 02599752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00975176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-06-23 13:25 - 2015-07-07 09:37 - 01358804 _____ C:\Windows\WindowsUpdate.log
2015-06-23 13:24 - 2015-06-23 13:24 - 00081264 _____ C:\Users\Barycz\Documents\cc_20150623_132425.reg
2015-06-23 12:32 - 2015-07-06 09:40 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\FileZilla
2015-06-23 12:32 - 2015-06-23 12:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-06-23 12:31 - 2015-06-23 12:31 - 06477032 _____ (Tim Kosse) C:\Users\Barycz\Downloads\FileZilla_3.11.0.2_win64-setup.exe
2015-06-22 22:50 - 2015-07-06 07:54 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth
2015-06-22 22:28 - 2014-03-19 01:43 - 00229080 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-06-22 22:28 - 2014-03-19 01:43 - 00190168 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-06-22 22:28 - 2012-07-27 04:18 - 00040248 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-06-22 22:26 - 2015-06-22 22:26 - 00000000 ____D C:\ProgramData\Realtek
2015-06-17 17:43 - 2015-06-24 22:45 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-17 17:43 - 2015-06-17 17:43 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-17 17:43 - 2015-06-17 17:43 - 00002069 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-16 22:15 - 2015-06-16 22:15 - 00037685 _____ C:\Users\Barycz\Downloads\Game-of-Thrones-S05E10(0000256028).srt
2015-06-15 19:31 - 2015-07-04 10:00 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Foxit Software
2015-06-14 00:57 - 2015-06-14 00:57 - 00045794 _____ C:\Users\Barycz\Downloads\Justified-S02E06(0000172949).srt
2015-06-13 22:37 - 2015-06-13 22:37 - 00052412 _____ C:\Users\Barycz\Downloads\Justified-S02E05(0000172653).srt
2015-06-12 01:12 - 2015-06-12 01:12 - 00051498 _____ C:\Users\Barycz\Downloads\Justified-S02E04(0000172233).srt
2015-06-11 19:47 - 2015-06-11 19:51 - 477898484 _____ C:\Users\Barycz\Downloads\AOKILPHORIZONSRMXPARTS.zip
2015-06-10 23:25 - 2015-06-10 23:25 - 00050514 _____ C:\Users\Barycz\Downloads\Justified-S02E03(0000171821).srt
2015-06-10 16:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 16:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 16:27 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 16:27 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 16:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 16:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 16:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 16:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 16:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 16:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 16:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 16:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 16:27 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-10 16:27 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-10 16:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 16:27 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 16:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 16:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 16:27 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-10 16:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 16:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 16:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 16:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 16:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 16:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 16:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 16:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 16:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 16:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 16:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 16:27 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-10 16:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 16:27 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-10 16:27 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-10 16:27 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 16:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 16:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 16:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 16:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 16:27 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-10 16:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 16:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 16:27 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 16:27 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 16:27 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2015-06-10 16:27 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2015-06-10 16:27 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rgb9rast.dll
2015-06-10 16:27 - 2015-04-09 00:07 - 00410336 _____ C:\Windows\system32\ApnDatabase.xml
2015-06-10 16:27 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-06-10 16:27 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-06-10 16:27 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-06-10 16:27 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-06-10 16:27 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-06-10 16:27 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-10 16:27 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2015-06-10 16:27 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2015-06-10 16:26 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-09 23:13 - 2015-06-09 23:13 - 00034740 _____ C:\Users\Barycz\Downloads\Game-of-Thrones-S05E09(0000255766).srt
