Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017
Ran by Ruthan (administrator) on NASOND (21-02-2017 02:25:24)
Running from C:\Users\Ruthan\Desktop
Loaded Profiles: Ruthan (Available Profiles: Ruthan & ETB User & tUser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Czech (Czech Republic)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(LogMeIn Inc.) C:\Programs\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc.) C:\Programs\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Programs\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Ruthan\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [TortoiseHgOverlayIconServer] => C:\Programs\TortoiseHg\TortoiseHgOverlayServer.exe [100616 2014-11-20] ()
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-11-12] (IvoSoft)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [394208 2015-12-21] ()
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [462328 2009-10-27] (Acronis)
HKLM\...\Run: [tvncontrol] => C:\Programs\TightVNC\tvnserver.exe [1725920 2016-09-23] (GlavSoft LLC.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320584 2016-05-31] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Programy\Avira\AntiVir Desktop\avgnt.exe [917576 2016-12-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61896 2016-12-29] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [EaseUs Tray] => C:\Programy\EaseUS Todo Backup\bin\TrayNotify.exe [743560 2011-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM-x32\...\Run: [EaseUs Watch] => C:\Programy\EaseUS Todo Backup\bin\EuWatch.exe [70792 2011-12-22] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM-x32\...\Run: [tvncontrol] => C:\Programy\TightVNC\tvnserver.exe [826896 2011-05-26] (GlavSoft LLC.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Programy\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [298776 2015-12-18] (Intel Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Display] => C:\Programs\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Programs\LogMeIn Hamachi\hamachi-2-ui.exe [5565960 2016-11-11] (LogMeIn Inc.)
HKLM-x32\...\Run: [adm_tray.exe] => C:\Programs\Acronis Disk Monitor\DriveMonitor\adm_tray.exe [530768 2010-06-04] (Acronis)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-04-08] (Sun Microsystems, Inc.)
HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\GIGABYTE\EasyTune\etro.exe [5632 2015-09-24] (GIGA-BYTE TECHNOLOGY CO., LTD.)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Command Processor: "C:\Programs\clink\0.4.2\clink" inject --profile "~\clink" <======= ATTENTION
HKU\S-1-5-21-898345549-4091288585-2178738310-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [163328 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-21-898345549-4091288585-2178738310-1000\...\Run: [TeamCityTrayNotify] => C:\Programs\JetBrains\TeamCity\TrayNotifier\JetBrains.TrayNotifier.exe [281208 2014-09-26] (JetBrains)
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2016-09-17]
ShortcutTarget: APC UPS Status.lnk -> C:\Programs\PowerChute Personal Edition\Display.exe (Schneider Electric)
Startup: C:\Users\Ruthan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OS X Mountain Lion - Shortcut.lnk [2015-12-29]
ShortcutTarget: OS X Mountain Lion - Shortcut.lnk -> V:\MAc OS X Mountain Lion Vmware\OS X Mountain Lion.vmx (No File)
Startup: C:\Users\Ruthan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VmServiceTray.lnk [2015-11-22]
ShortcutTarget: VmServiceTray.lnk -> C:\vms\VmServiceTray.exe ()
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog9 01 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 09 C:\Programy\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 01 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 02 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 03 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 04 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 05 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 06 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 07 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 08 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 09 C:\Programy\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-22] (Avira Operations GmbH & Co. KG)
Tcpip\..\Interfaces\{CAE87645-C633-4C1E-A08A-405E5402ED15}: [NameServer] 10.0.0.138,8.8.4.4
Tcpip\..\Interfaces\{D324AACB-DACD-486B-B7E2-1C1DFADB61D6}: [NameServer] 10.0.0.138,8.4.4.8

Internet Explorer:
==================
HKU\S-1-5-21-898345549-4091288585-2178738310-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/?pc=AVBR
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKU\S-1-5-21-898345549-4091288585-2178738310-1000 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKU\S-1-5-21-898345549-4091288585-2178738310-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKU\S-1-5-21-898345549-4091288585-2178738310-1000 -> {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = hxxp://www.ask.com/web?o=15710&l=dis&q={searchTerms}
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-07] (Sun Microsystems, Inc.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
DPF: HKLM-x32 {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} hxxp://download.gigabyte.com.tw/object/Dldrv.ocx

