Prosim o kontrolu logu
Napsal: 24 kvě 2016 16:50
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-05-2016
Ran by gabi (administrator) on GABI-PC (24-05-2016 11:39:10)
Running from C:\Users\gabi\Desktop
Loaded Profiles: gabi (Available Profiles: gabi)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Google Inc.) C:\Users\gabi\AppData\Local\Google\Update\GoogleUpdate.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\HPNetworkCommunicatorCom.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files (x86)\IObit\iFreeUp\iFreeUpMini.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848 2015-07-08] (ESET)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-05-02] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5889824 2015-07-28] (IObit)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [Google Update] => C:\Users\gabi\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [HP ENVY 5530 series (NET)] => C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-4097007782-1966444928-4019047729-1000] => :0
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A95C1F79-C963-44D3-88A2-B0540AD12411}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{FC0D0F0F-DAEC-4297-9451-C8B98AD770E1}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1ewenusDefaultPack/SKY2_FRPage
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope {62E1E48F-ED7E-4ECE-9E44-7D6F4223C188} URL =
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> buffer URL =
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> firmy.cz-020302 URL = hxxp://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> mapy.cz-020302 URL = hxxp://www.mapy.cz/?sourceid=quicksearch_6826& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> seznam.cz-020302 URL = hxxp://searchou.com/?q={searchTerms}&id=838fbb60000000000000f46d04641d3c&r=664
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> seznam.cz-091952 URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> videa.seznam.cz-181817 URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> zbozi.cz-020302 URL = hxxp://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> {180780f0-b348-4b44-8210-94a8f3ee15b2} URL = hxxp://search.comcast.net/search/?cat=Web&con=toolbar&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = hxxp://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10140_cnet_150509&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-04-21] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-21] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
Toolbar: HKU\.DEFAULT -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Toolbar: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-04-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default
FF NewTab: hxxps://www.facebook.com/
FF DefaultSearchEngine: Google Default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Bing
FF SelectedSearchEngine,S:
FF Homepage: hxxps://www.facebook.com/
FF Session Restore: -> is enabled.
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.http", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.http_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.no_proxies_on", "localhost, 127.0.0.1");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.share_proxy_settings", false);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.socks", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.socks_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.ssl", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.ssl_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.type", 5);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.http", "127.0.0.1");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.http_port", 8888);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.no_proxies_on", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.share_proxy_settings", false);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.socks", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.socks_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.ssl", "127.0.0.1");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.ssl_port", 8888);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.type", 1);
FF Keyword.URL: hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-21] ()
FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-06-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-06-18] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-21] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-06-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2015-06-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-04-25] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-05-19] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-05-19] (NVIDIA Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2014-11-05] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-06-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4097007782-1966444928-4019047729-1000: @tools.google.com/Google Update;version=3 -> C:\Users\gabi\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-4097007782-1966444928-4019047729-1000: @tools.google.com/Google Update;version=9 -> C:\Users\gabi\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF user.js: detected! => C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\user.js [2015-11-29]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\amazoncom-pro.xml [2015-05-09]
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\facebook.xml [2015-12-10]
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\google-default.xml [2015-05-09]
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\youtube.xml [2015-05-09]
FF Extension: Empty Cache Button - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\extensions\{4cc4a13b-94a6-7568-370d-5f9de54a9c7f} [2016-04-28]
FF Extension: Search By Image (by Google) - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi [2016-04-28]
FF Extension: Greasemonkey - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-04-30]
FF Extension: saveensharie - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\8fa6m-h@iiyiyeeiyi.com [2013-09-13] [not signed]
FF Extension: Bing Search Engine - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\bingsearch.full@microsoft.com [2015-04-02] [not signed]
FF Extension: MyWordTool - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\emily@wilford.biz [2013-11-24] [not signed]
FF Extension: HTML5 Video Everywhere! - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\html5-video-everywhere@lejenome.me.xpi [2016-01-06]
FF Extension: User Agent RG (FFox update) - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\useragentrg-upd@mozilla.org.xpi [2016-04-27]
FF Extension: Charles Autoconfiguration - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\{3e9a3920-1b27-11da-8cd6-0800200c9a66}.xpi [2015-03-22] [not signed]
FF Extension: YouTube Flash Video Player - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2016-05-03]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-04-29]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Firefox\Extensions: [{4340308e-3e37-4dd7-9192-8cf05ce9c9f2}] - C:\Program Files (x86)\LyriXeeker\130.xpi => not found
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-06-20] <==== ATTENTION
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC ... earchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR Profile: C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Disk Google) - C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-24]
CHR HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\gabi\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-04]
CHR HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cgdebfobecnopjndjbdoapgokdjfffpj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [hahpjplbmicfkmoccokbjejahjjpnena] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lfffjahnfbocnaooecgijfnbpcfekoik] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-04-29]
CHR HKLM-x32\...\Chrome\Extension: [oddhjgogndegicgabhgibhfoompkifcn] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - <no Path/update_url>
StartMenuInternet: Google Chrome - C:\Users\gabi\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
S3 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [922240 2011-06-13] ()
S3 ASDiskUnlocker; C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [258688 2010-12-02] (ASUSTeK Computer Inc.)
S3 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2010-12-01] ()
S3 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2010-10-21] ()
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-04-29] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-04-29] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files (x86)\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720 2015-07-08] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-05-02] (NVIDIA Corporation)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [882464 2015-07-17] (IObit)
R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3020440 2015-11-25] (Intel(R) Corporation)
S3 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-05-02] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-05-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-05-02] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-19] (Electronic Arts)
S3 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [487960 2014-12-16] (Sony Corporation)
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [878904 2016-05-16] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15736 2016-05-16] (McAfee, Inc.)
S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2016-05-16] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 AiChargerPlus; C:\Windows\System32\DRIVERS\AiChargerPlus.sys [14464 2010-11-08] (ASUSTek Computer Inc.)
S3 ASFLTDrv.sys; C:\Program Files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [16512 2010-09-16] (ASUSTeK Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-08-18] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [251632 2015-07-14] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [231520 2015-07-14] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [53360 2015-07-14] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [72400 2015-07-14] (ESET)
R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [39504 2013-04-11] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-23] (GFI Software)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-05-16] (REALiX(tm))
S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-05-24] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-05-02] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [242688 2015-07-05] (QUALCOMM Incorporated)
R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
S3 TuneUpUtilitiesDrv; no ImagePath
R3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
S1 VDiskBus; C:\Windows\System32\DRIVERS\VDiskBus64.sys [43136 2010-09-21] (ASUSTeK Computer Inc.)