2015-06-09 20:29 - 2015-06-09 20:29 - 57182144 _____ C:\Users\Barycz\Downloads\TO RISE REMIXPACK (1).zip
2015-06-09 00:51 - 2015-06-09 00:51 - 00052496 _____ C:\Users\Barycz\Downloads\Justified-S02E02(0000171135).srt
2015-06-08 19:54 - 2015-06-08 19:54 - 00053302 _____ C:\Users\Barycz\Downloads\Justified-S02E01(0000170681).srt
2015-06-07 23:31 - 2015-06-07 23:31 - 00044945 _____ C:\Users\Barycz\Downloads\Justified-S01E13(0000156767).srt
2015-06-07 16:49 - 2015-06-07 16:51 - 150631643 _____ C:\Users\Barycz\Downloads\valhalla_all_in_rmx.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-07 09:21 - 2015-05-17 23:59 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Seznam.cz
2015-07-07 09:21 - 2015-05-12 16:21 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3355354101-3930625369-1265342347-1001
2015-07-07 09:18 - 2014-10-21 13:24 - 00739924 _____ C:\Windows\system32\perfh005.dat
2015-07-07 09:18 - 2014-10-21 13:24 - 00151610 _____ C:\Windows\system32\perfc005.dat
2015-07-07 09:18 - 2014-03-18 17:26 - 01745984 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-07 09:16 - 2015-05-12 16:18 - 00000093 _____ C:\Users\Barycz\AppData\Roaming\sp_data.sys
2015-07-07 09:11 - 2015-05-28 18:00 - 00001292 _____ C:\Windows\mlkumidi.log
2015-07-07 09:11 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-07 09:02 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-07-07 08:41 - 2015-05-12 16:30 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job
2015-07-07 08:41 - 2015-05-12 16:30 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job
2015-07-07 07:11 - 2015-05-18 00:27 - 00000000 ____D C:\Users\Barycz\AppData\Local\Adobe
2015-07-06 09:43 - 2015-06-06 09:31 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-06 09:40 - 2015-05-12 19:23 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\DAEMON Tools Lite
2015-07-06 09:39 - 2015-05-29 09:40 - 00000000 ____D C:\Windows\Minidump
2015-07-06 07:51 - 2015-05-12 16:15 - 00000000 ____D C:\Users\Barycz
2015-07-06 07:22 - 2014-12-20 14:32 - 00000000 ____D C:\ProgramData\McAfee
2015-07-06 07:22 - 2013-08-22 15:25 - 00000226 _____ C:\Windows\win.ini
2015-07-05 16:41 - 2015-05-13 16:50 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\vlc
2015-07-05 12:52 - 2015-05-18 00:22 - 00000000 ____D C:\Users\Barycz\AppData\Local\26423
2015-07-04 19:42 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2015-07-03 12:24 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-07-03 12:24 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2015-07-03 12:10 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-07-02 17:32 - 2013-08-22 16:44 - 05057848 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-02 17:25 - 2015-05-12 21:35 - 00000000 ____D C:\Users\Barycz\Documents\My Games
2015-06-30 21:10 - 2015-05-12 16:15 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Adobe
2015-06-28 11:38 - 2015-05-17 09:12 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Skype
2015-06-25 15:48 - 2015-05-17 17:00 - 00000000 __SHD C:\Users\Barycz\AppData\Local\EmieBrowserModeList
2015-06-25 15:48 - 2015-05-12 16:28 - 00000000 __SHD C:\Users\Barycz\AppData\Local\EmieUserList
2015-06-25 15:48 - 2015-05-12 16:28 - 00000000 __SHD C:\Users\Barycz\AppData\Local\EmieSiteList
2015-06-24 20:56 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-23 23:37 - 2015-05-30 23:53 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Might & Magic Heroes VI
2015-06-23 13:29 - 2014-12-20 14:13 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-23 13:29 - 2014-12-20 14:12 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-06-23 13:26 - 2015-06-01 13:28 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-20 05:02 - 2015-05-17 15:40 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-20 05:02 - 2015-05-17 15:40 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-18 13:48 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\tracing
2015-06-17 17:45 - 2015-05-18 00:27 - 00000000 ____D C:\ProgramData\Adobe
2015-06-17 17:43 - 2015-05-18 10:27 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-17 11:10 - 2015-06-01 13:46 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-06-17 11:10 - 2014-12-20 14:12 - 03395648 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-06-17 11:10 - 2014-12-20 14:12 - 00030966 _____ C:\Windows\system32\nvinfo.pb
2015-06-17 08:48 - 2014-12-20 14:13 - 06873232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 03492168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 01059472 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-06-17 08:48 - 2014-12-20 14:13 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 00074896 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-06-14 04:21 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2015-06-13 17:27 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2015-06-13 17:27 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 16:49 - 2015-05-16 01:41 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 16:41 - 2015-05-16 01:40 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2015-05-12 16:18 - 2015-07-07 09:16 - 0000093 _____ () C:\Users\Barycz\AppData\Roaming\sp_data.sys
2014-12-20 14:16 - 2014-12-20 14:16 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-10-21 06:28 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2014-10-21 06:28 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2014-10-21 06:28 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS


Some files in TEMP:
====================
C:\Users\Barycz\AppData\Local\Temp\bedfjbebca.exe
C:\Users\Barycz\AppData\Local\Temp\bedfjbebeb.exe
C:\Users\Barycz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpmiwekh.dll
C:\Users\Barycz\AppData\Local\Temp\Foxit PhantomPDF Updater.exe
C:\Users\Barycz\AppData\Local\Temp\IQIYIsetup_l_spl004@kb005.exe
C:\Users\Barycz\AppData\Local\Temp\McCSPInstall.dll
C:\Users\Barycz\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Barycz\AppData\Local\Temp\mytmpinstaller.exe
C:\Users\Barycz\AppData\Local\Temp\Quarantine.exe
C:\Users\Barycz\AppData\Local\Temp\setup3.exe
C:\Users\Barycz\AppData\Local\Temp\sevensetup.exe
C:\Users\Barycz\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Barycz\Desktop" je 4 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by Barycz (administrator) on BARY on 07-07-2015 09:40:17
Running from C:\Users\Barycz\Desktop
Loaded Profiles: Barycz (Available Profiles: Barycz)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\APRP\aprp.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Disc Soft Ltd) D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe
() C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
() C:\Program Files (x86)\baidu\baidu.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSPanel.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Barycz\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Barycz\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-05-23] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [63296 2014-08-20] ()
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039240 2013-05-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-03] (Avast Software s.r.o.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [Google Update] => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-12] (Google Inc.)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [DAEMON Tools Lite] => D:\Programy\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\baidu.exe [61440 2015-06-20] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {0d5a6f9f-f8b1-11e4-825e-5c93a2cc85ff} - "G:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {3b0f2dee-fe49-11e4-8264-5c93a2cc85ff} - "I:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fbbe0-02ae-11e5-8267-5c93a2cc85ff} - "J:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fc065-02ae-11e5-8267-5c93a2cc85ff} - "K:\autorun.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-12-20]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-03] (Avast Software s.r.o.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {14C69B97-2553-4896-8228-AB8912AB62B9} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {661A9F83-EBEC-45E1-B099-2ABC020F4BC3} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {9BEE27FE-2D06-4742-8EAF-404CDAF9638E} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {B73BC120-CA9F-4147-BCC2-059661FE69F8} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {C80E9446-C5FA-4AAD-A294-FFB3FB94A568} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {C97B95DC-7CD4-4F94-A949-F7E2EE501FF5} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {D91E8DA3-DC99-4588-9EA5-2623DDB34F11} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {DA4700A0-49EB-488C-B96E-E5EAF6235FBD} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKU\S-1-5-21-3355354101-3930625369-1265342347-1001 -> {FE810CD8-965F-4E2C-BAE5-6EF6877B439E} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{E2B6E6C0-ADE0-4FC6-ABF1-B4B09AEADA44}: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\Barycz\AppData\Roaming\Mozilla\Firefox\Profiles\p7hh0m73.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-06-28] ()
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-28] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-12-18] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-12-18] ()
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\Programy\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> D:\Programy\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3355354101-3930625369-1265342347-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Barycz\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3355354101-3930625369-1265342347-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Barycz\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Extension: eye perform 1.0.1 - C:\Users\Barycz\AppData\Roaming\Mozilla\Firefox\Profiles\p7hh0m73.default\Extensions\{d11195b7-3360-435c-8dba-aca103f9bec5}.xpi [2015-07-04]
StartMenuInternet: FIREFOX.EXE - D:\Programy\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR Profile: C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-12]
CHR Extension: (Google Docs) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-12]
CHR Extension: (Google Drive) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-12]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-05-18]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-05-18]
CHR Extension: (YouTube) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-12]
CHR Extension: (Google Search) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-12]
CHR Extension: (Google Sheets) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-12]
CHR Extension: (AdBlock) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-05-12]
CHR Extension: (Google Wallet) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-16]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-05-18]
CHR Extension: (Gmail) - C:\Users\Barycz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [71168 2014-08-20] (ASUS Cloud Corporation) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-03] (Avast Software s.r.o.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-23] (NVIDIA Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315376 2014-05-14] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
S2 MBAMService; D:\Programy\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-05-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23006864 2015-05-23] (NVIDIA Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-03] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-03] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-03] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-03] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-03] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-03] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-03] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-03] ()