FireFox:
========
FF ProfilePath: C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default [2017-02-21]
FF Homepage: Mozilla\Firefox\Profiles\olbp40kp.default -> hxxp://google.com
FF Extension: (Classic Theme Restorer) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2016-11-22]
FF Extension: (Download Panel Tweaks) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\downloadpaneltweaks@dagger2-addons.mozilla.org.xpi [2016-06-26]
FF Extension: (Xmarks) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\foxmarks@kei.com [2016-06-26]
FF Extension: (NetVideoHunter) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\netvideohunter@netvideohunter.com [2016-06-26]
FF Extension: (Screengrab (fix version)) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi [2017-02-20]
FF Extension: (Copy Plain Text) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\{723AAF16-AF1F-4404-A5D7-0BFE39766605} [2015-11-22] [not signed]
FF Extension: (Adblock Plus) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-28]
FF Extension: (Tab Mix Plus) - C:\Users\Ruthan\AppData\Roaming\Mozilla\Firefox\Profiles\olbp40kp.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2016-11-19]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-11-22] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-14] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-14] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Programy\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2011-05-23] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2011-07-07] (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin HKU\S-1-5-21-898345549-4091288585-2178738310-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Ruthan\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-898345549-4091288585-2178738310-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Ruthan\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-898345549-4091288585-2178738310-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ruthan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2011-09-13] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-898345549-4091288585-2178738310-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-06-27] ()
StartMenuInternet: FIREFOX.EXE - C:\Programs\Mozilla Firefox\firefox.exe

Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Ruthan\AppData\Local\Google\Chrome\User Data\Default [2016-03-23]
CHR Extension: (Avira Browser Safety) - C:\Users\Ruthan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-03-01]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Ruthan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-01]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx

Opera: 
=======
StartMenuInternet: (HKLM) OperaStable - C:\Programs\Opera\Launcher.exe

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirSchedulerService; C:\Programy\Avira\AntiVir Desktop\sched.exe [476736 2016-12-12] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Programy\Avira\AntiVir Desktop\avguard.exe [476736 2016-12-12] (Avira Operations GmbH & Co. KG)
S2 APC Data Service; C:\Programs\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)
S2 APC UPS Service; C:\Programs\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG)
S2 EaseUS Agent; C:\Programy\EaseUS Todo Backup\bin\Agent.exe [61064 2011-12-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
S2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [File not signed]
S3 GalaxyClientService; C:\Programs\GalaxyClient\GalaxyClientService.exe [244800 2016-07-08] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6211648 2016-06-08] (GOG.com)
S2 Guard Agent; C:\Programy\EaseUS Todo Backup\bin\GuardAgent.exe [23176 2011-12-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
R2 Hamachi2Svc; C:\Programs\LogMeIn Hamachi\x64\hamachi-2.exe [2627080 2016-11-11] (LogMeIn Inc.)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2016-05-31] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [365024 2015-12-21] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S2 NfsClnt; C:\Windows\system32\nfsclnt.exe [65536 2010-11-21] (Microsoft Corporation)
S2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-11-17] (NVIDIA Corporation)
S3 Origin Client Service; C:\Programs\Origin\OriginClientService.exe [2122248 2016-06-26] (Electronic Arts)
S2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [301720 2011-12-22] ()
S2 SBSDWSCService; C:\Programy\Spybot SearchDestroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S2 TCBuildAgent; c:\TeamCity\buildAgent\launcher\bin\TeamCityAgentService-windows-x86-32.exe [209920 2014-12-08] () [File not signed]
S2 TeamCity; c:\TeamCity\bin\TeamCityService.exe [392808 2014-09-26] (JetBrains GmbH)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
S3 TermService; C:\Windows\system32\rdpwrap.dll [116736 2016-10-17] (Stas'M Corp.) [File not signed]
S2 tvnserver; C:\Programs\TightVNC\tvnserver.exe [1725920 2016-09-23] (GlavSoft LLC.)
S2 VBoxVmService; C:\vms\VBoxVmService64.exe [127488 2016-07-13] () [File not signed]
S2 VMAuthdService; C:\Programs\VmwarePlayer\vmware-authd.exe [95816 2016-05-05] (VMware, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-08-05] (Microsoft Corporation)
S2 WinMediaService; C:\Windows\msapss\bin\msapp.exe [3177472 2016-11-23] () [File not signed]
S2 AntiVirMailService; "C:\Programy\Avira\AntiVir Desktop\avmailc.exe" [X]
S4 AntiVirWebService; "C:\Programy\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]
S3 CacheDump; "C:\Users\ETBUSE~1\AppData\Local\Temp\cachedump64.exe" -s [X] <==== ATTENTION
S2 DES2 Service; "C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe" [X]
S2 FileZilla Server; "C:\Programy\FileZilla Server\FileZilla Server.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 %ServiceName%; C:\Windows\System32\drivers\iusb3hcs.sys [22768 2015-12-21] (Intel Corporation)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176464 2016-12-12] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [148032 2016-12-12] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-12] (Avira Operations GmbH & Co. KG)
S3 cpuz138; C:\Users\Ruthan\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [27320 2016-11-22] (CPUID) <==== ATTENTION
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [510952 2015-11-24] (Intel Corporation)
R0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [57480 2011-12-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [51336 2011-12-22] () [File not signed]
S4 EUDISK; C:\Windows\system32\drivers\eudisk.sys [193928 2011-04-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
S1 EUDSKACS; C:\Windows\system32\drivers\eudskacs.sys [19592 2011-12-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
S1 EUFDDISK; C:\Windows\system32\drivers\EuFdDisk.sys [189576 2011-12-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
S4 EUFS; C:\Windows\system32\drivers\eufs.sys [26504 2011-04-22] (CHENGDU YIWO Tech Development Co., Ltd) [File not signed]
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2015-11-22] ()
S1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2015-11-22] (REALiX(tm))
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [32240 2016-05-31] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation)
S3 NfsRdr; C:\Windows\System32\drivers\nfsrdr.sys [246272 2010-11-21] (Microsoft Corporation)
S3 PsxDrv; C:\Windows\System32\drivers\psxdrv.sys [10240 2009-07-14] (Microsoft Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 RpcXdr; C:\Windows\System32\drivers\rpcxdr.sys [104960 2010-11-21] (Microsoft Corporation)
S3 RTCore64; C:\Programs\MSI Afterburner\RTCore64.sys [13512 2015-12-09] ()
S3 smserial; C:\Windows\System32\DRIVERS\SmSerl64.sys [1227776 2009-06-10] (Motorola Inc.)
S1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [102576 2015-11-10] ()
S1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [25904 2015-11-10] ()
S1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [701360 2015-11-10] ()
S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [352816 2011-10-13] (Paragon)
S3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN60.sys [24064 2010-12-14] (Windows (R) Codename Longhorn DDK provider)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [76480 2015-05-21] (VMware, Inc.)
U4 %VMnetAdapter.Service.Name%; no ImagePath
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
U4 nicm; no ImagePath
U4 nwfilter; no ImagePath
U4 parvdm; no ImagePath
U4 smbios; no ImagePath
U4 VMTools; no ImagePath
U4 VMUpgradeHelper; no ImagePath
S2 vstor2; \??\C:\Program Files (x86)\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys [X]
S3 WinRing0_1_2_0; \??\C:\Programs\NZXT CAM\CAM_Client_V3.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-21 02:25 - 2017-02-21 02:25 - 00025034 _____ C:\Users\Ruthan\Desktop\FRST.txt
2017-02-21 02:23 - 2017-02-21 02:23 - 64153152 _____ (Oracle Corporation) C:\Users\Ruthan\Desktop\jre-8u121-windows-x64.exe
2017-02-20 02:42 - 2017-02-21 02:25 - 00000000 ____D C:\FRST
2017-02-20 02:41 - 2017-02-20 02:41 - 00112640 _____ (forum.viry.cz) C:\Users\Ruthan\Downloads\FRSTLauncher.exe
2017-02-20 02:41 - 2017-02-20 02:41 - 00112640 _____ (forum.viry.cz) C:\Users\Ruthan\Desktop\FRSTLauncher.exe
2017-02-20 02:40 - 2017-02-20 02:40 - 02422784 _____ (Farbar) C:\Users\Ruthan\Desktop\FRST64.exe
2017-02-19 23:45 - 2017-02-21 02:21 - 00455606 _____ C:\Windows\ntbtlog.txt
2017-01-09 02:54 - 2017-01-09 02:54 - 00003288 ____N C:\bootsqm.dat
2017-01-07 14:26 - 2017-01-26 05:03 - 00000000 ____D C:\Windows\jb-JP
2017-01-07 14:26 - 2017-01-07 14:26 - 00000000 ____D C:\Windows\msapss
2017-01-02 21:09 - 2017-01-02 21:04 - 00067418 _____ C:\Users\Ruthan\Downloads\_YKS675_README_.hta
2017-01-02 21:04 - 2017-01-02 21:04 - 00067418 _____ C:\Users\ETB User\Desktop\_YKS675_README_.hta
2017-01-02 18:30 - 2017-01-02 18:30 - 00000000 ____D C:\Users\ETB User\AppData\Roaming\WinRAR
2017-01-02 18:29 - 2017-01-02 18:29 - 00000000 ____D C:\Users\ETB User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-01-02 18:29 - 2017-01-02 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-01-02 18:29 - 2017-01-02 18:29 - 00000000 ____D C:\Program Files\WinRAR
2017-01-02 17:52 - 2017-01-02 17:52 - 00000000 ____D C:\Users\ETB User\AppData\Roaming\TeamViewer
2017-01-02 05:31 - 2017-01-02 05:31 - 00000909 _____ C:\Users\Ruthan\Desktop\RG20170102.lnk
2016-12-19 00:38 - 2016-12-19 00:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-12-13 14:25 - 2016-12-13 14:25 - 00000000 __SHD C:\found.003
2016-12-10 23:40 - 2016-12-10 23:40 - 00000000 ____D C:\Users\Ruthan\AppData\Roaming\FileZilla Server
2016-12-10 23:36 - 2016-12-10 23:36 - 00000000 ____D C:\ProgramData\TightVNC
2016-12-10 23:36 - 2016-12-10 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TightVNC
2016-12-10 23:23 - 2016-12-19 00:16 - 00000989 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2016-11-29 22:34 - 2016-11-29 22:34 - 00028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
2016-11-29 22:34 - 2016-11-29 22:34 - 00019112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110_clr0400.dll
2016-11-29 22:34 - 2016-11-29 22:34 - 00019112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll
2016-11-29 22:34 - 2016-11-29 22:34 - 00019112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110_clr0400.dll
2016-11-29 22:27 - 2016-11-29 22:27 - 00030400 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
2016-11-29 22:27 - 2016-11-29 22:27 - 00019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr110_clr0400.dll
2016-11-29 22:27 - 2016-11-29 22:27 - 00019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
2016-11-29 22:27 - 2016-11-29 22:27 - 00019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcp110_clr0400.dll
2016-11-28 02:13 - 2016-11-28 02:13 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-11-28 02:13 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-11-28 02:13 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2016-11-28 02:13 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-11-28 02:13 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2016-11-28 02:12 - 2016-11-17 01:58 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2016-11-28 02:11 - 2016-11-17 03:04 - 40123840 _____ C:\Windows\system32\nvcompiler.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 35224632 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 34704952 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 28140088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 19936464 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 17440392 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 17361976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 14410120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 14048312 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-11-28 02:11 - 2016-11-17 03:04 - 10912232 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 10795128 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 10346024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 09150704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 08754160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 03941720 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 03645496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 03479560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 03206592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437595.