S3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN60.sys [29472 2010-01-14] (Windows (R) Codename Longhorn DDK provider)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
S3 ZTEusbMB; C:\Windows\System32\DRIVERS\ZTEusbnmeaext2.sys [123520 2010-12-29] (ZTE Incorporated)
S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [235008 2011-04-09] (ZTE Incorporated)
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 cpuz137; \??\C:\Users\gabi\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-24 11:39 - 2016-05-24 11:39 - 00031048 _____ C:\Users\gabi\Desktop\FRST.txt
2016-05-24 11:39 - 2016-05-24 11:39 - 00000000 ____D C:\FRST
2016-05-24 11:37 - 2016-05-24 11:37 - 02383360 _____ (Farbar) C:\Users\gabi\Desktop\FRST64.exe
2016-05-24 10:43 - 2016-05-24 10:43 - 00000263 _____ C:\Users\gabi\Desktop\ORGONIT, chemtrails a obrana před ovlivňováním lidí EZOpress.URL
2016-05-23 16:39 - 2016-05-23 16:40 - 292445609 _____ C:\Users\gabi\Downloads\MLUVENÉ SLOVO - Simenon, Georges_ Přístav v mlze (DETEKTIVKA).mp4
2016-05-23 14:17 - 2016-05-23 14:17 - 00001188 _____ C:\Users\gabi\Documents\cc_20160523_141706.reg
2016-05-23 12:34 - 2016-05-19 21:45 - 00113208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-05-23 12:32 - 2016-05-21 17:10 - 01581624 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll
2016-05-23 12:32 - 2016-05-21 17:10 - 00141256 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-05-23 12:32 - 2016-05-21 17:10 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 39979576 _____ C:\Windows\system32\nvcompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 35117112 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 31600696 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 25372096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 21794064 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 21336720 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 19110968 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 18138232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 17732936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 17236560 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 13412408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-05-23 12:32 - 2016-05-20 03:01 - 10642728 _____ C:\Windows\system32\nvptxJitCompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 08733096 _____ C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 03447232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 03001792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436822.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 01573432 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436822.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00984512 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00911416 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00770496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00708032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00669952 _____ C:\Windows\system32\nvfatbinaryLoader.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00565392 _____ C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00476848 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00394912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00177952 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00155768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00153232 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00131584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00000594 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-05-23 12:32 - 2016-05-20 03:01 - 00000594 _____ C:\Windows\system32\nv-vk64.json
2016-05-23 11:07 - 2016-05-23 11:07 - 00000209 _____ C:\Users\gabi\Desktop\WeTransfer.URL
2016-05-23 08:46 - 2016-05-23 08:46 - 00444656 _____ (ASMedia Technology Inc) C:\Windows\system32\Drivers\asmtxhci.sys
2016-05-23 08:44 - 2016-05-23 08:44 - 00003130 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2016-05-23 08:44 - 2016-05-23 08:44 - 00003128 _____ C:\Windows\System32\Tasks\SmartDefrag_Update
2016-05-23 08:44 - 2016-05-23 08:44 - 00000000 ____D C:\Windows\IObit
2016-05-23 08:44 - 2016-05-23 08:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2016-05-23 02:24 - 2016-05-23 02:24 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-05-23 02:24 - 2016-05-23 02:24 - 00001151 _____ C:\ProgramData\Desktop\Mozilla Firefox.lnk
2016-05-23 00:31 - 2016-05-24 02:01 - 00000000 ____D C:\Users\gabi\Downloads\Mluvene knihy
2016-05-22 23:43 - 2016-05-22 23:43 - 00001654 _____ C:\Users\gabi\Documents\cc_20160522_234339.reg
2016-05-21 19:34 - 2016-05-24 11:18 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-21 19:34 - 2016-05-23 09:18 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-05-21 19:34 - 2016-05-23 09:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-21 19:34 - 2016-05-23 09:18 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-05-20 09:35 - 2016-05-20 09:35 - 00000251 _____ C:\Users\gabi\Desktop\(103) II.Kat Rum Meyhanesi.URL
2016-05-17 09:40 - 2016-05-17 09:40 - 00000224 _____ C:\Users\gabi\Desktop\Beer Can Bacon Burger recipes by the BBQ Pit Boys - YouTube.URL
2016-05-15 16:45 - 2016-05-15 16:45 - 00000228 _____ C:\Users\gabi\Desktop\MicroTouch Switchblade™ - 2 in 1 Trimmer Lets You Groom Everywhere, Head to Toe!.URL
2016-05-15 12:28 - 2016-05-15 12:28 - 00000292 _____ C:\Users\gabi\Desktop\Dutch Glow® Cleaning Tonic Powerful, nontoxic, all natural kitchen cleaner!.URL
2016-05-13 12:21 - 2016-05-10 00:07 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436519.dll
2016-05-13 12:21 - 2016-05-10 00:07 - 01573432 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436519.dll
2016-05-13 12:18 - 2016-04-14 01:38 - 00113216 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-05-13 12:18 - 2016-04-14 01:38 - 00102976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-05-13 12:18 - 2016-04-14 01:38 - 00056384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-05-13 10:28 - 2016-05-13 15:08 - 711588193 _____ C:\Users\gabi\Downloads\Linka.c.657.720p.BluRay.x264.CZ.dabing.mkv
2016-05-13 07:32 - 2016-05-13 08:16 - 791111680 _____ C:\Users\gabi\Downloads\Poldove-a-zlodeji.avi
2016-05-08 16:34 - 2016-05-08 17:26 - 933451776 _____ C:\Users\gabi\Downloads\Navrat-blbyho-a-blbejsiho-Komedie-2014-CZ-adriatic.avi
2016-05-08 00:56 - 2016-05-08 00:56 - 00011802 _____ C:\Users\gabi\Documents\Filip 10.txt
2016-05-07 11:34 - 2016-05-08 01:18 - 1712567876 _____ C:\Users\gabi\Downloads\Terminator.Genisys.2015.BluRay.1080p.TrueHD.7.1.Atmos.x264-EPiC.mkv
2016-05-06 21:49 - 2016-05-06 22:30 - 728084652 _____ C:\Users\gabi\Downloads\Vo-štvorici-po-opici-2-Komedie-2011-CZ-adriatic.avi
2016-05-06 12:03 - 2016-05-06 12:44 - 738929644 _____ C:\Users\gabi\Downloads\Viktor-Frankenstein---2015-CZ-dabing.avi
2016-05-05 17:35 - 2016-05-05 18:52 - 1378323908 _____ C:\Users\gabi\Downloads\S-láskou,-Rosie-(komedie,romantic.-2014)cz---IRISA.avi
2016-05-05 15:25 - 2016-05-05 16:31 - 1182362666 _____ C:\Users\gabi\Downloads\Pád-Země-(2015)-Xvid-⍟ℋ.avi