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69904 2014-03-31] (ASUS Corporation)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-11-14] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7546544 2014-12-20] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30352 2015-05-12] (Disc Soft Ltd)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-24] (Huawei Technologies Co., Ltd.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-28] (Intel Corporation)
R3 mlkumidi; C:\Windows\system32\drivers\mlkumidi.sys [57408 2012-08-29] (MusicLab, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2015-04-03] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-10-21] (Microsoft Corporation)
S3 btwrchid; \SystemRoot\System32\drivers\btwrchid.sys [X]
U0 msahci; system32\drivers\msahci.sys
S3 WinRing0_1_2_0; \??\C:\Users\Barycz\AppData\Local\Temp\Rar$EXa0.038\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-07 09:39 - 2015-07-07 09:39 - 00052644 _____ C:\Users\Barycz\Desktop\FRST3.txt
2015-07-07 09:36 - 2015-07-07 09:40 - 00022051 _____ C:\Users\Barycz\Desktop\FRST.txt
2015-07-07 09:36 - 2015-07-07 09:40 - 00000000 ____D C:\FRST
2015-07-07 09:35 - 2015-07-07 09:35 - 00112640 _____ (forum.viry.cz) C:\Users\Barycz\Desktop\FRSTLauncher.exe
2015-07-07 09:25 - 2015-07-07 09:25 - 02112512 _____ (Farbar) C:\Users\Barycz\Desktop\FRST64.exe
2015-07-07 09:11 - 2015-07-07 09:12 - 00000348 _____ C:\Windows\setupact.log
2015-07-07 09:11 - 2015-07-07 09:11 - 00000346 _____ C:\Windows\PFRO.log
2015-07-07 09:11 - 2015-07-07 09:11 - 00000000 _____ C:\Windows\setuperr.log
2015-07-07 09:06 - 2015-07-07 09:10 - 00000000 ____D C:\AdwCleaner
2015-07-07 09:04 - 2015-07-07 09:04 - 02244096 _____ C:\Users\Barycz\Desktop\adwcleaner_4.207.exe
2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\rsit
2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\Program Files\trend micro
2015-07-06 18:32 - 2015-07-06 18:32 - 01222144 _____ C:\Users\Barycz\Downloads\RSITx64.exe
2015-07-06 10:07 - 2015-07-06 10:07 - 00001080 _____ C:\Users\Barycz\Desktop\firefox.exe – zástupce.lnk
2015-07-06 09:40 - 2015-07-06 09:40 - 00028550 _____ C:\Users\Barycz\Documents\cc_20150706_094020.reg
2015-07-05 09:38 - 2015-07-05 09:59 - 1467600896 _____ C:\Users\Barycz\Downloads\Ovečka Shaun ve filmu Shaun the Sheep Movie (2015).avi
2015-07-05 08:49 - 2015-07-05 09:00 - 764308882 _____ C:\Users\Barycz\Downloads\Zvonilka a tvor Netvor (2014 CZ dab).avi
2015-07-04 19:50 - 2015-07-04 19:50 - 00079920 _____ C:\Users\Barycz\Downloads\Superfast-(0000255734).srt
2015-07-03 12:28 - 2015-07-03 12:28 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\AVAST Software
2015-07-03 12:27 - 2015-07-03 12:27 - 00001940 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-03 12:27 - 2015-07-03 12:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-03 12:26 - 2015-07-03 12:27 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-07-03 12:26 - 2015-07-03 12:26 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-07-03 12:26 - 2015-07-03 12:26 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-07-03 12:26 - 2015-07-03 12:26 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-07-03 12:25 - 2015-07-03 12:25 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-03 12:25 - 2015-03-03 15:17 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 12:22 - 2015-07-03 12:22 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Barycz\Downloads\avast_free_antivirus_setup_online.exe
2015-07-03 12:22 - 2015-07-03 12:22 - 00000000 ____D C:\ProgramData\AVAST Software
2015-07-03 12:19 - 2015-07-03 12:20 - 00002364 _____ C:\Users\Barycz\Desktop\Google Chrome.lnk
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 ____D C:\Program Files (x86)\baidu
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 _____ C:\Windows\prleth.sys
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 _____ C:\Windows\hgfs.sys
2015-07-03 12:08 - 2015-07-03 12:13 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-07-03 12:00 - 2015-07-03 12:00 - 00632652 _____ C:\Users\Barycz\Downloads\Candy Crush Soda Saga HACK TOO Downloader.zip
2015-07-02 19:43 - 2015-07-03 12:23 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
2015-07-02 17:47 - 2015-07-02 17:48 - 05384466 _____ C:\Users\Barycz\Downloads\(Pentium.N3530.7z
2015-07-02 17:41 - 2015-07-02 17:41 - 00000000 ____D C:\ProgramData\Codemasters
2015-07-02 17:27 - 2015-07-02 17:27 - 00000000 ____D C:\Users\Barycz\AppData\Local\ali213GameLauncher
2015-07-02 15:08 - 2015-07-03 17:23 - 00000000 ___HD C:\Users\Barycz\AppData\Roaming\Origin
2015-07-01 20:26 - 2015-07-01 20:26 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\OpenOffice
2015-07-01 20:17 - 2015-07-01 20:17 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
2015-07-01 20:17 - 2015-07-01 20:17 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2015-07-01 20:16 - 2015-07-01 20:17 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2015-07-01 20:12 - 2015-07-01 20:13 - 128741109 _____ C:\Users\Barycz\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_cs.exe
2015-06-30 21:10 - 2015-06-30 21:10 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2015-06-30 16:16 - 2015-06-30 16:25 - 00000000 ___RD C:\Users\Barycz\Dropbox
2015-06-30 16:12 - 2015-06-30 16:12 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Dropbox
2015-06-30 16:08 - 2015-07-02 17:32 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-06-30 16:08 - 2015-06-30 17:12 - 00000000 ____D C:\Users\Barycz\AppData\Local\Dropbox
2015-06-30 16:08 - 2015-06-30 16:08 - 00660960 _____ (Dropbox, Inc.) C:\Users\Barycz\Downloads\DropboxInstaller.exe
2015-06-30 16:08 - 2015-06-30 16:08 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-29 19:51 - 2015-06-29 19:51 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Sony Creative Software Inc
2015-06-29 15:59 - 2015-06-29 15:59 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Publish Providers
2015-06-29 14:13 - 2015-06-29 15:58 - 00000000 ____D C:\Users\Barycz\AppData\Local\Sony
2015-06-29 14:13 - 2015-06-29 14:14 - 00006078 _____ C:\Windows\system32\--traceoff
2015-06-29 14:13 - 2015-06-29 14:13 - 00001056 _____ C:\Users\Public\Desktop\Vegas Pro 13.0 (64-bit).lnk
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\ProgramData\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\Program Files\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 ____D C:\Program Files (x86)\Sony
2015-06-29 14:13 - 2015-06-29 14:13 - 00000000 _____ C:\Windows\system32\--debugoff
2015-06-29 14:12 - 2015-06-29 18:57 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Sony