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 01595456 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 01585088 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437595.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 01037248 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00974272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00943552 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00895424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00520912 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00491536 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00436088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00407064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00212936 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-11-28 02:11 - 2016-11-17 03:04 - 00170872 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-11-28 02:11 - 2016-11-17 03:04 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-11-28 02:11 - 2016-11-17 03:04 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2016-11-28 01:26 - 2016-05-05 02:42 - 00074824 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
2016-11-28 01:26 - 2016-05-05 02:42 - 00041544 _____ (VMware, Inc.) C:\Windows\system32\Drivers\VMkbd.sys
2016-11-28 01:26 - 2015-05-21 17:36 - 00076480 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
2016-11-28 01:26 - 2015-05-21 17:35 - 00068288 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
2016-11-28 01:26 - 2015-05-21 17:35 - 00064192 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
2016-11-28 01:25 - 2016-11-28 01:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2016-11-28 01:25 - 2016-11-28 01:25 - 00000000 ____D C:\Program Files\Common Files\VMware
2016-11-28 01:25 - 2016-05-05 02:43 - 00446536 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2016-11-28 01:25 - 2016-05-05 02:42 - 00939592 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
2016-11-28 01:25 - 2015-10-21 12:41 - 00055488 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-21 02:22 - 2016-11-22 03:13 - 00000000 ____D C:\Users\Ruthan\AppData\LocalLow\Mozilla
2017-02-21 02:22 - 2014-12-09 04:28 - 00000000 ____D C:\Users\Ruthan\AppData\Local\clink
2017-02-20 02:38 - 2014-12-29 21:02 - 00000000 ____D C:\Users\Ruthan\AppData\Roaming\VMware
2017-02-20 02:38 - 2014-12-29 21:02 - 00000000 ____D C:\Users\Ruthan\AppData\Local\VMware
2017-02-20 02:08 - 2010-11-21 10:27 - 00706164 _____ C:\Windows\system32\perfh005.dat
2017-02-20 02:08 - 2010-11-21 10:27 - 00156680 _____ C:\Windows\system32\perfc005.dat
2017-02-20 02:08 - 2009-07-14 06:13 - 00006946 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-20 01:32 - 2014-02-05 12:12 - 00000000 ____D C:\Temp
2017-02-20 00:56 - 2015-11-22 15:21 - 00018560 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-02-20 00:56 - 2015-11-22 15:21 - 00018560 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-02-20 00:54 - 2015-11-22 16:23 - 00000000 ____D C:\Users\Ruthan\AppData\Local\ClassicShell
2017-02-20 00:54 - 2014-08-12 22:42 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-20 00:53 - 2014-12-29 03:35 - 00000000 ____D C:\ProgramData\VMware
2017-02-20 00:53 - 2014-12-03 01:29 - 00000000 ____D C:\Users\Ruthan\AppData\Roaming\TortoiseHg
2017-02-20 00:53 - 2012-10-07 13:38 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-20 00:53 - 2011-07-07 02:55 - 00000000 ____D C:\Users\Ruthan\.VirtualBox
2017-02-20 00:53 - 2011-07-07 02:29 - 00000000 ____D C:\Users\Ruthan\AppData\Local\LogMeIn Hamachi
2017-02-20 00:53 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-20 00:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration
2017-02-20 00:49 - 2009-07-14 05:45 - 00271312 _____ C:\Windows\system32\FNTCACHE.DAT
2017-02-20 00:48 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2017-02-20 00:48 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism
2017-02-19 21:55 - 2016-09-14 04:55 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-02-19 21:55 - 2016-09-14 04:55 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-02-19 21:55 - 2016-09-14 04:55 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-02-19 21:55 - 2016-09-14 04:55 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-01-26 07:00 - 2013-11-20 01:46 - 00435712 ___SH C:\EUMONBMP.SYS
2017-01-26 06:58 - 2011-09-06 20:03 - 00000000 ____D C:\Users\Ruthan\AppData\Roaming\uTorrent
2017-01-26 00:49 - 2016-07-22 13:31 - 00000000 ____D C:\Users\ETB User\AppData\Local\LogMeIn Hamachi
2017-01-25 18:34 - 2016-11-04 11:49 - 00000000 ____D C:\Users\ETB User\AppData\Local\ClassicShell
2017-01-25 16:10 - 2016-07-22 13:31 - 00000000 ____D C:\Users\ETB User\AppData\Local\clink
2017-01-24 08:17 - 2012-10-14 13:26 - 00000000 ____D C:\Program Files (x86)\TeamViewer

==================== Files in the root of some directories =======

2015-12-22 01:10 - 2016-06-26 20:58 - 1065984 _____ () C:\Users\Ruthan\AppData\Local\file__0.localstorage
2015-11-22 18:11 - 2015-11-22 18:11 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\Ruthan\en_res.dll
C:\Users\Ruthan\es_res.dll
C:\Users\Ruthan\fr_res.dll
C:\Users\Ruthan\grm_res.dll
C:\Users\Ruthan\it_res.dll
C:\Users\Ruthan\jp_res.dll
C:\Users\Ruthan\mfc80u.dll
C:\Users\Ruthan\msiexec.exe
C:\Users\Ruthan\msvcr80.dll
C:\Users\Ruthan\PCPE Setup.exe
C:\Users\Ruthan\pt_res.dll
C:\Users\Ruthan\ResourceReader.dll
C:\Users\Ruthan\ru_res.dll
C:\Users\Ruthan\zh_res.dll


Some files in TEMP:
====================
2016-07-22 13:31 - 2016-07-22 13:31 - 0000000 ____D () C:\Users\ETB User\AppData\Local\Temp\avgnt.exe
2015-11-22 16:09 - 2015-11-22 16:09 - 0000000 ____D () C:\Users\Ruthan\AppData\Local\Temp\avgnt.exe
2016-06-27 00:01 - 2016-06-27 00:01 - 0208896 _____ (Sony DADC Austria AG) C:\Users\Ruthan\AppData\Local\Temp\drm_dyndata_7370012.dll
2016-06-27 16:03 - 2016-06-27 22:53 - 0204800 _____ (Sony DADC Austria AG) C:\Users\Ruthan\AppData\Local\Temp\drm_dyndata_7370014.dll
2016-11-19 21:48 - 2016-10-17 07:40 - 0380928 _____ (Rational Intellectual Holdings Ltd.) C:\Users\Ruthan\AppData\Local\Temp\_unps.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


ATTENTION: ==> Could not access BCD. 

LastRegBack: 2017-01-03 04:32

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (Win7-64UltimateSSD) (Fixed) (Total:212.39 GB) (Free:22.43 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive z: (DiskAndRemoteBackups) (Fixed) (Total:1862.89 GB) (Free:96.4 GB) NTFS

Available physical RAM: 14668.98 MB
Total physical RAM: 16336.04 MB
Percentage of memory in use: 10%

==================== MBR and Partition Table ==================

Vhd Resizer (HKLM-x32\...\{8FAA57C5-7BD1-4285-B4B1-36D7337D7BE5}) (Version: 1.0.42 - Xcarab)
Disk: 0 (Size: 1863 GB) (Disk ID: 58ECB010)
Partition 1: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)
Disk: 1 (Size: 223.6 GB) (Disk ID: 50777930)
Partition 1: (Not Active) - (Size=212.4 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=11.2 GB) - (Type=83)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avira Antivirus (Enabled - Out of date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Out of date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)

  
***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Ruthan\Desktop" je 63 MB.
 
 
***** Startup Programs *****
 
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Programy\Adobe\Reader 9.0\Reader\Reader_sl.exe" 

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GalaxyClient
C:\Programs\GalaxyClient\GalaxyClient.exe /launchViaAutoStart [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Users\Ruthan\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [x]

 
***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    EnableFirewall    REG_DWORD    0x0
    DisableNotifications    REG_DWORD    0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    EnableFirewall    REG_DWORD    0x0
    DisableNotifications    REG_DWORD    0x0
    DoNotAllowExceptions    REG_DWORD    0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
 
***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

 
==================== End Of Log ==============================