2016-05-03 22:23 - 2016-05-03 22:23 - 00129824 _____ C:\Windows\SysWOW64\vulkan-1-1-0-11-1.dll
2016-05-03 22:22 - 2016-05-03 22:22 - 00130848 _____ C:\Windows\system32\vulkan-1-1-0-11-1.dll
2016-05-03 22:22 - 2016-05-03 22:22 - 00045344 _____ C:\Windows\system32\vulkaninfo-1-1-0-11-1.exe
2016-05-03 22:22 - 2016-05-03 22:22 - 00040224 _____ C:\Windows\SysWOW64\vulkaninfo-1-1-0-11-1.exe
2016-05-02 21:25 - 2016-05-02 22:40 - 1299148676 _____ C:\Users\gabi\Downloads\Každý-milion-dobrý-Xvid-⍟ℋ.avi
2016-05-02 02:34 - 2016-05-02 02:34 - 00000308 _____ C:\Users\gabi\Desktop\Pokud někde uvidíte tohoto brouka, okamžitě běžte pryč. To, co s vámi totiž udělá, je děsivé!.URL
2016-05-02 00:35 - 2016-05-02 02:13 - 1762451456 _____ C:\Users\gabi\Downloads\Padesatka.2015.XviD.CZ.avi
2016-05-01 18:38 - 2016-05-01 20:20 - 1789501440 _____ C:\Users\gabi\Downloads\Superhypochondr-2014-Cz-dab..avi
2016-04-30 22:11 - 2016-04-30 23:04 - 762460160 _____ C:\Users\gabi\Downloads\Lucy-DVDRip_2014_CZ_Dab.avi
2016-04-30 15:00 - 2016-04-30 15:43 - 786511872 _____ C:\Users\gabi\Downloads\Mercy-(2014)-CZ-dabing.avi
2016-04-30 12:41 - 2016-04-30 13:31 - 891371520 _____ C:\Users\gabi\Downloads\Moje-segra-ma-prima-brachu-DVDRip_2014_CZ_Dabing.avi
2016-04-28 02:24 - 2016-04-28 02:24 - 00000742 _____ C:\Users\gabi\Documents\Kvasek.txt
2016-04-27 20:52 - 2016-04-27 21:41 - 734988288 _____ C:\Users\gabi\Downloads\The-Gambler-DVDRip_2015_Cz-Dabing.avi
2016-04-24 09:00 - 2016-04-24 10:59 - 00000000 ____D C:\Users\gabi\Downloads\Nová složka
2016-04-24 00:08 - 2016-04-24 00:08 - 00000842 _____ C:\Users\gabi\Documents\cc_20160424_000823.reg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-24 11:36 - 2015-05-16 15:46 - 00002870 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (gabi)
2016-05-24 11:34 - 2015-06-18 16:31 - 00000000 ____D C:\Users\gabi\Desktop\Cisteni a optimalizace
2016-05-24 11:33 - 2015-06-02 19:51 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-24 11:33 - 2015-05-16 15:44 - 00000000 ____D C:\ProgramData\ProductData
2016-05-24 11:33 - 2014-06-17 14:34 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf8a5ab905131a.job
2016-05-24 11:33 - 2012-03-11 22:47 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-24 11:33 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-24 11:32 - 2009-07-14 00:45 - 00017296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-24 11:32 - 2009-07-14 00:45 - 00017296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-24 10:33 - 2013-07-22 09:06 - 00000386 _____ C:\Windows\Tasks\update-S-1-5-21-4097007782-1966444928-4019047729-1000.job
2016-05-24 02:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2016-05-23 20:29 - 2013-01-29 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-05-23 14:21 - 2012-03-14 00:55 - 13005042 _____ C:\Windows\system32\perfh005.dat
2016-05-23 14:21 - 2012-03-14 00:55 - 04364684 _____ C:\Windows\system32\perfc005.dat
2016-05-23 14:21 - 2009-07-14 01:13 - 09048678 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-23 12:34 - 2016-03-10 14:31 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-05-23 12:34 - 2014-02-05 23:38 - 00000000 ____D C:\temp
2016-05-23 12:34 - 2013-01-06 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-05-23 12:34 - 2012-03-11 22:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-05-23 11:12 - 2016-04-13 15:41 - 00000000 ____D C:\Program Files\TrueKey
2016-05-23 11:12 - 2015-05-16 14:00 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d09002253e2ab2.job
2016-05-23 11:12 - 2015-02-04 09:25 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1d0407e5afc26.job
2016-05-23 11:12 - 2015-02-03 17:53 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d03ffbcb6285ca.job
2016-05-23 11:12 - 2014-06-17 14:34 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf8a5ab91b5a8e.job
2016-05-23 11:12 - 2014-06-17 09:49 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1cf8a33639a01d.job
2016-05-23 11:12 - 2014-06-17 09:49 - 00000852 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000Core1cf8a3361aa5f9.job
2016-05-23 11:12 - 2012-12-22 12:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-05-23 08:44 - 2015-11-29 12:45 - 00003238 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler
2016-05-23 08:44 - 2015-11-29 12:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3
2016-05-23 08:44 - 2015-05-16 15:43 - 00000000 ____D C:\Users\gabi\AppData\Roaming\IObit
2016-05-23 08:44 - 2015-05-16 15:43 - 00000000 ____D C:\Program Files (x86)\IObit
2016-05-23 02:24 - 2013-04-11 14:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-05-23 02:24 - 2012-12-22 12:37 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-05-23 00:33 - 2016-04-19 12:09 - 00000000 ____D C:\Users\gabi\Downloads\Knihy
2016-05-22 23:44 - 2015-05-16 15:44 - 00002900 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_gabi
2016-05-22 23:43 - 2014-04-13 00:50 - 00000000 ____D C:\Users\gabi\AppData\Local\CrashDumps
2016-05-22 01:47 - 2016-01-06 10:41 - 00000000 ____D C:\Users\gabi\Desktop\Babske rady
2016-05-21 21:33 - 2016-04-13 15:50 - 00001150 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk
2016-05-21 19:45 - 2015-05-16 14:00 - 00003906 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d09002253e2ab2
2016-05-21 19:45 - 2015-02-04 09:25 - 00003884 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1d0407e5afc26
2016-05-21 19:45 - 2015-02-03 17:53 - 00003906 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d03ffbcb6285ca
2016-05-21 19:45 - 2014-06-17 14:34 - 00003906 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf8a5ab91b5a8e
2016-05-21 19:45 - 2014-06-17 09:49 - 00003884 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1cf8a33639a01d
2016-05-21 19:45 - 2014-06-17 09:49 - 00003488 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000Core1cf8a3361aa5f9
2016-05-21 19:44 - 2016-04-13 15:50 - 00003330 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare)
2016-05-21 19:34 - 2014-09-02 18:00 - 00000000 ____D C:\Users\gabi\AppData\Local\Adobe
2016-05-21 14:39 - 2015-09-06 21:09 - 00000000 ____D C:\Users\gabi\Desktop\Vareni
2016-05-20 23:54 - 2015-08-22 14:15 - 00000000 ____D C:\Users\gabi\Desktop\Ruzne
2016-05-20 03:01 - 2016-03-01 14:12 - 16693208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-05-20 03:01 - 2015-12-01 12:21 - 00039124 _____ C:\Windows\system32\nvinfo.pb
2016-05-20 03:01 - 2013-02-26 00:32 - 14293592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2016-05-20 03:01 - 2013-02-26 00:32 - 03383448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2016-05-20 03:01 - 2012-03-11 22:46 - 03825384 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2016-05-19 22:11 - 2015-12-21 12:51 - 00531904 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2016-05-19 22:11 - 2015-12-21 12:51 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2016-05-19 22:11 - 2013-01-06 13:08 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 06346688 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 02454976 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 01352760 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2016-05-19 22:11 - 2012-03-11 22:47 - 00393784 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2016-05-19 21:33 - 2016-04-13 15:41 - 00000000 ____D C:\ProgramData\McAfee
2016-05-18 21:25 - 2014-03-22 10:17 - 00000000 ___RD C:\Users\gabi\Desktop\FOTKY
2016-05-18 19:25 - 2012-03-11 22:47 - 06448223 _____ C:\Windows\system32\nvcoproc.bin
2016-05-17 23:25 - 2016-03-03 12:56 - 00000000 ____D C:\Users\gabi\Downloads\Aplikace a programy
2016-05-16 22:59 - 2013-11-09 00:32 - 00000000 ____D C:\Users\gabi\Desktop\Stranky
2016-05-13 12:22 - 2012-03-11 22:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-05-13 12:18 - 2013-12-06 08:04 - 00000000 ____D C:\Users\gabi\AppData\Local\NVIDIA
2016-05-12 18:46 - 2012-03-14 14:16 - 00002370 _____ C:\Users\gabi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-10 18:05 - 2014-06-17 14:34 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cf8a5ab905131a
2016-05-09 20:50 - 2015-10-11 22:43 - 00000000 ____D C:\Users\gabi\Desktop\Nove do simsu
2016-05-08 14:17 - 2013-02-22 11:01 - 00000000 ____D C:\Program Files (x86)\Recepty doma
2016-05-08 00:57 - 2016-02-12 18:52 - 00000659 _____ C:\Users\gabi\Documents\Kody na kafe.txt
2016-05-07 12:34 - 2016-03-03 12:55 - 00000000 ____D C:\Users\gabi\Downloads\Filmy
2016-05-06 23:58 - 2015-07-27 01:51 - 00000000 ____D C:\Users\gabi\Desktop\Rucni prace a navody
2016-05-06 00:59 - 2014-11-22 19:06 - 00000000 ____D C:\Users\gabi\Desktop\Ryby
2016-05-05 16:24 - 2012-04-03 15:28 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-05-04 15:02 - 2015-04-25 06:54 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-05-04 15:02 - 2015-04-25 06:52 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-05-04 00:45 - 2015-06-20 12:32 - 00000000 ____D C:\Users\gabi\Desktop\Obchody
2016-05-03 22:23 - 2016-03-10 14:31 - 00129824 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-05-03 22:22 - 2016-03-10 14:31 - 00130848 _____ C:\Windows\system32\vulkan-1.dll
2016-05-03 22:22 - 2016-03-10 14:31 - 00045344 _____ C:\Windows\system32\vulkaninfo.exe
2016-05-03 22:22 - 2016-03-10 14:31 - 00040224 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-05-02 12:14 - 2014-11-08 16:52 - 00000000 ____D C:\Users\gabi\Desktop\Moje vánoční kuchařka
2016-05-02 01:39 - 2015-09-23 09:09 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-05-02 01:39 - 2013-12-06 08:04 - 01377800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-05-02 01:38 - 2015-11-27 11:53 - 00112032 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-05-02 01:38 - 2015-09-23 09:09 - 01756608 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-05-02 01:38 - 2013-12-06 08:04 - 01767944 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
==================== Files in the root of some directories =======
2013-08-26 12:19 - 2013-09-17 01:19 - 0000114 _____ () C:\Users\gabi\AppData\Roaming\WB.CFG
2013-08-26 12:19 - 2013-09-17 01:19 - 0000005 _____ () C:\Users\gabi\AppData\Roaming\WBPU-TTL.DAT
2015-04-07 05:49 - 2015-04-07 05:49 - 0000064 _____ () C:\Users\gabi\AppData\Local\29ac5b7c7af3f31b11ecb2fdbcc37a98
2013-10-12 12:48 - 2013-11-23 15:46 - 0003584 _____ () C:\Users\gabi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-03-09 12:29 - 2013-03-09 12:29 - 0002661 _____ () C:\Users\gabi\AppData\Local\recently-used.xbel
2013-05-10 18:04 - 2013-05-16 01:35 - 0007611 _____ () C:\Users\gabi\AppData\Local\Resmon.ResmonCfg
2013-04-07 18:17 - 2013-04-07 18:17 - 0000003 _____ () C:\Users\gabi\AppData\Local\updater.log
2013-04-07 18:17 - 2015-10-02 02:47 - 0000424 _____ () C:\Users\gabi\AppData\Local\UserProducts.xml
2014-12-24 19:54 - 2014-12-24 19:54 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-05-16 15:50 - 2015-05-16 15:50 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2013-07-02 18:57] - [2015-06-02 19:08] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79
C:\Windows\SysWOW64\User32.dll
[2013-07-02 18:57] - [2015-06-02 19:08] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-05-18 03:58
==================== End of FRST.txt ============================
Ran by gabi (administrator) on GABI-PC (24-05-2016 11:39:10)
Running from C:\Users\gabi\Desktop
Loaded Profiles: gabi (Available Profiles: gabi)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Google Inc.) C:\Users\gabi\AppData\Local\Google\Update\GoogleUpdate.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\HPNetworkCommunicatorCom.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files (x86)\IObit\iFreeUp\iFreeUpMini.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848 2015-07-08] (ESET)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-05-02] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5889824 2015-07-28] (IObit)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [Google Update] => C:\Users\gabi\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [HP ENVY 5530 series (NET)] => C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-4097007782-1966444928-4019047729-1000] => :0
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A95C1F79-C963-44D3-88A2-B0540AD12411}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{FC0D0F0F-DAEC-4297-9451-C8B98AD770E1}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1ewenusDefaultPack/SKY2_FRPage
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope {62E1E48F-ED7E-4ECE-9E44-7D6F4223C188} URL =
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> buffer URL =
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> firmy.cz-020302 URL = hxxp://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> mapy.cz-020302 URL = hxxp://www.mapy.cz/?sourceid=quicksearch_6826& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> seznam.cz-020302 URL = hxxp://searchou.com/?q={searchTerms}&id=838fbb60000000000000f46d04641d3c&r=664
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> seznam.cz-091952 URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> videa.seznam.cz-181817 URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> zbozi.cz-020302 URL = hxxp://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> {180780f0-b348-4b44-8210-94a8f3ee15b2} URL = hxxp://search.comcast.net/search/?cat=Web&con=toolbar&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = hxxp://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10140_cnet_150509&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-04-21] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-21] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
Toolbar: HKU\.DEFAULT -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Toolbar: HKU\S-1-5-21-4097007782-1966444928-4019047729-1000 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-04-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default
FF NewTab: hxxps://www.facebook.com/
FF DefaultSearchEngine: Google Default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Bing
FF SelectedSearchEngine,S:
FF Homepage: hxxps://www.facebook.com/
FF Session Restore: -> is enabled.
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.http", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.http_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.no_proxies_on", "localhost, 127.0.0.1");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.share_proxy_settings", false);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.socks", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.socks_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.ssl", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.ssl_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.disabled.network.proxy.type", 5);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.http", "127.0.0.1");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.http_port", 8888);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.no_proxies_on", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.share_proxy_settings", false);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.socks", "");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.socks_port", 0);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.ssl", "127.0.0.1");
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.ssl_port", 8888);
FF NetworkProxy: "user_pref("extensions.charles.settings.enabled.network.proxy.type", 1);
FF Keyword.URL: hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-21] ()
FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-06-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-06-18] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-21] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-06-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2015-06-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-04-25] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-05-19] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-05-19] (NVIDIA Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2014-11-05] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-06-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4097007782-1966444928-4019047729-1000: @tools.google.com/Google Update;version=3 -> C:\Users\gabi\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-4097007782-1966444928-4019047729-1000: @tools.google.com/Google Update;version=9 -> C:\Users\gabi\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF user.js: detected! => C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\user.js [2015-11-29]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\amazoncom-pro.xml [2015-05-09]
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\facebook.xml [2015-12-10]
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\google-default.xml [2015-05-09]
FF SearchPlugin: C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\searchplugins\youtube.xml [2015-05-09]
FF Extension: Empty Cache Button - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\extensions\{4cc4a13b-94a6-7568-370d-5f9de54a9c7f} [2016-04-28]
FF Extension: Search By Image (by Google) - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi [2016-04-28]
FF Extension: Greasemonkey - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-04-30]
FF Extension: saveensharie - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\8fa6m-h@iiyiyeeiyi.com [2013-09-13] [not signed]
FF Extension: Bing Search Engine - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\bingsearch.full@microsoft.com [2015-04-02] [not signed]
FF Extension: MyWordTool - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\emily@wilford.biz [2013-11-24] [not signed]
FF Extension: HTML5 Video Everywhere! - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\html5-video-everywhere@lejenome.me.xpi [2016-01-06]
FF Extension: User Agent RG (FFox update) - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\useragentrg-upd@mozilla.org.xpi [2016-04-27]
FF Extension: Charles Autoconfiguration - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\{3e9a3920-1b27-11da-8cd6-0800200c9a66}.xpi [2015-03-22] [not signed]
FF Extension: YouTube Flash Video Player - C:\Users\gabi\AppData\Roaming\Mozilla\Firefox\Profiles\cznanbow.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2016-05-03]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-04-29]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\...\Firefox\Extensions: [{4340308e-3e37-4dd7-9192-8cf05ce9c9f2}] - C:\Program Files (x86)\LyriXeeker\130.xpi => not found
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-06-20] <==== ATTENTION
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC ... earchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR Profile: C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Disk Google) - C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-24]
CHR HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\gabi\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-04]
CHR HKU\S-1-5-21-4097007782-1966444928-4019047729-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cgdebfobecnopjndjbdoapgokdjfffpj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [hahpjplbmicfkmoccokbjejahjjpnena] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lfffjahnfbocnaooecgijfnbpcfekoik] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-04-29]
CHR HKLM-x32\...\Chrome\Extension: [oddhjgogndegicgabhgibhfoompkifcn] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - <no Path/update_url>
StartMenuInternet: Google Chrome - C:\Users\gabi\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
S3 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [922240 2011-06-13] ()
S3 ASDiskUnlocker; C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [258688 2010-12-02] (ASUSTeK Computer Inc.)
S3 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2010-12-01] ()
S3 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2010-10-21] ()
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-04-29] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-04-29] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files (x86)\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720 2015-07-08] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-05-02] (NVIDIA Corporation)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [882464 2015-07-17] (IObit)
R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3020440 2015-11-25] (Intel(R) Corporation)
S3 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-05-02] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-05-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-05-02] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-19] (Electronic Arts)
S3 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [487960 2014-12-16] (Sony Corporation)
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [878904 2016-05-16] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15736 2016-05-16] (McAfee, Inc.)
S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2016-05-16] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 AiChargerPlus; C:\Windows\System32\DRIVERS\AiChargerPlus.sys [14464 2010-11-08] (ASUSTek Computer Inc.)
S3 ASFLTDrv.sys; C:\Program Files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [16512 2010-09-16] (ASUSTeK Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-08-18] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [251632 2015-07-14] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [231520 2015-07-14] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [53360 2015-07-14] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [72400 2015-07-14] (ESET)
R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [39504 2013-04-11] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-23] (GFI Software)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-05-16] (REALiX(tm))
S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-05-24] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-05-02] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [242688 2015-07-05] (QUALCOMM Incorporated)
R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
S3 TuneUpUtilitiesDrv; no ImagePath
R3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
S1 VDiskBus; C:\Windows\System32\DRIVERS\VDiskBus64.sys [43136 2010-09-21] (ASUSTeK Computer Inc.)
S3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN60.sys [29472 2010-01-14] (Windows (R) Codename Longhorn DDK provider)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
S3 ZTEusbMB; C:\Windows\System32\DRIVERS\ZTEusbnmeaext2.sys [123520 2010-12-29] (ZTE Incorporated)
S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [235008 2011-04-09] (ZTE Incorporated)
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 cpuz137; \??\C:\Users\gabi\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-24 11:39 - 2016-05-24 11:39 - 00031048 _____ C:\Users\gabi\Desktop\FRST.txt
2016-05-24 11:39 - 2016-05-24 11:39 - 00000000 ____D C:\FRST
2016-05-24 11:37 - 2016-05-24 11:37 - 02383360 _____ (Farbar) C:\Users\gabi\Desktop\FRST64.exe
2016-05-24 10:43 - 2016-05-24 10:43 - 00000263 _____ C:\Users\gabi\Desktop\ORGONIT, chemtrails a obrana před ovlivňováním lidí EZOpress.URL
2016-05-23 16:39 - 2016-05-23 16:40 - 292445609 _____ C:\Users\gabi\Downloads\MLUVENÉ SLOVO - Simenon, Georges_ Přístav v mlze (DETEKTIVKA).mp4
2016-05-23 14:17 - 2016-05-23 14:17 - 00001188 _____ C:\Users\gabi\Documents\cc_20160523_141706.reg
2016-05-23 12:34 - 2016-05-19 21:45 - 00113208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-05-23 12:32 - 2016-05-21 17:10 - 01581624 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll
2016-05-23 12:32 - 2016-05-21 17:10 - 00141256 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-05-23 12:32 - 2016-05-21 17:10 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 39979576 _____ C:\Windows\system32\nvcompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 35117112 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 31600696 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 25372096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 21794064 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 21336720 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 19110968 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 18138232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 17732936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 17236560 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 13412408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-05-23 12:32 - 2016-05-20 03:01 - 10642728 _____ C:\Windows\system32\nvptxJitCompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 08733096 _____ C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 03447232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 03001792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436822.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 01573432 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436822.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00984512 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00911416 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00770496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00708032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00669952 _____ C:\Windows\system32\nvfatbinaryLoader.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00565392 _____ C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00476848 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00394912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00177952 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00155768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00153232 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00131584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-05-23 12:32 - 2016-05-20 03:01 - 00000594 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-05-23 12:32 - 2016-05-20 03:01 - 00000594 _____ C:\Windows\system32\nv-vk64.json
2016-05-23 11:07 - 2016-05-23 11:07 - 00000209 _____ C:\Users\gabi\Desktop\WeTransfer.URL
2016-05-23 08:46 - 2016-05-23 08:46 - 00444656 _____ (ASMedia Technology Inc) C:\Windows\system32\Drivers\asmtxhci.sys
2016-05-23 08:44 - 2016-05-23 08:44 - 00003130 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2016-05-23 08:44 - 2016-05-23 08:44 - 00003128 _____ C:\Windows\System32\Tasks\SmartDefrag_Update
2016-05-23 08:44 - 2016-05-23 08:44 - 00000000 ____D C:\Windows\IObit
2016-05-23 08:44 - 2016-05-23 08:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2016-05-23 02:24 - 2016-05-23 02:24 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-05-23 02:24 - 2016-05-23 02:24 - 00001151 _____ C:\ProgramData\Desktop\Mozilla Firefox.lnk
2016-05-23 00:31 - 2016-05-24 02:01 - 00000000 ____D C:\Users\gabi\Downloads\Mluvene knihy
2016-05-22 23:43 - 2016-05-22 23:43 - 00001654 _____ C:\Users\gabi\Documents\cc_20160522_234339.reg
2016-05-21 19:34 - 2016-05-24 11:18 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-21 19:34 - 2016-05-23 09:18 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-05-21 19:34 - 2016-05-23 09:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-21 19:34 - 2016-05-23 09:18 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-05-20 09:35 - 2016-05-20 09:35 - 00000251 _____ C:\Users\gabi\Desktop\(103) II.Kat Rum Meyhanesi.URL
2016-05-17 09:40 - 2016-05-17 09:40 - 00000224 _____ C:\Users\gabi\Desktop\Beer Can Bacon Burger recipes by the BBQ Pit Boys - YouTube.URL
2016-05-15 16:45 - 2016-05-15 16:45 - 00000228 _____ C:\Users\gabi\Desktop\MicroTouch Switchblade™ - 2 in 1 Trimmer Lets You Groom Everywhere, Head to Toe!.URL
2016-05-15 12:28 - 2016-05-15 12:28 - 00000292 _____ C:\Users\gabi\Desktop\Dutch Glow® Cleaning Tonic Powerful, nontoxic, all natural kitchen cleaner!.URL
2016-05-13 12:21 - 2016-05-10 00:07 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436519.dll
2016-05-13 12:21 - 2016-05-10 00:07 - 01573432 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436519.dll
2016-05-13 12:18 - 2016-04-14 01:38 - 00113216 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-05-13 12:18 - 2016-04-14 01:38 - 00102976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-05-13 12:18 - 2016-04-14 01:38 - 00056384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-05-13 10:28 - 2016-05-13 15:08 - 711588193 _____ C:\Users\gabi\Downloads\Linka.c.657.720p.BluRay.x264.CZ.dabing.mkv
2016-05-13 07:32 - 2016-05-13 08:16 - 791111680 _____ C:\Users\gabi\Downloads\Poldove-a-zlodeji.avi
2016-05-08 16:34 - 2016-05-08 17:26 - 933451776 _____ C:\Users\gabi\Downloads\Navrat-blbyho-a-blbejsiho-Komedie-2014-CZ-adriatic.avi
2016-05-08 00:56 - 2016-05-08 00:56 - 00011802 _____ C:\Users\gabi\Documents\Filip 10.txt
2016-05-07 11:34 - 2016-05-08 01:18 - 1712567876 _____ C:\Users\gabi\Downloads\Terminator.Genisys.2015.BluRay.1080p.TrueHD.7.1.Atmos.x264-EPiC.mkv
2016-05-06 21:49 - 2016-05-06 22:30 - 728084652 _____ C:\Users\gabi\Downloads\Vo-štvorici-po-opici-2-Komedie-2011-CZ-adriatic.avi
2016-05-06 12:03 - 2016-05-06 12:44 - 738929644 _____ C:\Users\gabi\Downloads\Viktor-Frankenstein---2015-CZ-dabing.avi
2016-05-05 17:35 - 2016-05-05 18:52 - 1378323908 _____ C:\Users\gabi\Downloads\S-láskou,-Rosie-(komedie,romantic.-2014)cz---IRISA.avi
2016-05-05 15:25 - 2016-05-05 16:31 - 1182362666 _____ C:\Users\gabi\Downloads\Pád-Země-(2015)-Xvid-⍟ℋ.avi
2016-05-03 22:23 - 2016-05-03 22:23 - 00129824 _____ C:\Windows\SysWOW64\vulkan-1-1-0-11-1.dll
2016-05-03 22:22 - 2016-05-03 22:22 - 00130848 _____ C:\Windows\system32\vulkan-1-1-0-11-1.dll
2016-05-03 22:22 - 2016-05-03 22:22 - 00045344 _____ C:\Windows\system32\vulkaninfo-1-1-0-11-1.exe
2016-05-03 22:22 - 2016-05-03 22:22 - 00040224 _____ C:\Windows\SysWOW64\vulkaninfo-1-1-0-11-1.exe
2016-05-02 21:25 - 2016-05-02 22:40 - 1299148676 _____ C:\Users\gabi\Downloads\Každý-milion-dobrý-Xvid-⍟ℋ.avi
2016-05-02 02:34 - 2016-05-02 02:34 - 00000308 _____ C:\Users\gabi\Desktop\Pokud někde uvidíte tohoto brouka, okamžitě běžte pryč. To, co s vámi totiž udělá, je děsivé!.URL
2016-05-02 00:35 - 2016-05-02 02:13 - 1762451456 _____ C:\Users\gabi\Downloads\Padesatka.2015.XviD.CZ.avi
2016-05-01 18:38 - 2016-05-01 20:20 - 1789501440 _____ C:\Users\gabi\Downloads\Superhypochondr-2014-Cz-dab..avi
2016-04-30 22:11 - 2016-04-30 23:04 - 762460160 _____ C:\Users\gabi\Downloads\Lucy-DVDRip_2014_CZ_Dab.avi
2016-04-30 15:00 - 2016-04-30 15:43 - 786511872 _____ C:\Users\gabi\Downloads\Mercy-(2014)-CZ-dabing.avi
2016-04-30 12:41 - 2016-04-30 13:31 - 891371520 _____ C:\Users\gabi\Downloads\Moje-segra-ma-prima-brachu-DVDRip_2014_CZ_Dabing.avi
2016-04-28 02:24 - 2016-04-28 02:24 - 00000742 _____ C:\Users\gabi\Documents\Kvasek.txt
2016-04-27 20:52 - 2016-04-27 21:41 - 734988288 _____ C:\Users\gabi\Downloads\The-Gambler-DVDRip_2015_Cz-Dabing.avi
2016-04-24 09:00 - 2016-04-24 10:59 - 00000000 ____D C:\Users\gabi\Downloads\Nová složka
2016-04-24 00:08 - 2016-04-24 00:08 - 00000842 _____ C:\Users\gabi\Documents\cc_20160424_000823.reg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-24 11:36 - 2015-05-16 15:46 - 00002870 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (gabi)
2016-05-24 11:34 - 2015-06-18 16:31 - 00000000 ____D C:\Users\gabi\Desktop\Cisteni a optimalizace
2016-05-24 11:33 - 2015-06-02 19:51 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-24 11:33 - 2015-05-16 15:44 - 00000000 ____D C:\ProgramData\ProductData
2016-05-24 11:33 - 2014-06-17 14:34 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf8a5ab905131a.job
2016-05-24 11:33 - 2012-03-11 22:47 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-24 11:33 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-24 11:32 - 2009-07-14 00:45 - 00017296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-24 11:32 - 2009-07-14 00:45 - 00017296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-24 10:33 - 2013-07-22 09:06 - 00000386 _____ C:\Windows\Tasks\update-S-1-5-21-4097007782-1966444928-4019047729-1000.job
2016-05-24 02:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2016-05-23 20:29 - 2013-01-29 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-05-23 14:21 - 2012-03-14 00:55 - 13005042 _____ C:\Windows\system32\perfh005.dat
2016-05-23 14:21 - 2012-03-14 00:55 - 04364684 _____ C:\Windows\system32\perfc005.dat
2016-05-23 14:21 - 2009-07-14 01:13 - 09048678 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-23 12:34 - 2016-03-10 14:31 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-05-23 12:34 - 2014-02-05 23:38 - 00000000 ____D C:\temp
2016-05-23 12:34 - 2013-01-06 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-05-23 12:34 - 2012-03-11 22:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-05-23 11:12 - 2016-04-13 15:41 - 00000000 ____D C:\Program Files\TrueKey
2016-05-23 11:12 - 2015-05-16 14:00 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d09002253e2ab2.job
2016-05-23 11:12 - 2015-02-04 09:25 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1d0407e5afc26.job
2016-05-23 11:12 - 2015-02-03 17:53 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d03ffbcb6285ca.job
2016-05-23 11:12 - 2014-06-17 14:34 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf8a5ab91b5a8e.job
2016-05-23 11:12 - 2014-06-17 09:49 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1cf8a33639a01d.job
2016-05-23 11:12 - 2014-06-17 09:49 - 00000852 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000Core1cf8a3361aa5f9.job
2016-05-23 11:12 - 2012-12-22 12:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-05-23 08:44 - 2015-11-29 12:45 - 00003238 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler
2016-05-23 08:44 - 2015-11-29 12:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3
2016-05-23 08:44 - 2015-05-16 15:43 - 00000000 ____D C:\Users\gabi\AppData\Roaming\IObit
2016-05-23 08:44 - 2015-05-16 15:43 - 00000000 ____D C:\Program Files (x86)\IObit
2016-05-23 02:24 - 2013-04-11 14:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-05-23 02:24 - 2012-12-22 12:37 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-05-23 00:33 - 2016-04-19 12:09 - 00000000 ____D C:\Users\gabi\Downloads\Knihy
2016-05-22 23:44 - 2015-05-16 15:44 - 00002900 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_gabi
2016-05-22 23:43 - 2014-04-13 00:50 - 00000000 ____D C:\Users\gabi\AppData\Local\CrashDumps
2016-05-22 01:47 - 2016-01-06 10:41 - 00000000 ____D C:\Users\gabi\Desktop\Babske rady
2016-05-21 21:33 - 2016-04-13 15:50 - 00001150 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk
2016-05-21 19:45 - 2015-05-16 14:00 - 00003906 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d09002253e2ab2
2016-05-21 19:45 - 2015-02-04 09:25 - 00003884 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1d0407e5afc26
2016-05-21 19:45 - 2015-02-03 17:53 - 00003906 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d03ffbcb6285ca
2016-05-21 19:45 - 2014-06-17 14:34 - 00003906 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf8a5ab91b5a8e
2016-05-21 19:45 - 2014-06-17 09:49 - 00003884 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000UA1cf8a33639a01d
2016-05-21 19:45 - 2014-06-17 09:49 - 00003488 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4097007782-1966444928-4019047729-1000Core1cf8a3361aa5f9
2016-05-21 19:44 - 2016-04-13 15:50 - 00003330 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare)
2016-05-21 19:34 - 2014-09-02 18:00 - 00000000 ____D C:\Users\gabi\AppData\Local\Adobe
2016-05-21 14:39 - 2015-09-06 21:09 - 00000000 ____D C:\Users\gabi\Desktop\Vareni
2016-05-20 23:54 - 2015-08-22 14:15 - 00000000 ____D C:\Users\gabi\Desktop\Ruzne
2016-05-20 03:01 - 2016-03-01 14:12 - 16693208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-05-20 03:01 - 2015-12-01 12:21 - 00039124 _____ C:\Windows\system32\nvinfo.pb
2016-05-20 03:01 - 2013-02-26 00:32 - 14293592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2016-05-20 03:01 - 2013-02-26 00:32 - 03383448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2016-05-20 03:01 - 2012-03-11 22:46 - 03825384 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2016-05-19 22:11 - 2015-12-21 12:51 - 00531904 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2016-05-19 22:11 - 2015-12-21 12:51 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2016-05-19 22:11 - 2013-01-06 13:08 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 06346688 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 02454976 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 01352760 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2016-05-19 22:11 - 2012-03-11 22:47 - 00393784 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2016-05-19 22:11 - 2012-03-11 22:47 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2016-05-19 21:33 - 2016-04-13 15:41 - 00000000 ____D C:\ProgramData\McAfee
2016-05-18 21:25 - 2014-03-22 10:17 - 00000000 ___RD C:\Users\gabi\Desktop\FOTKY
2016-05-18 19:25 - 2012-03-11 22:47 - 06448223 _____ C:\Windows\system32\nvcoproc.bin
2016-05-17 23:25 - 2016-03-03 12:56 - 00000000 ____D C:\Users\gabi\Downloads\Aplikace a programy
2016-05-16 22:59 - 2013-11-09 00:32 - 00000000 ____D C:\Users\gabi\Desktop\Stranky
2016-05-13 12:22 - 2012-03-11 22:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-05-13 12:18 - 2013-12-06 08:04 - 00000000 ____D C:\Users\gabi\AppData\Local\NVIDIA
2016-05-12 18:46 - 2012-03-14 14:16 - 00002370 _____ C:\Users\gabi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-10 18:05 - 2014-06-17 14:34 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cf8a5ab905131a
2016-05-09 20:50 - 2015-10-11 22:43 - 00000000 ____D C:\Users\gabi\Desktop\Nove do simsu
2016-05-08 14:17 - 2013-02-22 11:01 - 00000000 ____D C:\Program Files (x86)\Recepty doma
2016-05-08 00:57 - 2016-02-12 18:52 - 00000659 _____ C:\Users\gabi\Documents\Kody na kafe.txt
2016-05-07 12:34 - 2016-03-03 12:55 - 00000000 ____D C:\Users\gabi\Downloads\Filmy
2016-05-06 23:58 - 2015-07-27 01:51 - 00000000 ____D C:\Users\gabi\Desktop\Rucni prace a navody
2016-05-06 00:59 - 2014-11-22 19:06 - 00000000 ____D C:\Users\gabi\Desktop\Ryby
2016-05-05 16:24 - 2012-04-03 15:28 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-05-04 15:02 - 2015-04-25 06:54 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-05-04 15:02 - 2015-04-25 06:52 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-05-04 00:45 - 2015-06-20 12:32 - 00000000 ____D C:\Users\gabi\Desktop\Obchody
2016-05-03 22:23 - 2016-03-10 14:31 - 00129824 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-05-03 22:22 - 2016-03-10 14:31 - 00130848 _____ C:\Windows\system32\vulkan-1.dll
2016-05-03 22:22 - 2016-03-10 14:31 - 00045344 _____ C:\Windows\system32\vulkaninfo.exe
2016-05-03 22:22 - 2016-03-10 14:31 - 00040224 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-05-02 12:14 - 2014-11-08 16:52 - 00000000 ____D C:\Users\gabi\Desktop\Moje vánoční kuchařka
2016-05-02 01:39 - 2015-09-23 09:09 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-05-02 01:39 - 2013-12-06 08:04 - 01377800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-05-02 01:38 - 2015-11-27 11:53 - 00112032 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-05-02 01:38 - 2015-09-23 09:09 - 01756608 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-05-02 01:38 - 2013-12-06 08:04 - 01767944 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
==================== Files in the root of some directories =======
2013-08-26 12:19 - 2013-09-17 01:19 - 0000114 _____ () C:\Users\gabi\AppData\Roaming\WB.CFG
2013-08-26 12:19 - 2013-09-17 01:19 - 0000005 _____ () C:\Users\gabi\AppData\Roaming\WBPU-TTL.DAT
2015-04-07 05:49 - 2015-04-07 05:49 - 0000064 _____ () C:\Users\gabi\AppData\Local\29ac5b7c7af3f31b11ecb2fdbcc37a98
2013-10-12 12:48 - 2013-11-23 15:46 - 0003584 _____ () C:\Users\gabi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-03-09 12:29 - 2013-03-09 12:29 - 0002661 _____ () C:\Users\gabi\AppData\Local\recently-used.xbel
2013-05-10 18:04 - 2013-05-16 01:35 - 0007611 _____ () C:\Users\gabi\AppData\Local\Resmon.ResmonCfg
2013-04-07 18:17 - 2013-04-07 18:17 - 0000003 _____ () C:\Users\gabi\AppData\Local\updater.log
2013-04-07 18:17 - 2015-10-02 02:47 - 0000424 _____ () C:\Users\gabi\AppData\Local\UserProducts.xml
2014-12-24 19:54 - 2014-12-24 19:54 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-05-16 15:50 - 2015-05-16 15:50 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2013-07-02 18:57] - [2015-06-02 19:08] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79
C:\Windows\SysWOW64\User32.dll
[2013-07-02 18:57] - [2015-06-02 19:08] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-05-18 03:58
==================== End of FRST.txt ============================