2015-06-29 07:55 - 2015-06-29 07:55 - 00000878 _____ C:\Users\Barycz\Desktop\Obrázky – zástupce.lnk
2015-06-28 11:57 - 2015-06-28 11:57 - 00000000 ____D C:\Users\Barycz\AppData\Local\Macromedia
2015-06-28 11:45 - 2015-06-28 11:45 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Mozilla
2015-06-28 11:45 - 2015-06-28 11:45 - 00000000 ____D C:\Users\Barycz\AppData\Local\Mozilla
2015-06-28 11:44 - 2015-06-28 11:44 - 40140168 _____ C:\Users\Barycz\Downloads\Firefox Setup 38.0.5.exe
2015-06-28 11:30 - 2015-06-28 11:30 - 00000000 ____D C:\Users\Barycz\Documents\My Cheat Tables
2015-06-28 11:30 - 2015-06-28 11:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2015-06-28 09:38 - 2015-07-02 19:13 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-06-26 07:59 - 2015-06-26 08:00 - 05091011 _____ C:\Users\Barycz\Downloads\79899.rar
2015-06-26 07:50 - 2015-06-26 07:50 - 00000000 ____D C:\Windows\system32\Plug-In Settings
2015-06-25 12:22 - 2015-06-25 12:22 - 22644048 _____ C:\Users\Barycz\Downloads\HuginSetup_2014.0.0_64bit_Windows.exe
2015-06-25 12:07 - 2015-06-25 12:07 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\GardenGnomeSoftware
2015-06-25 12:06 - 2015-06-25 12:06 - 24039376 _____ (Garden Gnome Software) C:\Users\Barycz\Downloads\pano2vr_install64_4_5_3.exe
2015-06-23 23:55 - 2015-07-07 09:16 - 00000000 ____D C:\Users\Barycz\AppData\Local\CrashDumps
2015-06-23 13:26 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 22947144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 17724600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 15866992 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 15224784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 13263056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 12855416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 11831856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-06-23 13:26 - 2015-06-17 11:10 - 02997544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 02599752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00975176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-06-23 13:26 - 2015-06-17 11:10 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-06-23 13:25 - 2015-07-07 09:37 - 01358804 _____ C:\Windows\WindowsUpdate.log
2015-06-23 13:24 - 2015-06-23 13:24 - 00081264 _____ C:\Users\Barycz\Documents\cc_20150623_132425.reg
2015-06-23 12:32 - 2015-07-06 09:40 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\FileZilla
2015-06-23 12:32 - 2015-06-23 12:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-06-23 12:31 - 2015-06-23 12:31 - 06477032 _____ (Tim Kosse) C:\Users\Barycz\Downloads\FileZilla_3.11.0.2_win64-setup.exe
2015-06-22 22:50 - 2015-07-06 07:54 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth
2015-06-22 22:28 - 2014-03-19 01:43 - 00229080 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-06-22 22:28 - 2014-03-19 01:43 - 00190168 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-06-22 22:28 - 2012-07-27 04:18 - 00040248 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-06-22 22:26 - 2015-06-22 22:26 - 00000000 ____D C:\ProgramData\Realtek
2015-06-17 17:43 - 2015-06-24 22:45 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-17 17:43 - 2015-06-17 17:43 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-17 17:43 - 2015-06-17 17:43 - 00002069 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-16 22:15 - 2015-06-16 22:15 - 00037685 _____ C:\Users\Barycz\Downloads\Game-of-Thrones-S05E10(0000256028).srt
2015-06-15 19:31 - 2015-07-04 10:00 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Foxit Software
2015-06-14 00:57 - 2015-06-14 00:57 - 00045794 _____ C:\Users\Barycz\Downloads\Justified-S02E06(0000172949).srt
2015-06-13 22:37 - 2015-06-13 22:37 - 00052412 _____ C:\Users\Barycz\Downloads\Justified-S02E05(0000172653).srt
2015-06-12 01:12 - 2015-06-12 01:12 - 00051498 _____ C:\Users\Barycz\Downloads\Justified-S02E04(0000172233).srt
2015-06-11 19:47 - 2015-06-11 19:51 - 477898484 _____ C:\Users\Barycz\Downloads\AOKILPHORIZONSRMXPARTS.zip
2015-06-10 23:25 - 2015-06-10 23:25 - 00050514 _____ C:\Users\Barycz\Downloads\Justified-S02E03(0000171821).srt
2015-06-10 16:27 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 16:27 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 16:27 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 16:27 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 16:27 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 16:27 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 16:27 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 16:27 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 16:27 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 16:27 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 16:27 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 16:27 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 16:27 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-10 16:27 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-10 16:27 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 16:27 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 16:27 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 16:27 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 16:27 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-10 16:27 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 16:27 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 16:27 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 16:27 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 16:27 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 16:27 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 16:27 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 16:27 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 16:27 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 16:27 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 16:27 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 16:27 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-10 16:27 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 16:27 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-10 16:27 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-10 16:27 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 16:27 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 16:27 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 16:27 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 16:27 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 16:27 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-10 16:27 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 16:27 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 16:27 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 16:27 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 16:27 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2015-06-10 16:27 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2015-06-10 16:27 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rgb9rast.dll
2015-06-10 16:27 - 2015-04-09 00:07 - 00410336 _____ C:\Windows\system32\ApnDatabase.xml
2015-06-10 16:27 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-06-10 16:27 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-06-10 16:27 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-06-10 16:27 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-06-10 16:27 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-06-10 16:27 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-10 16:27 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2015-06-10 16:27 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2015-06-10 16:26 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-09 23:13 - 2015-06-09 23:13 - 00034740 _____ C:\Users\Barycz\Downloads\Game-of-Thrones-S05E09(0000255766).srt
2015-06-09 20:29 - 2015-06-09 20:29 - 57182144 _____ C:\Users\Barycz\Downloads\TO RISE REMIXPACK (1).zip
2015-06-09 00:51 - 2015-06-09 00:51 - 00052496 _____ C:\Users\Barycz\Downloads\Justified-S02E02(0000171135).srt
2015-06-08 19:54 - 2015-06-08 19:54 - 00053302 _____ C:\Users\Barycz\Downloads\Justified-S02E01(0000170681).srt
2015-06-07 23:31 - 2015-06-07 23:31 - 00044945 _____ C:\Users\Barycz\Downloads\Justified-S01E13(0000156767).srt
2015-06-07 16:49 - 2015-06-07 16:51 - 150631643 _____ C:\Users\Barycz\Downloads\valhalla_all_in_rmx.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-07 09:41 - 2015-05-12 16:30 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job
2015-07-07 09:21 - 2015-05-17 23:59 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Seznam.cz
2015-07-07 09:21 - 2015-05-12 16:21 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3355354101-3930625369-1265342347-1001
2015-07-07 09:18 - 2014-10-21 13:24 - 00739924 _____ C:\Windows\system32\perfh005.dat
2015-07-07 09:18 - 2014-10-21 13:24 - 00151610 _____ C:\Windows\system32\perfc005.dat
2015-07-07 09:18 - 2014-03-18 17:26 - 01745984 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-07 09:16 - 2015-05-12 16:18 - 00000093 _____ C:\Users\Barycz\AppData\Roaming\sp_data.sys
2015-07-07 09:11 - 2015-05-28 18:00 - 00001292 _____ C:\Windows\mlkumidi.log
2015-07-07 09:11 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-07 09:02 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-07-07 08:41 - 2015-05-12 16:30 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job
2015-07-07 07:11 - 2015-05-18 00:27 - 00000000 ____D C:\Users\Barycz\AppData\Local\Adobe
2015-07-06 09:43 - 2015-06-06 09:31 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-06 09:40 - 2015-05-12 19:23 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\DAEMON Tools Lite
2015-07-06 09:39 - 2015-05-29 09:40 - 00000000 ____D C:\Windows\Minidump
2015-07-06 07:51 - 2015-05-12 16:15 - 00000000 ____D C:\Users\Barycz
2015-07-06 07:22 - 2014-12-20 14:32 - 00000000 ____D C:\ProgramData\McAfee
2015-07-06 07:22 - 2013-08-22 15:25 - 00000226 _____ C:\Windows\win.ini
2015-07-05 16:41 - 2015-05-13 16:50 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\vlc
2015-07-05 12:52 - 2015-05-18 00:22 - 00000000 ____D C:\Users\Barycz\AppData\Local\26423
2015-07-04 19:42 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2015-07-03 12:24 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-07-03 12:24 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2015-07-03 12:10 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-07-02 17:32 - 2013-08-22 16:44 - 05057848 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-02 17:25 - 2015-05-12 21:35 - 00000000 ____D C:\Users\Barycz\Documents\My Games
2015-06-30 21:10 - 2015-05-12 16:15 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Adobe
2015-06-28 11:38 - 2015-05-17 09:12 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Skype
2015-06-25 15:48 - 2015-05-17 17:00 - 00000000 __SHD C:\Users\Barycz\AppData\Local\EmieBrowserModeList
2015-06-25 15:48 - 2015-05-12 16:28 - 00000000 __SHD C:\Users\Barycz\AppData\Local\EmieUserList
2015-06-25 15:48 - 2015-05-12 16:28 - 00000000 __SHD C:\Users\Barycz\AppData\Local\EmieSiteList
2015-06-24 20:56 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-23 23:37 - 2015-05-30 23:53 - 00000000 ____D C:\Users\Barycz\AppData\Roaming\Might & Magic Heroes VI
2015-06-23 13:29 - 2014-12-20 14:13 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-23 13:29 - 2014-12-20 14:12 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-06-23 13:26 - 2015-06-01 13:28 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-20 05:02 - 2015-05-17 15:40 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-20 05:02 - 2015-05-17 15:40 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-18 13:48 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\tracing
2015-06-17 17:45 - 2015-05-18 00:27 - 00000000 ____D C:\ProgramData\Adobe
2015-06-17 17:43 - 2015-05-18 10:27 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-17 11:10 - 2015-06-01 13:46 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-06-17 11:10 - 2014-12-20 14:12 - 03395648 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-06-17 11:10 - 2014-12-20 14:12 - 00030966 _____ C:\Windows\system32\nvinfo.pb
2015-06-17 08:48 - 2014-12-20 14:13 - 06873232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 03492168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 01059472 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-06-17 08:48 - 2014-12-20 14:13 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 00074896 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2015-06-17 08:48 - 2014-12-20 14:13 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-06-14 04:21 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2015-06-13 17:27 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2015-06-13 17:27 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 16:49 - 2015-05-16 01:41 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 16:41 - 2015-05-16 01:40 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Re: Prosím o kontrolu, děkuji

#6 Příspěvek od Barycz »

==================== Files in the root of some directories =======

2015-05-12 16:18 - 2015-07-07 09:16 - 0000093 _____ () C:\Users\Barycz\AppData\Roaming\sp_data.sys
2014-12-20 14:16 - 2014-12-20 14:16 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-10-21 06:28 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2014-10-21 06:28 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2014-10-21 06:28 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS


Some files in TEMP:
====================
C:\Users\Barycz\AppData\Local\Temp\bedfjbebca.exe
C:\Users\Barycz\AppData\Local\Temp\bedfjbebeb.exe
C:\Users\Barycz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpmiwekh.dll
C:\Users\Barycz\AppData\Local\Temp\Foxit PhantomPDF Updater.exe
C:\Users\Barycz\AppData\Local\Temp\IQIYIsetup_l_spl004@kb005.exe
C:\Users\Barycz\AppData\Local\Temp\McCSPInstall.dll
C:\Users\Barycz\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Barycz\AppData\Local\Temp\mytmpinstaller.exe
C:\Users\Barycz\AppData\Local\Temp\Quarantine.exe
C:\Users\Barycz\AppData\Local\Temp\setup3.exe
C:\Users\Barycz\AppData\Local\Temp\sevensetup.exe
C:\Users\Barycz\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Barycz\Desktop" je 4 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu, děkuji

#7 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039240 2013-05-16] (Adobe Systems Incorporated)
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKLM\...\Policies\Explorer: [NoFolderOptions] 0
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [Google Update] => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-12] (Google Inc.)
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [DAEMON Tools Lite] => D:\Programy\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd)
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [AdobeBridge] => [X]
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\baidu.exe [61440 2015-06-20] ()
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoFolderOptions] 0
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {0d5a6f9f-f8b1-11e4-825e-5c93a2cc85ff} - "G:\setup.exe"
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {3b0f2dee-fe49-11e4-8264-5c93a2cc85ff} - "I:\setup.exe"
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fbbe0-02ae-11e5-8267-5c93a2cc85ff} - "J:\setup.exe"
    HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fc065-02ae-11e5-8267-5c93a2cc85ff} - "K:\autorun.exe" 
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    
    FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
    
    U0 msahci; system32\drivers\msahci.sys
    S3 WinRing0_1_2_0; \??\C:\Users\Barycz\AppData\Local\Temp\Rar$EXa0.038\WinRing0x64.sys [X]
    
    C:\Program Files (x86)\baidu
    2015-07-07 09:36 - 2015-07-07 09:37 - 00022157 _____ C:\Users\Barycz\Desktop\FRST.txt
    2015-07-07 09:35 - 2015-07-07 09:35 - 00112640 _____ (forum.viry.cz) C:\Users\Barycz\Desktop\FRSTLauncher.exe
    2015-07-07 09:11 - 2015-07-07 09:12 - 00000348 _____ C:\Windows\setupact.log
    2015-07-07 09:11 - 2015-07-07 09:11 - 00000346 _____ C:\Windows\PFRO.log
    2015-07-07 09:11 - 2015-07-07 09:11 - 00000000 _____ C:\Windows\setuperr.log
    2015-07-07 09:06 - 2015-07-07 09:10 - 00000000 ____D C:\AdwCleaner
    2015-07-07 09:04 - 2015-07-07 09:04 - 02244096 _____ C:\Users\Barycz\Desktop\adwcleaner_4.207.exe
    2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\rsit
    2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\Program Files\trend micro
    2015-07-06 18:32 - 2015-07-06 18:32 - 01222144 _____ C:\Users\Barycz\Downloads\RSITx64.exe
    2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 ____D C:\Program Files (x86)\baidu
    2015-07-03 12:22 - 2015-07-03 12:22 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Barycz\Downloads\avast_free_antivirus_setup_online.exe
    2014-10-21 06:28 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
    2014-10-21 06:28 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
    2014-10-21 06:28 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
    
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Re: Prosím o kontrolu, děkuji

#8 Příspěvek od Barycz »

Fix result of Farbar Recovery Scan Tool (x64) Version:05-07-2015
Ran by Barycz at 2015-07-07 20:01:50 Run:1
Running from C:\Users\Barycz\Desktop
Loaded Profiles: Barycz (Available Profiles: Barycz)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039240 2013-05-16] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [Google Update] => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-12] (Google Inc.)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [DAEMON Tools Lite] => D:\Programy\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Barycz\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\baidu.exe [61440 2015-06-20] ()
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {0d5a6f9f-f8b1-11e4-825e-5c93a2cc85ff} - "G:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {3b0f2dee-fe49-11e4-8264-5c93a2cc85ff} - "I:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fbbe0-02ae-11e5-8267-5c93a2cc85ff} - "J:\setup.exe"
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\...\MountPoints2: {893fc065-02ae-11e5-8267-5c93a2cc85ff} - "K:\autorun.exe"
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()

U0 msahci; system32\drivers\msahci.sys
S3 WinRing0_1_2_0; \??\C:\Users\Barycz\AppData\Local\Temp\Rar$EXa0.038\WinRing0x64.sys [X]

C:\Program Files (x86)\baidu
2015-07-07 09:36 - 2015-07-07 09:37 - 00022157 _____ C:\Users\Barycz\Desktop\FRST.txt
2015-07-07 09:35 - 2015-07-07 09:35 - 00112640 _____ (forum.viry.cz) C:\Users\Barycz\Desktop\FRSTLauncher.exe
2015-07-07 09:11 - 2015-07-07 09:12 - 00000348 _____ C:\Windows\setupact.log
2015-07-07 09:11 - 2015-07-07 09:11 - 00000346 _____ C:\Windows\PFRO.log
2015-07-07 09:11 - 2015-07-07 09:11 - 00000000 _____ C:\Windows\setuperr.log
2015-07-07 09:06 - 2015-07-07 09:10 - 00000000 ____D C:\AdwCleaner
2015-07-07 09:04 - 2015-07-07 09:04 - 02244096 _____ C:\Users\Barycz\Desktop\adwcleaner_4.207.exe
2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\rsit
2015-07-06 18:32 - 2015-07-06 18:33 - 00000000 ____D C:\Program Files\trend micro
2015-07-06 18:32 - 2015-07-06 18:32 - 01222144 _____ C:\Users\Barycz\Downloads\RSITx64.exe
2015-07-03 12:09 - 2015-07-03 12:09 - 00000000 ____D C:\Program Files (x86)\baidu
2015-07-03 12:22 - 2015-07-03 12:22 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Barycz\Downloads\avast_free_antivirus_setup_online.exe
2014-10-21 06:28 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2014-10-21 06:28 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2014-10-21 06:28 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS

Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job => C:\Users\Barycz\AppData\Local\Google\Update\GoogleUpdate.exe

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS6ServiceManager => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCEPServiceManager => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Run\\apphide => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
"HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d5a6f9f-f8b1-11e4-825e-5c93a2cc85ff}" => key removed successfully
HKCR\CLSID\{0d5a6f9f-f8b1-11e4-825e-5c93a2cc85ff} => key not found.
"HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3b0f2dee-fe49-11e4-8264-5c93a2cc85ff}" => key removed successfully
HKCR\CLSID\{3b0f2dee-fe49-11e4-8264-5c93a2cc85ff} => key not found.
"HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{893fbbe0-02ae-11e5-8267-5c93a2cc85ff}" => key removed successfully
HKCR\CLSID\{893fbbe0-02ae-11e5-8267-5c93a2cc85ff} => key not found.
"HKU\S-1-5-21-3355354101-3930625369-1265342347-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{893fc065-02ae-11e5-8267-5c93a2cc85ff}" => key removed successfully
HKCR\CLSID\{893fc065-02ae-11e5-8267-5c93a2cc85ff} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0" => key removed successfully
C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll => moved successfully.
msahci => Service removed successfully
WinRing0_1_2_0 => Service removed successfully
C:\Program Files (x86)\baidu => moved successfully.
C:\Users\Barycz\Desktop\FRST.txt => moved successfully.
C:\Users\Barycz\Desktop\FRSTLauncher.exe => moved successfully.
C:\Windows\setupact.log => moved successfully.
C:\Windows\PFRO.log => moved successfully.
C:\Windows\setuperr.log => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\Barycz\Desktop\adwcleaner_4.207.exe => moved successfully.
C:\rsit => moved successfully.
C:\Program Files\trend micro => moved successfully.
C:\Users\Barycz\Downloads\RSITx64.exe => moved successfully.
"C:\Program Files (x86)\baidu" => File/Folder not found.
C:\Users\Barycz\Downloads\avast_free_antivirus_setup_online.exe => moved successfully.
C:\ProgramData\SetStretch.cmd => moved successfully.
C:\ProgramData\SetStretch.exe => moved successfully.
C:\ProgramData\SetStretch.VBS => moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001Core.job => moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3355354101-3930625369-1265342347-1001UA.job => moved successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 724.5 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 20:02:55 ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu, děkuji

#9 Příspěvek od vyosek »

Jak se chova PC?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Re: Prosím o kontrolu, děkuji

#10 Příspěvek od Barycz »

PC frčí dobře, jen prohlížeč poslední 2 dny tak 5 sekund přemýšlí, pak až se rozmyslí a spustí stránku co jsem mu zadal.

Možná ho zkusím přeinstalovat.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu, děkuji

#11 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remove disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Barycz
Návštěvník
Návštěvník
Příspěvky: 39
Registrován: 05 led 2015 16:23

Re: Prosím o kontrolu, děkuji

#12 Příspěvek od Barycz »

Jsme to zase té havěti nandali :x Děkuji :thumbsup:
Hezký den.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu, děkuji

#13 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy :)


A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno