
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
kontrola logu chytil jsem trojana 2 stránky
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
kontrola logu chytil jsem trojana 2 stránky
Zdravím, prosím o kontrolu logu podařilo se mě chytit trojana. Dávám log z FRST a rovnou i AdwCleaneru
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016
Ran by Vitek (administrator) on VITEK-PC (15-04-2016 09:27:56)
Running from C:\Users\Vitek\Desktop
Loaded Profiles: Vitek (Available Profiles: Vitek)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSRService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-23] (NVIDIA Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-14] (AVAST Software)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [USB Safely Remove] => C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe [2468664 2013-03-13] (Crystal Rich Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [3931192 2016-03-26] (GOG.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-14] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{499A0B31-2460-439B-8906-899F1BEC8498}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131043123621972670&GUID=00000000-0000-0000-0000-000000000000
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {1D471673-7264-48B6-BB80-C994666E090B} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {7570738B-2C59-4B16-82E3-9561343343AB} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {75C2D683-8397-4749-9C4B-6BD774DA884B} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {A952281E-129E-4FCF-BBB8-D342E792185D} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {B52B511D-2CBA-4900-996B-8FB7992F92C3} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {E6CB1931-497E-4347-90C5-53B6A7626738} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-02] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-14] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-02] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-14] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: hxxp://www.yessearches.com/?ts=AHEpCH0sBXYnC0. ... ode=ffseng
FF DefaultSearchEngine: yessearches
FF SelectedSearchEngine: yessearches
FF Homepage: hxxps://www.seznam.cz/
FF Keyword.URL: hxxp://www.yessearches.com/chrome.php?uid=8C5E ... toolbar&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-03-27]
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-04]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-01-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.yessearches.com/?mode=nnnb&ptid=cos ... CH0sBXYnC0..
CHR StartupUrls: Default -> "hxxp://www.yessearches.com/?mode=nnnb&ptid=cos ... CH0sBXYnC0.."
CHR Profile: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-25]
CHR Extension: (Gmail) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-02]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-14] (AVAST Software)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [227896 2016-03-26] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6133816 2016-04-13] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-23] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-23] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-23] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-03-28] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-04-15] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [103736 2014-04-15] ()
R2 USBSafelyRemoveService; C:\Program Files (x86)\USB Safely Remove\USBSRService.exe [1521464 2013-03-13] (Crystal Rich Ltd)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 ggbugreport; "C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe" {154DFF63-3402-4815-941A-AAD63AE8B428} [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-14] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-03-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [464256 2016-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-14] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Marvell Semiconductor, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-12-31] () [File not signed]
U3 a7fo5lej; C:\Windows\System32\Drivers\a7fo5lej.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 usbbus; system32\DRIVERS\lgx64bus.sys [X]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-15 09:27 - 2016-04-15 09:28 - 00018771 _____ C:\Users\Vitek\Desktop\FRST.txt
2016-04-15 09:27 - 2016-04-15 09:27 - 00000000 ____D C:\FRST
2016-04-15 09:24 - 2016-04-15 09:25 - 02375168 _____ (Farbar) C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 09:23 - 2016-04-15 09:23 - 03677760 _____ C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 10:20 - 2016-04-04 20:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-04-13 10:20 - 2016-04-04 20:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-04-13 10:20 - 2016-04-02 15:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-04-13 10:20 - 2016-03-29 19:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-04-13 10:20 - 2016-03-23 16:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-04-13 10:20 - 2016-03-18 01:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 01:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-04-13 10:20 - 2016-03-18 01:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-04-13 10:20 - 2016-03-18 01:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-04-13 10:20 - 2016-03-18 01:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-13 10:20 - 2016-03-18 01:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-04-13 10:20 - 2016-03-18 00:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 10:20 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 00:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-04-13 10:20 - 2016-03-17 23:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-04-13 10:20 - 2016-03-17 23:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-04-13 10:20 - 2016-03-17 23:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-13 10:20 - 2016-03-17 23:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-04-13 10:20 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-04-13 10:20 - 2016-03-17 23:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-13 10:20 - 2016-03-17 23:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 10:20 - 2016-03-17 23:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-04-13 10:20 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-04-13 10:20 - 2016-03-16 20:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-04-13 10:20 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-04-13 10:20 - 2016-03-11 20:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-04-13 10:20 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 10:20 - 2016-02-05 20:56 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2016-04-13 10:20 - 2016-02-05 20:54 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-04-13 10:20 - 2016-02-05 19:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2016-04-13 10:20 - 2016-02-02 20:57 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-04-13 10:20 - 2016-01-21 02:51 - 00073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2016-04-13 10:20 - 2015-06-03 22:21 - 00451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-04-11 19:16 - 2016-04-11 19:16 - 00045776 _____ C:\Users\Vitek\Desktop\Agents of SHIELD - S03E15 Spacetime (AVS).srt
2016-04-11 19:16 - 2016-04-11 19:16 - 00045772 _____ C:\Users\Vitek\Desktop\Agents of SHIELD - S03E15 Spacetime (KILLERS).srt
2016-04-11 19:15 - 2016-04-06 18:28 - 365384658 _____ C:\Users\Vitek\Desktop\Marvels.Agents.of.S.H.I.E.L.D.S03E15.REPACK.HDTV.XviD-FUM.avi
2016-04-10 16:22 - 2016-04-10 16:30 - 564251581 _____ C:\Users\Vitek\Desktop\Survivor.S32E07.HDTV.x264-UAV.mp4
2016-04-10 16:21 - 2016-04-02 16:24 - 00055115 _____ C:\Users\Vitek\Desktop\Survivor.S32E07.HDTV.x264-UAV.srt
2016-04-07 13:04 - 2016-04-07 13:11 - 354084323 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.mp4
2016-04-07 13:03 - 2016-04-02 21:17 - 00053363 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.srt
2016-03-29 19:43 - 2016-03-29 19:51 - 00244810 _____ C:\Users\Vitek\Desktop\Daně Dana.xlsx
2016-03-29 19:43 - 2016-03-29 19:43 - 00238031 _____ C:\Users\Vitek\Desktop\Daňe Víťa.xlsx
2016-03-27 20:55 - 2016-03-27 20:55 - 00000000 ____D C:\Program Files (x86)\SearchesToYesbnd
2016-03-27 16:12 - 2016-03-27 16:12 - 00000000 ____D C:\Users\Vitek\Documents\PC Speed Maximizer
2016-03-27 15:56 - 2016-03-27 15:56 - 00000000 ____D C:\Users\Vitek\AppData\Local\CrashDumps
2016-03-27 15:56 - 2016-03-27 15:56 - 00000000 ____D C:\Program Files (x86)\Winsere
2016-03-27 15:55 - 2016-03-27 15:56 - 00000000 ____D C:\Users\Vitek\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-03-27 15:55 - 2016-03-27 15:55 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-03-27 15:55 - 2016-03-27 15:55 - 00000000 ____D C:\Program Files (x86)\WinTaske
2016-03-27 15:52 - 2013-10-27 15:58 - 00073728 _____ ( ) C:\Windows\system\vdremote.dll
2016-03-27 15:52 - 2013-10-27 15:58 - 00065536 _____ ( ) C:\Windows\system\vdsvrlnk.dll
2016-03-21 16:22 - 2016-03-21 16:22 - 00000000 ____D C:\Users\Vitek\Desktop\Army
2016-03-20 19:42 - 2016-03-21 10:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-15 09:16 - 2013-12-31 14:24 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-15 09:12 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-15 09:12 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-15 09:09 - 2013-12-31 13:00 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Seznam.cz
2016-04-15 09:04 - 2014-11-09 12:41 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\USBSafelyRemove
2016-04-15 09:04 - 2013-12-31 13:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-15 09:03 - 2013-12-31 13:18 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-15 09:03 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-14 19:34 - 2014-02-12 15:08 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-14 11:52 - 2011-04-12 10:34 - 00668866 _____ C:\Windows\system32\perfh005.dat
2016-04-14 11:52 - 2011-04-12 10:34 - 00141526 _____ C:\Windows\system32\perfc005.dat
2016-04-14 11:52 - 2009-07-14 07:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-14 11:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-14 11:46 - 2009-07-14 06:45 - 00417568 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-14 11:43 - 2014-12-11 22:58 - 00000000 ____D C:\Windows\system32\appraiser
2016-04-13 09:33 - 2014-03-23 17:45 - 00000000 ____D C:\Movie
2016-04-10 13:07 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Local\Battle.net
2016-04-10 10:07 - 2014-02-27 10:16 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-04-08 13:34 - 2014-02-12 15:08 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-08 13:34 - 2013-12-31 13:46 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-08 13:34 - 2013-12-31 13:46 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 13:13 - 2013-12-31 13:35 - 00000000 ____D C:\Program Files (x86)\Google
2016-04-07 12:46 - 2014-01-21 20:17 - 00000000 ____D C:\Hudba
2016-04-05 17:36 - 2015-05-20 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-04-04 20:14 - 2013-12-31 13:16 - 01559268 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-04-02 11:06 - 2014-01-05 18:58 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-03-28 13:16 - 2014-11-25 13:27 - 00000000 ____D C:\ProgramData\Origin
2016-03-28 13:15 - 2014-11-25 13:26 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-27 19:53 - 2013-12-31 12:58 - 00001873 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-27 19:53 - 2013-12-31 12:58 - 00001861 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-27 19:22 - 2016-03-14 11:25 - 00000000 ____D C:\Program Files (x86)\Gabest
2016-03-27 15:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2016-03-27 14:24 - 2015-05-20 11:16 - 00000000 ____D C:\Users\Vitek\Documents\The Witcher 3
2016-03-26 11:58 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Battle.net
2016-03-26 11:58 - 2014-01-05 18:57 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-25 11:15 - 2014-11-25 14:53 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2016-03-23 13:05 - 2014-01-03 21:50 - 00000000 ____D C:\Users\Vitek\Desktop\Práce
2016-03-21 16:32 - 2016-03-14 18:20 - 00000000 ____D C:\Users\Vitek\Desktop\Nová složka (2)
2016-03-21 16:23 - 2014-07-01 12:55 - 00000000 ____D C:\Users\Vitek\Desktop\Mamka
2016-03-21 16:22 - 2015-11-16 10:45 - 00000000 ____D C:\Users\Vitek\Desktop\Běh treninky
2016-03-21 16:22 - 2015-09-03 19:25 - 00000000 ____D C:\Users\Vitek\Desktop\Brácha
2016-03-21 14:04 - 2013-12-31 13:55 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Skype
2016-03-21 10:29 - 2013-12-31 12:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2014-08-03 11:14 - 2014-08-03 11:14 - 0000135 _____ () C:\Users\Vitek\AppData\Roaming\default.rss
2014-09-11 12:20 - 2014-09-11 12:20 - 0000001 _____ () C:\Users\Vitek\AppData\Local\llftool.4.40.agreement
2016-03-05 12:33 - 2016-03-05 12:33 - 0029696 _____ () C:\Users\Vitek\AppData\Local\MSGBOX.EXE
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 09:30
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016
Ran by Vitek (administrator) on VITEK-PC (15-04-2016 09:27:56)
Running from C:\Users\Vitek\Desktop
Loaded Profiles: Vitek (Available Profiles: Vitek)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSRService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-23] (NVIDIA Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-14] (AVAST Software)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [USB Safely Remove] => C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe [2468664 2013-03-13] (Crystal Rich Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [3931192 2016-03-26] (GOG.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-14] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{499A0B31-2460-439B-8906-899F1BEC8498}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131043123621972670&GUID=00000000-0000-0000-0000-000000000000
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {1D471673-7264-48B6-BB80-C994666E090B} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {7570738B-2C59-4B16-82E3-9561343343AB} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {75C2D683-8397-4749-9C4B-6BD774DA884B} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {A952281E-129E-4FCF-BBB8-D342E792185D} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {B52B511D-2CBA-4900-996B-8FB7992F92C3} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {E6CB1931-497E-4347-90C5-53B6A7626738} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-02] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-14] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-02] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-14] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: hxxp://www.yessearches.com/?ts=AHEpCH0sBXYnC0. ... ode=ffseng
FF DefaultSearchEngine: yessearches
FF SelectedSearchEngine: yessearches
FF Homepage: hxxps://www.seznam.cz/
FF Keyword.URL: hxxp://www.yessearches.com/chrome.php?uid=8C5E ... toolbar&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-03-27]
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-04]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-01-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.yessearches.com/?mode=nnnb&ptid=cos ... CH0sBXYnC0..
CHR StartupUrls: Default -> "hxxp://www.yessearches.com/?mode=nnnb&ptid=cos ... CH0sBXYnC0.."
CHR Profile: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-25]
CHR Extension: (Gmail) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-02]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-14] (AVAST Software)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [227896 2016-03-26] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6133816 2016-04-13] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-23] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-23] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-23] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-03-28] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-04-15] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [103736 2014-04-15] ()
R2 USBSafelyRemoveService; C:\Program Files (x86)\USB Safely Remove\USBSRService.exe [1521464 2013-03-13] (Crystal Rich Ltd)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 ggbugreport; "C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe" {154DFF63-3402-4815-941A-AAD63AE8B428} [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-14] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-03-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [464256 2016-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-14] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Marvell Semiconductor, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-12-31] () [File not signed]
U3 a7fo5lej; C:\Windows\System32\Drivers\a7fo5lej.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 usbbus; system32\DRIVERS\lgx64bus.sys [X]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-15 09:27 - 2016-04-15 09:28 - 00018771 _____ C:\Users\Vitek\Desktop\FRST.txt
2016-04-15 09:27 - 2016-04-15 09:27 - 00000000 ____D C:\FRST
2016-04-15 09:24 - 2016-04-15 09:25 - 02375168 _____ (Farbar) C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 09:23 - 2016-04-15 09:23 - 03677760 _____ C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 10:20 - 2016-04-04 20:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-04-13 10:20 - 2016-04-04 20:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-04-13 10:20 - 2016-04-02 15:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-04-13 10:20 - 2016-03-29 19:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-04-13 10:20 - 2016-03-23 16:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-04-13 10:20 - 2016-03-18 01:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 01:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-04-13 10:20 - 2016-03-18 01:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-04-13 10:20 - 2016-03-18 01:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-04-13 10:20 - 2016-03-18 01:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-13 10:20 - 2016-03-18 01:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-04-13 10:20 - 2016-03-18 00:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 10:20 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 00:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-04-13 10:20 - 2016-03-17 23:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-04-13 10:20 - 2016-03-17 23:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-04-13 10:20 - 2016-03-17 23:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-13 10:20 - 2016-03-17 23:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-04-13 10:20 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-04-13 10:20 - 2016-03-17 23:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-13 10:20 - 2016-03-17 23:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 10:20 - 2016-03-17 23:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-04-13 10:20 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-04-13 10:20 - 2016-03-16 20:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-04-13 10:20 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-04-13 10:20 - 2016-03-11 20:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-04-13 10:20 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 10:20 - 2016-02-05 20:56 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2016-04-13 10:20 - 2016-02-05 20:54 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-04-13 10:20 - 2016-02-05 19:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2016-04-13 10:20 - 2016-02-02 20:57 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-04-13 10:20 - 2016-01-21 02:51 - 00073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2016-04-13 10:20 - 2015-06-03 22:21 - 00451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-04-11 19:16 - 2016-04-11 19:16 - 00045776 _____ C:\Users\Vitek\Desktop\Agents of SHIELD - S03E15 Spacetime (AVS).srt
2016-04-11 19:16 - 2016-04-11 19:16 - 00045772 _____ C:\Users\Vitek\Desktop\Agents of SHIELD - S03E15 Spacetime (KILLERS).srt
2016-04-11 19:15 - 2016-04-06 18:28 - 365384658 _____ C:\Users\Vitek\Desktop\Marvels.Agents.of.S.H.I.E.L.D.S03E15.REPACK.HDTV.XviD-FUM.avi
2016-04-10 16:22 - 2016-04-10 16:30 - 564251581 _____ C:\Users\Vitek\Desktop\Survivor.S32E07.HDTV.x264-UAV.mp4
2016-04-10 16:21 - 2016-04-02 16:24 - 00055115 _____ C:\Users\Vitek\Desktop\Survivor.S32E07.HDTV.x264-UAV.srt
2016-04-07 13:04 - 2016-04-07 13:11 - 354084323 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.mp4
2016-04-07 13:03 - 2016-04-02 21:17 - 00053363 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.srt
2016-03-29 19:43 - 2016-03-29 19:51 - 00244810 _____ C:\Users\Vitek\Desktop\Daně Dana.xlsx
2016-03-29 19:43 - 2016-03-29 19:43 - 00238031 _____ C:\Users\Vitek\Desktop\Daňe Víťa.xlsx
2016-03-27 20:55 - 2016-03-27 20:55 - 00000000 ____D C:\Program Files (x86)\SearchesToYesbnd
2016-03-27 16:12 - 2016-03-27 16:12 - 00000000 ____D C:\Users\Vitek\Documents\PC Speed Maximizer
2016-03-27 15:56 - 2016-03-27 15:56 - 00000000 ____D C:\Users\Vitek\AppData\Local\CrashDumps
2016-03-27 15:56 - 2016-03-27 15:56 - 00000000 ____D C:\Program Files (x86)\Winsere
2016-03-27 15:55 - 2016-03-27 15:56 - 00000000 ____D C:\Users\Vitek\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-03-27 15:55 - 2016-03-27 15:55 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-03-27 15:55 - 2016-03-27 15:55 - 00000000 ____D C:\Program Files (x86)\WinTaske
2016-03-27 15:52 - 2013-10-27 15:58 - 00073728 _____ ( ) C:\Windows\system\vdremote.dll
2016-03-27 15:52 - 2013-10-27 15:58 - 00065536 _____ ( ) C:\Windows\system\vdsvrlnk.dll
2016-03-21 16:22 - 2016-03-21 16:22 - 00000000 ____D C:\Users\Vitek\Desktop\Army
2016-03-20 19:42 - 2016-03-21 10:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-15 09:16 - 2013-12-31 14:24 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-15 09:12 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-15 09:12 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-15 09:09 - 2013-12-31 13:00 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Seznam.cz
2016-04-15 09:04 - 2014-11-09 12:41 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\USBSafelyRemove
2016-04-15 09:04 - 2013-12-31 13:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-15 09:03 - 2013-12-31 13:18 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-15 09:03 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-14 19:34 - 2014-02-12 15:08 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-14 11:52 - 2011-04-12 10:34 - 00668866 _____ C:\Windows\system32\perfh005.dat
2016-04-14 11:52 - 2011-04-12 10:34 - 00141526 _____ C:\Windows\system32\perfc005.dat
2016-04-14 11:52 - 2009-07-14 07:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-14 11:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-14 11:46 - 2009-07-14 06:45 - 00417568 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-14 11:43 - 2014-12-11 22:58 - 00000000 ____D C:\Windows\system32\appraiser
2016-04-13 09:33 - 2014-03-23 17:45 - 00000000 ____D C:\Movie
2016-04-10 13:07 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Local\Battle.net
2016-04-10 10:07 - 2014-02-27 10:16 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-04-08 13:34 - 2014-02-12 15:08 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-08 13:34 - 2013-12-31 13:46 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-08 13:34 - 2013-12-31 13:46 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 13:13 - 2013-12-31 13:35 - 00000000 ____D C:\Program Files (x86)\Google
2016-04-07 12:46 - 2014-01-21 20:17 - 00000000 ____D C:\Hudba
2016-04-05 17:36 - 2015-05-20 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-04-04 20:14 - 2013-12-31 13:16 - 01559268 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-04-02 11:06 - 2014-01-05 18:58 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-03-28 13:16 - 2014-11-25 13:27 - 00000000 ____D C:\ProgramData\Origin
2016-03-28 13:15 - 2014-11-25 13:26 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-27 19:53 - 2013-12-31 12:58 - 00001873 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-27 19:53 - 2013-12-31 12:58 - 00001861 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-27 19:22 - 2016-03-14 11:25 - 00000000 ____D C:\Program Files (x86)\Gabest
2016-03-27 15:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2016-03-27 14:24 - 2015-05-20 11:16 - 00000000 ____D C:\Users\Vitek\Documents\The Witcher 3
2016-03-26 11:58 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Battle.net
2016-03-26 11:58 - 2014-01-05 18:57 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-25 11:15 - 2014-11-25 14:53 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2016-03-23 13:05 - 2014-01-03 21:50 - 00000000 ____D C:\Users\Vitek\Desktop\Práce
2016-03-21 16:32 - 2016-03-14 18:20 - 00000000 ____D C:\Users\Vitek\Desktop\Nová složka (2)
2016-03-21 16:23 - 2014-07-01 12:55 - 00000000 ____D C:\Users\Vitek\Desktop\Mamka
2016-03-21 16:22 - 2015-11-16 10:45 - 00000000 ____D C:\Users\Vitek\Desktop\Běh treninky
2016-03-21 16:22 - 2015-09-03 19:25 - 00000000 ____D C:\Users\Vitek\Desktop\Brácha
2016-03-21 14:04 - 2013-12-31 13:55 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Skype
2016-03-21 10:29 - 2013-12-31 12:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2014-08-03 11:14 - 2014-08-03 11:14 - 0000135 _____ () C:\Users\Vitek\AppData\Roaming\default.rss
2014-09-11 12:20 - 2014-09-11 12:20 - 0000001 _____ () C:\Users\Vitek\AppData\Local\llftool.4.40.agreement
2016-03-05 12:33 - 2016-03-05 12:33 - 0029696 _____ () C:\Users\Vitek\AppData\Local\MSGBOX.EXE
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 09:30
==================== End of FRST.txt ============================
Re: kontrola logu chytil jsem trojana 2 stránky
AdwCleaner
# AdwCleaner v5.111 - Log soubor vytvořen 15/04/2016 o 09:40:12
# Aktualizováno 14/04/2016 by Xplode
# Databáze : 2016-04-11.4 [Server]
# Operační systém : Windows 7 Professional Service Pack 1 (X64)
# Jméno uživatele : Vitek - VITEK-PC
# Spuštěno z : C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
# Volba : Čištění
# Podpora : http://toolslib.net/forum
***** [ Služby ] *****
[-] Služba smazáno : ggbugreport
***** [ Složky ] *****
[-] Složka smazáno : C:\Program Files (x86)\SearchesToYesbnd
[-] Složka smazáno : C:\Program Files (x86)\Winsere
[-] Složka smazáno : C:\Program Files (x86)\WinTaske
[-] Složka smazáno : C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\YourGSearchFinder_br
[-] Složka smazáno : C:\Users\Vitek\Documents\PC Speed Maximizer
***** [ Soubory ] *****
[-] Soubor smazáno : C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\dd1b66d4.xml
***** [ DLLs ] *****
***** [ Zástupci ] *****
***** [ Naplánované úkoly ] *****
[-] Úkol smazáno : WinTaske
***** [ Registr ] *****
[-] Klávesa smazáno : HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Klávesa smazáno : HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Klávesa smazáno : HKCU\Software\Conduit
[-] Klávesa smazáno : HKLM\SOFTWARE\yessearchesSoftware
***** [ Webové prohlížeče ] *****
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.newtab.url", "hxxp://www.yessearches.com/?ts=AHEpCH0sBXYnC0. ... ode=ffseng");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.defaultenginename", "yessearches");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.searchengine.hp", "hxxp://www.yessearches.com/?ts=AHEpCH0sBXYnC0. ... =ffsengext");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.searchengine.sp", "hxxp://www.yessearches.com/chrome.php?mode=ffs ... v=20160323");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.searchengine.url", "hxxp://www.yessearches.com/chrome.php?mode=ffs ... v=20160323");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.selectedEngine", "yessearches");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "45.0");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=782a37cf");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016032719");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1459101251158");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"cs\",\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"ja\",\"en\"],\"defaultLocale\":\"en\",\"supp[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.shownUninstall", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.startupTasks", "{\"clearPrefs\":[\"extensions.toolbar.mindspark._brMembers_.shownUninstall\"],\"undoDisableHPGuard\":[\"true\"]}");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "hxxp://www.yessearches.com/chrome.php?uid=8C5E ... ttoolbar&q[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"filesToDelete\":[\"C:\\\\Users\\\\Vitek\\\\AppData\\\\[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("keyword.URL", "hxxp://www.yessearches.com/chrome.php?uid=8C5E ... toolbar&q=");
*************************
:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno
:: Chrome preferences reset : C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [8262 bytes] - [15/04/2016 09:40:12]
C:\AdwCleaner\AdwCleaner[S1].txt - [8130 bytes] - [15/04/2016 09:38:32]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [8408 bytes] ##########
# AdwCleaner v5.111 - Log soubor vytvořen 15/04/2016 o 09:40:12
# Aktualizováno 14/04/2016 by Xplode
# Databáze : 2016-04-11.4 [Server]
# Operační systém : Windows 7 Professional Service Pack 1 (X64)
# Jméno uživatele : Vitek - VITEK-PC
# Spuštěno z : C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
# Volba : Čištění
# Podpora : http://toolslib.net/forum
***** [ Služby ] *****
[-] Služba smazáno : ggbugreport
***** [ Složky ] *****
[-] Složka smazáno : C:\Program Files (x86)\SearchesToYesbnd
[-] Složka smazáno : C:\Program Files (x86)\Winsere
[-] Složka smazáno : C:\Program Files (x86)\WinTaske
[-] Složka smazáno : C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\YourGSearchFinder_br
[-] Složka smazáno : C:\Users\Vitek\Documents\PC Speed Maximizer
***** [ Soubory ] *****
[-] Soubor smazáno : C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\dd1b66d4.xml
***** [ DLLs ] *****
***** [ Zástupci ] *****
***** [ Naplánované úkoly ] *****
[-] Úkol smazáno : WinTaske
***** [ Registr ] *****
[-] Klávesa smazáno : HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Klávesa smazáno : HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Klávesa smazáno : HKCU\Software\Conduit
[-] Klávesa smazáno : HKLM\SOFTWARE\yessearchesSoftware
***** [ Webové prohlížeče ] *****
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.newtab.url", "hxxp://www.yessearches.com/?ts=AHEpCH0sBXYnC0. ... ode=ffseng");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.defaultenginename", "yessearches");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.searchengine.hp", "hxxp://www.yessearches.com/?ts=AHEpCH0sBXYnC0. ... =ffsengext");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.searchengine.sp", "hxxp://www.yessearches.com/chrome.php?mode=ffs ... v=20160323");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.searchengine.url", "hxxp://www.yessearches.com/chrome.php?mode=ffs ... v=20160323");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("browser.search.selectedEngine", "yessearches");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "45.0");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=782a37cf");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016032719");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1459101251158");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"cs\",\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"ja\",\"en\"],\"defaultLocale\":\"en\",\"supp[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.shownUninstall", true);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.startupTasks", "{\"clearPrefs\":[\"extensions.toolbar.mindspark._brMembers_.shownUninstall\"],\"undoDisableHPGuard\":[\"true\"]}");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "hxxp://www.yessearches.com/chrome.php?uid=8C5E ... ttoolbar&q[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"filesToDelete\":[\"C:\\\\Users\\\\Vitek\\\\AppData\\\\[...]
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com");
[-] [C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] smazáno : user_pref("keyword.URL", "hxxp://www.yessearches.com/chrome.php?uid=8C5E ... toolbar&q=");
*************************
:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno
:: Chrome preferences reset : C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [8262 bytes] - [15/04/2016 09:40:12]
C:\AdwCleaner\AdwCleaner[S1].txt - [8130 bytes] - [15/04/2016 09:38:32]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [8408 bytes] ##########
Re: kontrola logu chytil jsem trojana 2 stránky
ahoj,
vykonaj oba kroky >> http://forum.viry.cz/viewtopic.php?f=13 ... e#p1443946
vykonaj oba kroky >> http://forum.viry.cz/viewtopic.php?f=13 ... e#p1443946
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: kontrola logu chytil jsem trojana 2 stránky
Jak dlouho asi pracuje ten zoek? Pustil jsem ho 2x pokaždé
po 2 hodinách a vždy minimálně hodinu stojí na místě a nic nedělá. Tak to se mě to vždy zastaví.
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Vitek on p 15.04.2016 at 14:25:32,59.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vitek\Desktop\zoek.exe [Scan all users] [Script inserted]
===== Runcheck 14:27:41,50 =====
--- Create Environment Variables 14:27:43,49
--- Checking Input 14:27:57,72
--- Reset Hosts File 14:28:37,05
--- AU AppData Check 14:28:37,96
--- Remove From Windows Installer 14:28:43,92
--- Registry HKLM Software Check 14:30:33,21
--- Quick Launch Shortcut Check 14:30:56,38
--- IE Startpage Check 14:31:03,88
--- Program Files DB Check 14:32:42,53
--- C:\Users\Default\AppData\Roaming DB Check 14:34:20,66
--- C:\Users\Default User\AppData\Roaming DB Check 14:34:20,66
--- C:\Users\Vitek\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 14:34:20,66
--- C:\Users\Vitek DB Check 14:39:20,02
--- C:\PROGRA~3 DB Check 14:39:57,12
--- C:\Users\Default\AppData\Local DB Check 14:40:24,76
--- C:\Users\Default User\AppData\Local DB Check 14:40:24,76
--- C:\Users\Vitek\AppData\Local DB Check 14:40:24,76
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 14:40:24,76
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 14:40:24,76
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 14:40:24,76
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 14:40:24,76
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 14:43:48,77
--- C:\Users\Vitek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 14:44:10,90
--- Tasks DB Check 14:44:24,92
--- Downloads DB Check 14:44:34,07
--- C:\Users\Vitek\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 14:44:42,44
--- Tasks2 DB Check 14:46:23,56
--- Documents DB Check 14:47:32,68
--- C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1 DB Check 14:47:49,26
--- C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default DB Check 14:47:49,26
--- C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F DB Check 14:47:49,26
--- C:\Users\Public\Desktop DB Check 14:48:05,17
--- C:\Users\Vitek\Desktop DB Check 14:48:17,18
--- Services DB Check 14:48:36,68
--- FF prefs.js DB Check 14:49:13,90
--- Emptyclsid 14:53:14,58
--- Del by CLSID 14:53:17,88
--- Delete Services 14:53:49,08
--- Firefox Fix 14:53:53,52
--- Firefox Extensions 14:54:07,07
po 2 hodinách a vždy minimálně hodinu stojí na místě a nic nedělá. Tak to se mě to vždy zastaví.
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Vitek on p 15.04.2016 at 14:25:32,59.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vitek\Desktop\zoek.exe [Scan all users] [Script inserted]
===== Runcheck 14:27:41,50 =====
--- Create Environment Variables 14:27:43,49
--- Checking Input 14:27:57,72
--- Reset Hosts File 14:28:37,05
--- AU AppData Check 14:28:37,96
--- Remove From Windows Installer 14:28:43,92
--- Registry HKLM Software Check 14:30:33,21
--- Quick Launch Shortcut Check 14:30:56,38
--- IE Startpage Check 14:31:03,88
--- Program Files DB Check 14:32:42,53
--- C:\Users\Default\AppData\Roaming DB Check 14:34:20,66
--- C:\Users\Default User\AppData\Roaming DB Check 14:34:20,66
--- C:\Users\Vitek\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 14:34:20,66
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 14:34:20,66
--- C:\Users\Vitek DB Check 14:39:20,02
--- C:\PROGRA~3 DB Check 14:39:57,12
--- C:\Users\Default\AppData\Local DB Check 14:40:24,76
--- C:\Users\Default User\AppData\Local DB Check 14:40:24,76
--- C:\Users\Vitek\AppData\Local DB Check 14:40:24,76
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 14:40:24,76
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 14:40:24,76
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 14:40:24,76
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 14:40:24,76
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 14:43:48,77
--- C:\Users\Vitek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 14:44:10,90
--- Tasks DB Check 14:44:24,92
--- Downloads DB Check 14:44:34,07
--- C:\Users\Vitek\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 14:44:42,44
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 14:44:42,44
--- Tasks2 DB Check 14:46:23,56
--- Documents DB Check 14:47:32,68
--- C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1 DB Check 14:47:49,26
--- C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default DB Check 14:47:49,26
--- C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F DB Check 14:47:49,26
--- C:\Users\Public\Desktop DB Check 14:48:05,17
--- C:\Users\Vitek\Desktop DB Check 14:48:17,18
--- Services DB Check 14:48:36,68
--- FF prefs.js DB Check 14:49:13,90
--- Emptyclsid 14:53:14,58
--- Del by CLSID 14:53:17,88
--- Delete Services 14:53:49,08
--- Firefox Fix 14:53:53,52
--- Firefox Extensions 14:54:07,07
Re: kontrola logu chytil jsem trojana 2 stránky
Tak už se mě to podařilo dokončit zde je log zoek
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Vitek on p 15.04.2016 at 18:53:10,49.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vitek\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used]
==== Older Logs ======================
C:\zoek-results2016-04-15-104306.log 10271 bytes
C:\zoek-results2016-04-15-125407.log 4366 bytes
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultenginename", "yessearches");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.04.2016_1921_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.04.2016_1921_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.04.2016_1921_.backup
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\Vitek\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2016-04-13 08:20:45 C86AFCDD4584CFDF7B57335FEC7546E4 111616 ----a-w- C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 08:20:45 936AF75B1A7A663C24F999029A84142C 176128 ----a-w- C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 08:20:37 D25FCA441C69C3E6E78DE1BBCBF97BBC 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 08:20:37 8007E4C5C9B40FB30F816F6E74284DF1 1240576 ----a-w- C:\Windows\SysWOW64\msxml3.dll
2016-04-13 08:20:34 E518B37F8C82A4320732352E4DA9BF41 1414144 ----a-w- C:\Windows\SysWOW64\ole32.dll
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:33 40A0F37C85DFA5D6E963FFD496439661 1314112 ----a-w- C:\Windows\SysWOW64\ntdll.dll
2016-04-13 08:20:32 F7DF39F60CCB70AD4551BAC41C18ACA1 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll
2016-04-13 08:20:32 E8618EF4CB8D38462D4D8A4ED7DA9850 171520 ----a-w- C:\Windows\SysWOW64\wdigest.dll
2016-04-13 08:20:32 C8AE40931A2AC87E30E05C75E4A61796 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll
2016-04-13 08:20:32 B782F44A047D0D9459F0078A98AA8542 36352 ----a-w- C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 08:20:32 B52C499A81A73E8F74938ACA42734331 275456 ----a-w- C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 08:20:32 AAF65CD3A15EF6ECB0F4EF32F0D461B8 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 08:20:32 A3ECF0CFA0BFE509A77F0514885EA608 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll
2016-04-13 08:20:32 9F55E7A647A793A4D8C89A32B9543799 644096 ----a-w- C:\Windows\SysWOW64\advapi32.dll
2016-04-13 08:20:32 972332B4F1AC8EF3A42AE45BF65D3B60 141312 ----a-w- C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 88B9000A87883C908F927AF5036B8309 223232 ----a-w- C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 08:20:32 6B69810EDAEBBC68B205F5BBFD625E84 553984 ----a-w- C:\Windows\SysWOW64\kerberos.dll
2016-04-13 08:20:32 6B0E139FEF3B7C0061983C1502AE0CA3 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll
2016-04-13 08:20:32 47B6BE9CDF6888B7F9FDC5B2DB41B107 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 08:20:32 405B50ED43C2D73B32056168494DEA24 666112 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 08:20:32 361F32EEFC326C7D34CD2CCF05C469FC 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll
2016-04-13 08:20:32 28B998D3ACC5AF930B78A982B4698CB8 260608 ----a-w- C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 08:20:32 2610C8EF506344326F7250691093A3B9 251392 ----a-w- C:\Windows\SysWOW64\schannel.dll
2016-04-13 08:20:32 2347F9D5227F8751527C0AA0CDBA7375 342528 ----a-w- C:\Windows\SysWOW64\certcli.dll
2016-04-13 08:20:32 19E838D8DD2CB5576707259C8281EA78 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll
2016-04-13 08:20:32 002E17D37479281C5D241A189F973C5F 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 F5042159B95FD2748F55D89E08A89B48 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:28 4DD90351DB68847F9048133E45004B2F 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll
2016-04-13 08:20:28 38958A47AEE19E4CD89A0850640217C3 690688 ----a-w- C:\Windows\SysWOW64\adtschema.dll
2016-04-13 08:20:28 1FCAFC14E7B1BA3569DD1E483E486998 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 08:20:15 C2E392F3CE66FE21ADB7CA1158790BAA 15360 ----a-w- C:\Windows\SysWOW64\tbs.dll
2016-04-13 08:20:07 795F356F6027FCA3FD4AD5F3CCD904B7 60416 ----a-w- C:\Windows\SysWOW64\samlib.dll
2016-04-13 08:20:04 386E748E484BA802FCCBF00FC90729C4 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2016-04-13 08:20:46 A575C471CCFC7CBF32F446FA305E7341 156672 ----a-w- C:\Windows\Sysnative\mtxoci.dll
2016-04-13 08:20:38 622C96AFB07BB82C8650B47172137AC4 511488 ----a-w- C:\Windows\Sysnative\rpcss.dll
2016-04-13 08:20:37 F8A05F48B79CB5C087F089BA6C0659FB 1885696 ----a-w- C:\Windows\Sysnative\msxml3.dll
2016-04-13 08:20:37 D303AC584429678DB27DEBD4282CA1DF 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll
2016-04-13 08:20:35 10F466EF4048CA32CAF98FE4A3A16982 2084864 ----a-w- C:\Windows\Sysnative\ole32.dll
2016-04-13 08:20:34 7BE74B8A4BA6D27137E5557229EB83E3 631176 ----a-w- C:\Windows\Sysnative\winresume.efi
2016-04-13 08:20:34 6FCB62DDF2575ADFFD577A6648B25377 1464320 ----a-w- C:\Windows\Sysnative\lsasrv.dll
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe
2016-04-13 08:20:33 7AE8440A7C8B7E7078EE2654DDB8D21F 1732864 ----a-w- C:\Windows\Sysnative\ntdll.dll
2016-04-13 08:20:33 5817A07A72436A5658E48BF98A91137D 706280 ----a-w- C:\Windows\Sysnative\winload.efi
2016-04-13 08:20:32 EF34A098DD383766689A2F21BA2A990E 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll
2016-04-13 08:20:32 CB7E479501BC4C55328D242D41C1D074 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll
2016-04-13 08:20:32 C9F6BB175A7392A851FD86F2A3359088 463872 ----a-w- C:\Windows\Sysnative\certcli.dll
2016-04-13 08:20:32 C47B6624AF9AEE4146743DCB133A159D 34816 ----a-w- C:\Windows\Sysnative\appidsvc.dll
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe
2016-04-13 08:20:32 BEAD4B03B375B8F02C8C205E25A7CF0A 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll
2016-04-13 08:20:32 B46D03BABD31B23E6FCB226CB22D4D6B 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll
2016-04-13 08:20:32 B3A62D12B93A49189EA8CE51D186FC61 880640 ----a-w- C:\Windows\Sysnative\advapi32.dll
2016-04-13 08:20:32 AE9981D722DA386FBDDC78BEE6E41E56 419840 ----a-w- C:\Windows\Sysnative\KernelBase.dll
2016-04-13 08:20:32 9D8F5EBE48750AF80C5EB5542BEC448B 59904 ----a-w- C:\Windows\Sysnative\appidapi.dll
2016-04-13 08:20:32 9C73710485E2E1540D869BDB8A8A68CA 43520 ----a-w- C:\Windows\Sysnative\cryptbase.dll
2016-04-13 08:20:32 97C1D81250E9E73F7FC8568EF622017A 22016 ----a-w- C:\Windows\Sysnative\credssp.dll
2016-04-13 08:20:32 841BF993597DCD498247684B5D3AE845 215552 ----a-w- C:\Windows\Sysnative\winsrv.dll
2016-04-13 08:20:32 81AA2961530A4F036046CC627B4A90BC 28160 ----a-w- C:\Windows\Sysnative\secur32.dll
2016-04-13 08:20:32 811D9D4242A3E53D6DA86A400CCD63D0 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll
2016-04-13 08:20:32 7F9ADD80DE0B27B5EF2ACA7B19EAA3E5 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll
2016-04-13 08:20:32 7BBBB5DE05EFEEF2E45A48F9A943B6B0 243712 ----a-w- C:\Windows\Sysnative\wow64.dll
2016-04-13 08:20:32 77372D87A1A5E170C366E436990C6CB5 312320 ----a-w- C:\Windows\Sysnative\ncrypt.dll
2016-04-13 08:20:32 7407A5C092DAD554A3FC768B9859A847 210432 ----a-w- C:\Windows\Sysnative\wdigest.dll
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\Sysnative\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\Sysnative\lsass.exe
2016-04-13 08:20:32 6199722CB619A0887BE81F16A4474538 190464 ----a-w- C:\Windows\Sysnative\rpchttp.dll
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe
2016-04-13 08:20:32 593BC0F0D33A1905B5DC37FA756EB2BA 50176 ----a-w- C:\Windows\Sysnative\srclient.dll
2016-04-13 08:20:32 54D7B147EB4E7691AA5A2FA110A38363 1212928 ----a-w- C:\Windows\Sysnative\rpcrt4.dll
2016-04-13 08:20:32 4F374ED543FC9F3BB17EC6A7C8DF39A1 344064 ----a-w- C:\Windows\Sysnative\schannel.dll
2016-04-13 08:20:32 487D19B284DAFCBAE811AE785CC8B603 731136 ----a-w- C:\Windows\Sysnative\kerberos.dll
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\Sysnative\conhost.exe
2016-04-13 08:20:32 3B44D778B4719B1D5650FC6B1D90AA19 503808 ----a-w- C:\Windows\Sysnative\srcore.dll
2016-04-13 08:20:32 3B38C2EDA0D4854ED0E72BA3CBE8D72E 316416 ----a-w- C:\Windows\Sysnative\msv1_0.dll
2016-04-13 08:20:32 3A2DF0CC19D68C60F434DA02E1ED01B3 28672 ----a-w- C:\Windows\Sysnative\sspisrv.dll
2016-04-13 08:20:32 2D99A0ECE8475367798F1313197C933D 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe
2016-04-13 08:20:32 0CBD4E2DBBADABB79BFB8289E6E6227F 135680 ----a-w- C:\Windows\Sysnative\sspicli.dll
2016-04-13 08:20:28 DB651F0E6AC20C42348A9F0E8E7C42D5 690688 ----a-w- C:\Windows\Sysnative\adtschema.dll
2016-04-13 08:20:28 800AA696A0A773C039D1568F5828EFDE 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll
2016-04-13 08:20:28 6A019F8581D13BC1637DF9F2C92849DB 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll
2016-04-13 08:20:28 3D347AF86D2FDDEC5F30844537C355D1 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\Sysnative\win32k.sys
2016-04-13 08:20:15 D99F8968C0C5CAD46A6B93A1FA6738B2 109568 ----a-w- C:\Windows\Sysnative\fveapibase.dll
2016-04-13 08:20:15 D1035B8EFC83165612F7AAB1816A81B4 451080 ----a-w- C:\Windows\Sysnative\fveapi.dll
2016-04-13 08:20:15 8F39E301AD8B219DADF83BD7DBE9842E 20480 ----a-w- C:\Windows\Sysnative\tbs.dll
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe
2016-04-13 08:20:10 9282C7B69C15B072A9D9F9EDE0AA9C40 1169408 ----a-w- C:\Windows\Sysnative\aeinv.dll
2016-04-13 08:20:10 6E613496CC7CFAD37FA3D1EA86229A26 76800 ----a-w- C:\Windows\Sysnative\acmigration.dll
2016-04-13 08:20:10 4AAF4B88EDABA4CA3ACA82C1A248A3F4 279040 ----a-w- C:\Windows\Sysnative\invagent.dll
2016-04-13 08:20:10 453EEF8F903DE266D9CB16313B5FA796 215040 ----a-w- C:\Windows\Sysnative\aepic.dll
2016-04-13 08:20:10 2A0822070B416170A690D5E061194907 698368 ----a-w- C:\Windows\Sysnative\generaltel.dll
2016-04-13 08:20:10 2816C405CD465CB1D3559D017284FD31 1386496 ----a-w- C:\Windows\Sysnative\appraiser.dll
2016-04-13 08:20:10 24AAC7624C0114C5DAC7DA794D38E18A 499200 ----a-w- C:\Windows\Sysnative\devinv.dll
2016-04-13 08:20:07 C91E969FDEB819E63E7D6BECF5A8B8D0 106496 ----a-w- C:\Windows\Sysnative\samlib.dll
2016-04-13 08:20:07 48AF282E07C70E053D4E3EE2C732AD0D 760320 ----a-w- C:\Windows\Sysnative\samsrv.dll
2016-04-13 08:20:04 83250E0CE090E705B826C17F3345C758 2048 ----a-w- C:\Windows\Sysnative\tzres.dll
====== C:\Windows\Sysnative\drivers =====
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\Sysnative\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\Sysnative\drivers\disk.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
======= C: =====
====== C:\Users\Vitek\AppData\Roaming ======
2016-03-27 13:56:43 -------- d-----w- C:\Users\Vitek\AppData\Local\CrashDumps
====== C:\Users\Vitek ======
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
====== C: exe-files ==
2016-04-15 14:08:55 D1C9F7E9FA346B9BA4A96D4A3B2EC42C 1039928 ----a-w- C:\ProgramData\GOG.com\Galaxy\temp\desktop-galaxy-updater\GalaxyUpdater.exe
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 12:23:22 496DE87E5E6D1F46C5FD7A0AA6EAB8CF 7720424 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\Packages\00008959\DAO.20637995.exe
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\System32\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\System32\rstrui.exe
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\System32\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\System32\lsass.exe
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\System32\conhost.exe
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\System32\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2016-04-13 08:20:04 2D98A2C9EC46ADE57B04DE54672DB205 49664 ----a-w- C:\Windows\servicing\GC64\tzupd.exe
2016-04-12 18:44:10 9B9FCBFA0D10099DB855E77AF0F43613 686520 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
2016-04-12 18:44:06 3DC3258BDBD3EF5E801ADB1B8228F70E 254904 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe
2016-04-09 11:08:58 F61FD51A32059A7682C27A8A113E255A 10239464 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7100\Battle.net.exe
2016-04-09 11:08:53 95873FF06A694F375A426BD865D3FA13 1334760 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7100\Battle.net Helper.exe
=== C: other files ==
2016-04-15 12:55:56 3A63C1B8240841A92721CDE6066F1DD0 4870 ----a-w- C:\Users\Vitek\AppData\Local\Temp\xpi\tmp.zip
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\System32\drivers\disk.sys
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\System32\win32k.sys
==== Orphaned Tasks deleted from Registry ======================
avast Emergency Update deleted
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"="C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [08.04.2016 13:34]
==== Other Scheduled Tasks ======================
"C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\AVAST Software\Avast settings backup" [C:\Program Files\Common Files\AV\avast Antivirus\backup.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [04.01.2016 12:52]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- GsearchFinder - %ProfilePath%\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14.12.2015 15:22]
Avast Online Security - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Web Store Payments - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IESR02
HKCU\SearchScopes\{1D471673-7264-48B6-BB80-C994666E090B} - http://encyklopedie.seznam.cz/search?q= ... arch_12454
HKCU\SearchScopes\{343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} - http://www.mapy.cz/?query={searchTerms} ... arch_12454
HKCU\SearchScopes\{7570738B-2C59-4B16-82E3-9561343343AB} - http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
HKCU\SearchScopes\{75C2D683-8397-4749-9C4B-6BD774DA884B} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{A952281E-129E-4FCF-BBB8-D342E792185D} - http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
HKCU\SearchScopes\{B52B511D-2CBA-4900-996B-8FB7992F92C3} - http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
HKCU\SearchScopes\{E6CB1931-497E-4347-90C5-53B6A7626738} - http://search.seznam.cz/?q={searchTerms ... arch_12454
HKCU\SearchScopes\{FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} - http://www.novinky.cz/hledej?w={searchT ... arch_12454
==== Reset Google Chrome ======================
C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesgbak was reset successfully
C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Web Datagbak was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\4a0ako7w.default\cache2 emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome Cache found
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1347 folders=556 152551425 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Vitek\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Vitek\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\img.csfd.cz" not found
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\media.novinky.cz" not found
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\rule34hentai.net" not found
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\static.xvideos.com" not found
==== EOF on p 15.04.2016 at 19:44:46,61 ======================
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Vitek on p 15.04.2016 at 18:53:10,49.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vitek\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used]
==== Older Logs ======================
C:\zoek-results2016-04-15-104306.log 10271 bytes
C:\zoek-results2016-04-15-125407.log 4366 bytes
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultenginename", "yessearches");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.04.2016_1921_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.04.2016_1921_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.04.2016_1921_.backup
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\Vitek\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2016-04-13 08:20:45 C86AFCDD4584CFDF7B57335FEC7546E4 111616 ----a-w- C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 08:20:45 936AF75B1A7A663C24F999029A84142C 176128 ----a-w- C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 08:20:37 D25FCA441C69C3E6E78DE1BBCBF97BBC 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 08:20:37 8007E4C5C9B40FB30F816F6E74284DF1 1240576 ----a-w- C:\Windows\SysWOW64\msxml3.dll
2016-04-13 08:20:34 E518B37F8C82A4320732352E4DA9BF41 1414144 ----a-w- C:\Windows\SysWOW64\ole32.dll
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:33 40A0F37C85DFA5D6E963FFD496439661 1314112 ----a-w- C:\Windows\SysWOW64\ntdll.dll
2016-04-13 08:20:32 F7DF39F60CCB70AD4551BAC41C18ACA1 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll
2016-04-13 08:20:32 E8618EF4CB8D38462D4D8A4ED7DA9850 171520 ----a-w- C:\Windows\SysWOW64\wdigest.dll
2016-04-13 08:20:32 C8AE40931A2AC87E30E05C75E4A61796 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll
2016-04-13 08:20:32 B782F44A047D0D9459F0078A98AA8542 36352 ----a-w- C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 08:20:32 B52C499A81A73E8F74938ACA42734331 275456 ----a-w- C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 08:20:32 AAF65CD3A15EF6ECB0F4EF32F0D461B8 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 08:20:32 A3ECF0CFA0BFE509A77F0514885EA608 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll
2016-04-13 08:20:32 9F55E7A647A793A4D8C89A32B9543799 644096 ----a-w- C:\Windows\SysWOW64\advapi32.dll
2016-04-13 08:20:32 972332B4F1AC8EF3A42AE45BF65D3B60 141312 ----a-w- C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 88B9000A87883C908F927AF5036B8309 223232 ----a-w- C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 08:20:32 6B69810EDAEBBC68B205F5BBFD625E84 553984 ----a-w- C:\Windows\SysWOW64\kerberos.dll
2016-04-13 08:20:32 6B0E139FEF3B7C0061983C1502AE0CA3 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll
2016-04-13 08:20:32 47B6BE9CDF6888B7F9FDC5B2DB41B107 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 08:20:32 405B50ED43C2D73B32056168494DEA24 666112 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 08:20:32 361F32EEFC326C7D34CD2CCF05C469FC 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll
2016-04-13 08:20:32 28B998D3ACC5AF930B78A982B4698CB8 260608 ----a-w- C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 08:20:32 2610C8EF506344326F7250691093A3B9 251392 ----a-w- C:\Windows\SysWOW64\schannel.dll
2016-04-13 08:20:32 2347F9D5227F8751527C0AA0CDBA7375 342528 ----a-w- C:\Windows\SysWOW64\certcli.dll
2016-04-13 08:20:32 19E838D8DD2CB5576707259C8281EA78 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll
2016-04-13 08:20:32 002E17D37479281C5D241A189F973C5F 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 F5042159B95FD2748F55D89E08A89B48 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:28 4DD90351DB68847F9048133E45004B2F 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll
2016-04-13 08:20:28 38958A47AEE19E4CD89A0850640217C3 690688 ----a-w- C:\Windows\SysWOW64\adtschema.dll
2016-04-13 08:20:28 1FCAFC14E7B1BA3569DD1E483E486998 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 08:20:15 C2E392F3CE66FE21ADB7CA1158790BAA 15360 ----a-w- C:\Windows\SysWOW64\tbs.dll
2016-04-13 08:20:07 795F356F6027FCA3FD4AD5F3CCD904B7 60416 ----a-w- C:\Windows\SysWOW64\samlib.dll
2016-04-13 08:20:04 386E748E484BA802FCCBF00FC90729C4 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2016-04-13 08:20:46 A575C471CCFC7CBF32F446FA305E7341 156672 ----a-w- C:\Windows\Sysnative\mtxoci.dll
2016-04-13 08:20:38 622C96AFB07BB82C8650B47172137AC4 511488 ----a-w- C:\Windows\Sysnative\rpcss.dll
2016-04-13 08:20:37 F8A05F48B79CB5C087F089BA6C0659FB 1885696 ----a-w- C:\Windows\Sysnative\msxml3.dll
2016-04-13 08:20:37 D303AC584429678DB27DEBD4282CA1DF 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll
2016-04-13 08:20:35 10F466EF4048CA32CAF98FE4A3A16982 2084864 ----a-w- C:\Windows\Sysnative\ole32.dll
2016-04-13 08:20:34 7BE74B8A4BA6D27137E5557229EB83E3 631176 ----a-w- C:\Windows\Sysnative\winresume.efi
2016-04-13 08:20:34 6FCB62DDF2575ADFFD577A6648B25377 1464320 ----a-w- C:\Windows\Sysnative\lsasrv.dll
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe
2016-04-13 08:20:33 7AE8440A7C8B7E7078EE2654DDB8D21F 1732864 ----a-w- C:\Windows\Sysnative\ntdll.dll
2016-04-13 08:20:33 5817A07A72436A5658E48BF98A91137D 706280 ----a-w- C:\Windows\Sysnative\winload.efi
2016-04-13 08:20:32 EF34A098DD383766689A2F21BA2A990E 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll
2016-04-13 08:20:32 CB7E479501BC4C55328D242D41C1D074 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll
2016-04-13 08:20:32 C9F6BB175A7392A851FD86F2A3359088 463872 ----a-w- C:\Windows\Sysnative\certcli.dll
2016-04-13 08:20:32 C47B6624AF9AEE4146743DCB133A159D 34816 ----a-w- C:\Windows\Sysnative\appidsvc.dll
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe
2016-04-13 08:20:32 BEAD4B03B375B8F02C8C205E25A7CF0A 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll
2016-04-13 08:20:32 B46D03BABD31B23E6FCB226CB22D4D6B 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll
2016-04-13 08:20:32 B3A62D12B93A49189EA8CE51D186FC61 880640 ----a-w- C:\Windows\Sysnative\advapi32.dll
2016-04-13 08:20:32 AE9981D722DA386FBDDC78BEE6E41E56 419840 ----a-w- C:\Windows\Sysnative\KernelBase.dll
2016-04-13 08:20:32 9D8F5EBE48750AF80C5EB5542BEC448B 59904 ----a-w- C:\Windows\Sysnative\appidapi.dll
2016-04-13 08:20:32 9C73710485E2E1540D869BDB8A8A68CA 43520 ----a-w- C:\Windows\Sysnative\cryptbase.dll
2016-04-13 08:20:32 97C1D81250E9E73F7FC8568EF622017A 22016 ----a-w- C:\Windows\Sysnative\credssp.dll
2016-04-13 08:20:32 841BF993597DCD498247684B5D3AE845 215552 ----a-w- C:\Windows\Sysnative\winsrv.dll
2016-04-13 08:20:32 81AA2961530A4F036046CC627B4A90BC 28160 ----a-w- C:\Windows\Sysnative\secur32.dll
2016-04-13 08:20:32 811D9D4242A3E53D6DA86A400CCD63D0 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll
2016-04-13 08:20:32 7F9ADD80DE0B27B5EF2ACA7B19EAA3E5 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll
2016-04-13 08:20:32 7BBBB5DE05EFEEF2E45A48F9A943B6B0 243712 ----a-w- C:\Windows\Sysnative\wow64.dll
2016-04-13 08:20:32 77372D87A1A5E170C366E436990C6CB5 312320 ----a-w- C:\Windows\Sysnative\ncrypt.dll
2016-04-13 08:20:32 7407A5C092DAD554A3FC768B9859A847 210432 ----a-w- C:\Windows\Sysnative\wdigest.dll
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\Sysnative\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\Sysnative\lsass.exe
2016-04-13 08:20:32 6199722CB619A0887BE81F16A4474538 190464 ----a-w- C:\Windows\Sysnative\rpchttp.dll
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe
2016-04-13 08:20:32 593BC0F0D33A1905B5DC37FA756EB2BA 50176 ----a-w- C:\Windows\Sysnative\srclient.dll
2016-04-13 08:20:32 54D7B147EB4E7691AA5A2FA110A38363 1212928 ----a-w- C:\Windows\Sysnative\rpcrt4.dll
2016-04-13 08:20:32 4F374ED543FC9F3BB17EC6A7C8DF39A1 344064 ----a-w- C:\Windows\Sysnative\schannel.dll
2016-04-13 08:20:32 487D19B284DAFCBAE811AE785CC8B603 731136 ----a-w- C:\Windows\Sysnative\kerberos.dll
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\Sysnative\conhost.exe
2016-04-13 08:20:32 3B44D778B4719B1D5650FC6B1D90AA19 503808 ----a-w- C:\Windows\Sysnative\srcore.dll
2016-04-13 08:20:32 3B38C2EDA0D4854ED0E72BA3CBE8D72E 316416 ----a-w- C:\Windows\Sysnative\msv1_0.dll
2016-04-13 08:20:32 3A2DF0CC19D68C60F434DA02E1ED01B3 28672 ----a-w- C:\Windows\Sysnative\sspisrv.dll
2016-04-13 08:20:32 2D99A0ECE8475367798F1313197C933D 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe
2016-04-13 08:20:32 0CBD4E2DBBADABB79BFB8289E6E6227F 135680 ----a-w- C:\Windows\Sysnative\sspicli.dll
2016-04-13 08:20:28 DB651F0E6AC20C42348A9F0E8E7C42D5 690688 ----a-w- C:\Windows\Sysnative\adtschema.dll
2016-04-13 08:20:28 800AA696A0A773C039D1568F5828EFDE 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll
2016-04-13 08:20:28 6A019F8581D13BC1637DF9F2C92849DB 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll
2016-04-13 08:20:28 3D347AF86D2FDDEC5F30844537C355D1 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\Sysnative\win32k.sys
2016-04-13 08:20:15 D99F8968C0C5CAD46A6B93A1FA6738B2 109568 ----a-w- C:\Windows\Sysnative\fveapibase.dll
2016-04-13 08:20:15 D1035B8EFC83165612F7AAB1816A81B4 451080 ----a-w- C:\Windows\Sysnative\fveapi.dll
2016-04-13 08:20:15 8F39E301AD8B219DADF83BD7DBE9842E 20480 ----a-w- C:\Windows\Sysnative\tbs.dll
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe
2016-04-13 08:20:10 9282C7B69C15B072A9D9F9EDE0AA9C40 1169408 ----a-w- C:\Windows\Sysnative\aeinv.dll
2016-04-13 08:20:10 6E613496CC7CFAD37FA3D1EA86229A26 76800 ----a-w- C:\Windows\Sysnative\acmigration.dll
2016-04-13 08:20:10 4AAF4B88EDABA4CA3ACA82C1A248A3F4 279040 ----a-w- C:\Windows\Sysnative\invagent.dll
2016-04-13 08:20:10 453EEF8F903DE266D9CB16313B5FA796 215040 ----a-w- C:\Windows\Sysnative\aepic.dll
2016-04-13 08:20:10 2A0822070B416170A690D5E061194907 698368 ----a-w- C:\Windows\Sysnative\generaltel.dll
2016-04-13 08:20:10 2816C405CD465CB1D3559D017284FD31 1386496 ----a-w- C:\Windows\Sysnative\appraiser.dll
2016-04-13 08:20:10 24AAC7624C0114C5DAC7DA794D38E18A 499200 ----a-w- C:\Windows\Sysnative\devinv.dll
2016-04-13 08:20:07 C91E969FDEB819E63E7D6BECF5A8B8D0 106496 ----a-w- C:\Windows\Sysnative\samlib.dll
2016-04-13 08:20:07 48AF282E07C70E053D4E3EE2C732AD0D 760320 ----a-w- C:\Windows\Sysnative\samsrv.dll
2016-04-13 08:20:04 83250E0CE090E705B826C17F3345C758 2048 ----a-w- C:\Windows\Sysnative\tzres.dll
====== C:\Windows\Sysnative\drivers =====
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\Sysnative\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\Sysnative\drivers\disk.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
======= C: =====
====== C:\Users\Vitek\AppData\Roaming ======
2016-03-27 13:56:43 -------- d-----w- C:\Users\Vitek\AppData\Local\CrashDumps
====== C:\Users\Vitek ======
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
====== C: exe-files ==
2016-04-15 14:08:55 D1C9F7E9FA346B9BA4A96D4A3B2EC42C 1039928 ----a-w- C:\ProgramData\GOG.com\Galaxy\temp\desktop-galaxy-updater\GalaxyUpdater.exe
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 12:23:22 496DE87E5E6D1F46C5FD7A0AA6EAB8CF 7720424 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\Packages\00008959\DAO.20637995.exe
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\System32\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\System32\rstrui.exe
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\System32\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\System32\lsass.exe
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\System32\conhost.exe
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\System32\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2016-04-13 08:20:04 2D98A2C9EC46ADE57B04DE54672DB205 49664 ----a-w- C:\Windows\servicing\GC64\tzupd.exe
2016-04-12 18:44:10 9B9FCBFA0D10099DB855E77AF0F43613 686520 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
2016-04-12 18:44:06 3DC3258BDBD3EF5E801ADB1B8228F70E 254904 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe
2016-04-09 11:08:58 F61FD51A32059A7682C27A8A113E255A 10239464 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7100\Battle.net.exe
2016-04-09 11:08:53 95873FF06A694F375A426BD865D3FA13 1334760 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7100\Battle.net Helper.exe
=== C: other files ==
2016-04-15 12:55:56 3A63C1B8240841A92721CDE6066F1DD0 4870 ----a-w- C:\Users\Vitek\AppData\Local\Temp\xpi\tmp.zip
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\System32\drivers\disk.sys
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\System32\win32k.sys
==== Orphaned Tasks deleted from Registry ======================
avast Emergency Update deleted
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"="C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [08.04.2016 13:34]
==== Other Scheduled Tasks ======================
"C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\AVAST Software\Avast settings backup" [C:\Program Files\Common Files\AV\avast Antivirus\backup.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [04.01.2016 12:52]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- GsearchFinder - %ProfilePath%\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14.12.2015 15:22]
Avast Online Security - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Web Store Payments - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IESR02
HKCU\SearchScopes\{1D471673-7264-48B6-BB80-C994666E090B} - http://encyklopedie.seznam.cz/search?q= ... arch_12454
HKCU\SearchScopes\{343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} - http://www.mapy.cz/?query={searchTerms} ... arch_12454
HKCU\SearchScopes\{7570738B-2C59-4B16-82E3-9561343343AB} - http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
HKCU\SearchScopes\{75C2D683-8397-4749-9C4B-6BD774DA884B} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{A952281E-129E-4FCF-BBB8-D342E792185D} - http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
HKCU\SearchScopes\{B52B511D-2CBA-4900-996B-8FB7992F92C3} - http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
HKCU\SearchScopes\{E6CB1931-497E-4347-90C5-53B6A7626738} - http://search.seznam.cz/?q={searchTerms ... arch_12454
HKCU\SearchScopes\{FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} - http://www.novinky.cz/hledej?w={searchT ... arch_12454
==== Reset Google Chrome ======================
C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesgbak was reset successfully
C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Web Datagbak was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\4a0ako7w.default\cache2 emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome Cache found
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1347 folders=556 152551425 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Vitek\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Vitek\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\img.csfd.cz" not found
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\media.novinky.cz" not found
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\rule34hentai.net" not found
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\static.xvideos.com" not found
==== EOF on p 15.04.2016 at 19:44:46,61 ======================
Re: kontrola logu chytil jsem trojana 2 stránky
A JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Professional x64
Ran by Vitek (Administrator) on p 15.04.2016 at 19:51:28,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 14
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bgjpfhpjcgdppjbgnpnjllokbmcdllig_0.localstorage-journal (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bgjpfhpjcgdppjbgnpnjllokbmcdllig_0.localstorage (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage-journal (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_olfeabkoenfaoljndfecamgilllcpiak_0.localstorage (File)
Successfully deleted: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M5NVO7J (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEH27ZXX (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HVJ9105Q (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SHLHTDTP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M5NVO7J (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEH27ZXX (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HVJ9105Q (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SHLHTDTP (Temporary Internet Files Folder)
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E6CB1931-497E-4347-90C5-53B6A7626738} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 15.04.2016 at 19:54:18,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Professional x64
Ran by Vitek (Administrator) on p 15.04.2016 at 19:51:28,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 14
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bgjpfhpjcgdppjbgnpnjllokbmcdllig_0.localstorage-journal (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bgjpfhpjcgdppjbgnpnjllokbmcdllig_0.localstorage (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage-journal (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_blmojkbhnkkphngknkmgccmlenfaelkd_0.localstorage (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_olfeabkoenfaoljndfecamgilllcpiak_0.localstorage (File)
Successfully deleted: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi (File)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M5NVO7J (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEH27ZXX (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HVJ9105Q (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SHLHTDTP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M5NVO7J (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEH27ZXX (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HVJ9105Q (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SHLHTDTP (Temporary Internet Files Folder)
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E6CB1931-497E-4347-90C5-53B6A7626738} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 15.04.2016 at 19:54:18,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: kontrola logu chytil jsem trojana 2 stránky
Su este nejake problemy?
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: kontrola logu chytil jsem trojana 2 stránky
Ano, pořád se mě špatně načítají stránky v internetovém prohlížeči (používám jenom firefox). Stránky se mě načtou až na 3 pokus většinou, internet funguje normálně mám na něm připojený ještě notas a vše na něm jede v pohodě
Re: kontrola logu chytil jsem trojana 2 stránky
Prescanuj PC s MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: kontrola logu chytil jsem trojana 2 stránky
Přeskenováno MBAM nalezeno 9 potencionálních hrozeb, byly přesunuty do karantény mám je vymazat? Problém s prohlížečem stále trvá.
Nevím kde najdu log s toho MBAM
Nevím kde najdu log s toho MBAM
Re: kontrola logu chytil jsem trojana 2 stránky
Našel jsem jenom takový log
<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2016/04/16 12:35:04 +0200</date>
<logfile>mbam-log-2016-04-16 (12-34-58).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.2.1.1043</version>
<malware-database>v2016.04.16.02</malware-database>
<rootkit-database>v2016.04.09.01</rootkit-database>
<license>trial</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<hostname>VITEK-PC</hostname>
<ip>10.0.0.3</ip>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>Vitek</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>completed</result>
<objects>351709</objects>
<time>648</time>
<processes>0</processes>
<modules>0</modules>
<keys>1</keys>
<values>4</values>
<datas>0</datas>
<folders>0</folders>
<files>4</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<key><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><vendor>PUP.Optional.YesSearches</vendor><action>success</action><hash>780aaf008f0a3bfb0805e254cd360000</hash></key>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>hp</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/?ts=AHEpCH0s ... sh></value>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>tab</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/?ts=AHEpCH0s ... sh></value>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>sp</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/chrome.php?u ... sh></value>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>surl</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/chrome.php?u ... sh></value>
<file><path>C:\Users\Vitek\Downloads\FLVPlayerSetup-Nf4YwfHPM.exe</path><vendor>PUP.Optional.Somoto</vendor><action>success</action><hash>f78ba30c0f8a1422654498b95ca5b14f</hash></file>
<file><path>C:\Users\Vitek\Downloads\jesse_jane_downloader.exe</path><vendor>PUP.Optional.Downloader</vendor><action>success</action><hash>89f9e0cfa3f654e238047f970af73dc3</hash></file>
<file><path>C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\searchplugins\DD1B66D4.xml</path><vendor>PUP.Optional.YesSearches</vendor><action>success</action><hash>f2904d628d0c0f2709d080e6c441639d</hash></file>
<file><path>C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\sessionstore.js</path><vendor>PUP.Optional.TerraClicks.ShrtCln</vendor><action>replaced</action><baddata>www.terraclicks.com</baddata><gooddata></gooddata><hash>a7db8728722786b03fdfb8b2d82d0ff1</hash></file>
</items>
</mbam-log>
<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2016/04/16 12:35:04 +0200</date>
<logfile>mbam-log-2016-04-16 (12-34-58).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.2.1.1043</version>
<malware-database>v2016.04.16.02</malware-database>
<rootkit-database>v2016.04.09.01</rootkit-database>
<license>trial</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<hostname>VITEK-PC</hostname>
<ip>10.0.0.3</ip>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>Vitek</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>completed</result>
<objects>351709</objects>
<time>648</time>
<processes>0</processes>
<modules>0</modules>
<keys>1</keys>
<values>4</values>
<datas>0</datas>
<folders>0</folders>
<files>4</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<key><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><vendor>PUP.Optional.YesSearches</vendor><action>success</action><hash>780aaf008f0a3bfb0805e254cd360000</hash></key>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>hp</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/?ts=AHEpCH0s ... sh></value>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>tab</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/?ts=AHEpCH0s ... sh></value>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>sp</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/chrome.php?u ... sh></value>
<value><path>HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}</path><valuename>surl</valuename><vendor>PUP.Optional.YesSearches</vendor><action>success</action><valuedata>http://www.yessearches.com/chrome.php?u ... sh></value>
<file><path>C:\Users\Vitek\Downloads\FLVPlayerSetup-Nf4YwfHPM.exe</path><vendor>PUP.Optional.Somoto</vendor><action>success</action><hash>f78ba30c0f8a1422654498b95ca5b14f</hash></file>
<file><path>C:\Users\Vitek\Downloads\jesse_jane_downloader.exe</path><vendor>PUP.Optional.Downloader</vendor><action>success</action><hash>89f9e0cfa3f654e238047f970af73dc3</hash></file>
<file><path>C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\searchplugins\DD1B66D4.xml</path><vendor>PUP.Optional.YesSearches</vendor><action>success</action><hash>f2904d628d0c0f2709d080e6c441639d</hash></file>
<file><path>C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\sessionstore.js</path><vendor>PUP.Optional.TerraClicks.ShrtCln</vendor><action>replaced</action><baddata>www.terraclicks.com</baddata><gooddata></gooddata><hash>a7db8728722786b03fdfb8b2d82d0ff1</hash></file>
</items>
</mbam-log>
Re: kontrola logu chytil jsem trojana 2 stránky
Este zopakuj zoek
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: kontrola logu chytil jsem trojana 2 stránky
Problém stále trvá.
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Vitek on ne 17.04.2016 at 14:20:21,50.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vitek\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used]
==== Older Logs ======================
C:\zoek-results2016-04-15-104306.log 10271 bytes
C:\zoek-results2016-04-15-125407.log 4366 bytes
C:\zoek-results2016-04-15-174446.log 32520 bytes
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultenginename", "yessearches");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_17.04.2016_1456_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_17.04.2016_1456_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_17.04.2016_1456_.backup
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\Vitek\AppData\Local\Temp ====
2016-04-15 17:50:53 2F9C7FDA92C346CB5AA32091536AE0CB 43520 ----a-w- C:\Users\Vitek\AppData\Local\Temp\jrt\nfo\nircmdc.exe
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2016-04-13 08:20:45 C86AFCDD4584CFDF7B57335FEC7546E4 111616 ----a-w- C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 08:20:45 936AF75B1A7A663C24F999029A84142C 176128 ----a-w- C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 08:20:37 D25FCA441C69C3E6E78DE1BBCBF97BBC 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 08:20:37 8007E4C5C9B40FB30F816F6E74284DF1 1240576 ----a-w- C:\Windows\SysWOW64\msxml3.dll
2016-04-13 08:20:34 E518B37F8C82A4320732352E4DA9BF41 1414144 ----a-w- C:\Windows\SysWOW64\ole32.dll
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:33 40A0F37C85DFA5D6E963FFD496439661 1314112 ----a-w- C:\Windows\SysWOW64\ntdll.dll
2016-04-13 08:20:32 F7DF39F60CCB70AD4551BAC41C18ACA1 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll
2016-04-13 08:20:32 E8618EF4CB8D38462D4D8A4ED7DA9850 171520 ----a-w- C:\Windows\SysWOW64\wdigest.dll
2016-04-13 08:20:32 C8AE40931A2AC87E30E05C75E4A61796 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll
2016-04-13 08:20:32 B782F44A047D0D9459F0078A98AA8542 36352 ----a-w- C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 08:20:32 B52C499A81A73E8F74938ACA42734331 275456 ----a-w- C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 08:20:32 AAF65CD3A15EF6ECB0F4EF32F0D461B8 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 08:20:32 A3ECF0CFA0BFE509A77F0514885EA608 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll
2016-04-13 08:20:32 9F55E7A647A793A4D8C89A32B9543799 644096 ----a-w- C:\Windows\SysWOW64\advapi32.dll
2016-04-13 08:20:32 972332B4F1AC8EF3A42AE45BF65D3B60 141312 ----a-w- C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 88B9000A87883C908F927AF5036B8309 223232 ----a-w- C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 08:20:32 6B69810EDAEBBC68B205F5BBFD625E84 553984 ----a-w- C:\Windows\SysWOW64\kerberos.dll
2016-04-13 08:20:32 6B0E139FEF3B7C0061983C1502AE0CA3 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll
2016-04-13 08:20:32 47B6BE9CDF6888B7F9FDC5B2DB41B107 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 08:20:32 405B50ED43C2D73B32056168494DEA24 666112 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 08:20:32 361F32EEFC326C7D34CD2CCF05C469FC 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll
2016-04-13 08:20:32 28B998D3ACC5AF930B78A982B4698CB8 260608 ----a-w- C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 08:20:32 2610C8EF506344326F7250691093A3B9 251392 ----a-w- C:\Windows\SysWOW64\schannel.dll
2016-04-13 08:20:32 2347F9D5227F8751527C0AA0CDBA7375 342528 ----a-w- C:\Windows\SysWOW64\certcli.dll
2016-04-13 08:20:32 19E838D8DD2CB5576707259C8281EA78 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll
2016-04-13 08:20:32 002E17D37479281C5D241A189F973C5F 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 F5042159B95FD2748F55D89E08A89B48 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:28 4DD90351DB68847F9048133E45004B2F 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll
2016-04-13 08:20:28 38958A47AEE19E4CD89A0850640217C3 690688 ----a-w- C:\Windows\SysWOW64\adtschema.dll
2016-04-13 08:20:28 1FCAFC14E7B1BA3569DD1E483E486998 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 08:20:15 C2E392F3CE66FE21ADB7CA1158790BAA 15360 ----a-w- C:\Windows\SysWOW64\tbs.dll
2016-04-13 08:20:07 795F356F6027FCA3FD4AD5F3CCD904B7 60416 ----a-w- C:\Windows\SysWOW64\samlib.dll
2016-04-13 08:20:04 386E748E484BA802FCCBF00FC90729C4 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2016-04-13 08:20:46 A575C471CCFC7CBF32F446FA305E7341 156672 ----a-w- C:\Windows\Sysnative\mtxoci.dll
2016-04-13 08:20:38 622C96AFB07BB82C8650B47172137AC4 511488 ----a-w- C:\Windows\Sysnative\rpcss.dll
2016-04-13 08:20:37 F8A05F48B79CB5C087F089BA6C0659FB 1885696 ----a-w- C:\Windows\Sysnative\msxml3.dll
2016-04-13 08:20:37 D303AC584429678DB27DEBD4282CA1DF 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll
2016-04-13 08:20:35 10F466EF4048CA32CAF98FE4A3A16982 2084864 ----a-w- C:\Windows\Sysnative\ole32.dll
2016-04-13 08:20:34 7BE74B8A4BA6D27137E5557229EB83E3 631176 ----a-w- C:\Windows\Sysnative\winresume.efi
2016-04-13 08:20:34 6FCB62DDF2575ADFFD577A6648B25377 1464320 ----a-w- C:\Windows\Sysnative\lsasrv.dll
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe
2016-04-13 08:20:33 7AE8440A7C8B7E7078EE2654DDB8D21F 1732864 ----a-w- C:\Windows\Sysnative\ntdll.dll
2016-04-13 08:20:33 5817A07A72436A5658E48BF98A91137D 706280 ----a-w- C:\Windows\Sysnative\winload.efi
2016-04-13 08:20:32 EF34A098DD383766689A2F21BA2A990E 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll
2016-04-13 08:20:32 CB7E479501BC4C55328D242D41C1D074 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll
2016-04-13 08:20:32 C9F6BB175A7392A851FD86F2A3359088 463872 ----a-w- C:\Windows\Sysnative\certcli.dll
2016-04-13 08:20:32 C47B6624AF9AEE4146743DCB133A159D 34816 ----a-w- C:\Windows\Sysnative\appidsvc.dll
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe
2016-04-13 08:20:32 BEAD4B03B375B8F02C8C205E25A7CF0A 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll
2016-04-13 08:20:32 B46D03BABD31B23E6FCB226CB22D4D6B 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll
2016-04-13 08:20:32 B3A62D12B93A49189EA8CE51D186FC61 880640 ----a-w- C:\Windows\Sysnative\advapi32.dll
2016-04-13 08:20:32 AE9981D722DA386FBDDC78BEE6E41E56 419840 ----a-w- C:\Windows\Sysnative\KernelBase.dll
2016-04-13 08:20:32 9D8F5EBE48750AF80C5EB5542BEC448B 59904 ----a-w- C:\Windows\Sysnative\appidapi.dll
2016-04-13 08:20:32 9C73710485E2E1540D869BDB8A8A68CA 43520 ----a-w- C:\Windows\Sysnative\cryptbase.dll
2016-04-13 08:20:32 97C1D81250E9E73F7FC8568EF622017A 22016 ----a-w- C:\Windows\Sysnative\credssp.dll
2016-04-13 08:20:32 841BF993597DCD498247684B5D3AE845 215552 ----a-w- C:\Windows\Sysnative\winsrv.dll
2016-04-13 08:20:32 81AA2961530A4F036046CC627B4A90BC 28160 ----a-w- C:\Windows\Sysnative\secur32.dll
2016-04-13 08:20:32 811D9D4242A3E53D6DA86A400CCD63D0 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll
2016-04-13 08:20:32 7F9ADD80DE0B27B5EF2ACA7B19EAA3E5 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll
2016-04-13 08:20:32 7BBBB5DE05EFEEF2E45A48F9A943B6B0 243712 ----a-w- C:\Windows\Sysnative\wow64.dll
2016-04-13 08:20:32 77372D87A1A5E170C366E436990C6CB5 312320 ----a-w- C:\Windows\Sysnative\ncrypt.dll
2016-04-13 08:20:32 7407A5C092DAD554A3FC768B9859A847 210432 ----a-w- C:\Windows\Sysnative\wdigest.dll
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\Sysnative\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\Sysnative\lsass.exe
2016-04-13 08:20:32 6199722CB619A0887BE81F16A4474538 190464 ----a-w- C:\Windows\Sysnative\rpchttp.dll
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe
2016-04-13 08:20:32 593BC0F0D33A1905B5DC37FA756EB2BA 50176 ----a-w- C:\Windows\Sysnative\srclient.dll
2016-04-13 08:20:32 54D7B147EB4E7691AA5A2FA110A38363 1212928 ----a-w- C:\Windows\Sysnative\rpcrt4.dll
2016-04-13 08:20:32 4F374ED543FC9F3BB17EC6A7C8DF39A1 344064 ----a-w- C:\Windows\Sysnative\schannel.dll
2016-04-13 08:20:32 487D19B284DAFCBAE811AE785CC8B603 731136 ----a-w- C:\Windows\Sysnative\kerberos.dll
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\Sysnative\conhost.exe
2016-04-13 08:20:32 3B44D778B4719B1D5650FC6B1D90AA19 503808 ----a-w- C:\Windows\Sysnative\srcore.dll
2016-04-13 08:20:32 3B38C2EDA0D4854ED0E72BA3CBE8D72E 316416 ----a-w- C:\Windows\Sysnative\msv1_0.dll
2016-04-13 08:20:32 3A2DF0CC19D68C60F434DA02E1ED01B3 28672 ----a-w- C:\Windows\Sysnative\sspisrv.dll
2016-04-13 08:20:32 2D99A0ECE8475367798F1313197C933D 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe
2016-04-13 08:20:32 0CBD4E2DBBADABB79BFB8289E6E6227F 135680 ----a-w- C:\Windows\Sysnative\sspicli.dll
2016-04-13 08:20:28 DB651F0E6AC20C42348A9F0E8E7C42D5 690688 ----a-w- C:\Windows\Sysnative\adtschema.dll
2016-04-13 08:20:28 800AA696A0A773C039D1568F5828EFDE 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll
2016-04-13 08:20:28 6A019F8581D13BC1637DF9F2C92849DB 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll
2016-04-13 08:20:28 3D347AF86D2FDDEC5F30844537C355D1 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\Sysnative\win32k.sys
2016-04-13 08:20:15 D99F8968C0C5CAD46A6B93A1FA6738B2 109568 ----a-w- C:\Windows\Sysnative\fveapibase.dll
2016-04-13 08:20:15 D1035B8EFC83165612F7AAB1816A81B4 451080 ----a-w- C:\Windows\Sysnative\fveapi.dll
2016-04-13 08:20:15 8F39E301AD8B219DADF83BD7DBE9842E 20480 ----a-w- C:\Windows\Sysnative\tbs.dll
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe
2016-04-13 08:20:10 9282C7B69C15B072A9D9F9EDE0AA9C40 1169408 ----a-w- C:\Windows\Sysnative\aeinv.dll
2016-04-13 08:20:10 6E613496CC7CFAD37FA3D1EA86229A26 76800 ----a-w- C:\Windows\Sysnative\acmigration.dll
2016-04-13 08:20:10 4AAF4B88EDABA4CA3ACA82C1A248A3F4 279040 ----a-w- C:\Windows\Sysnative\invagent.dll
2016-04-13 08:20:10 453EEF8F903DE266D9CB16313B5FA796 215040 ----a-w- C:\Windows\Sysnative\aepic.dll
2016-04-13 08:20:10 2A0822070B416170A690D5E061194907 698368 ----a-w- C:\Windows\Sysnative\generaltel.dll
2016-04-13 08:20:10 2816C405CD465CB1D3559D017284FD31 1386496 ----a-w- C:\Windows\Sysnative\appraiser.dll
2016-04-13 08:20:10 24AAC7624C0114C5DAC7DA794D38E18A 499200 ----a-w- C:\Windows\Sysnative\devinv.dll
2016-04-13 08:20:07 C91E969FDEB819E63E7D6BECF5A8B8D0 106496 ----a-w- C:\Windows\Sysnative\samlib.dll
2016-04-13 08:20:07 48AF282E07C70E053D4E3EE2C732AD0D 760320 ----a-w- C:\Windows\Sysnative\samsrv.dll
2016-04-13 08:20:04 83250E0CE090E705B826C17F3345C758 2048 ----a-w- C:\Windows\Sysnative\tzres.dll
====== C:\Windows\Sysnative\drivers =====
2016-04-16 10:33:37 78488AF2AB2111D67B3C4044707A519B 192216 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys
2016-04-16 10:33:02 78BFF5425E044086E74E78650A359FBB 27008 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys
2016-04-16 10:33:02 452ACB7A9914398D9E18CCCFFCF92208 64896 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys
2016-04-16 10:33:02 1239597BAB7EED2BB16D035AF87E65D9 140672 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\Sysnative\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\Sysnative\drivers\disk.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
======= C: =====
====== C:\Users\Vitek\AppData\Roaming ======
2016-04-16 08:43:50 CA4D31C9AD8FA745C6D194E85AF1C494 7600 ----a-w- C:\Users\Vitek\AppData\Local\Resmon.ResmonCfg
2016-04-15 17:31:45 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Users\Vitek\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Users\Default\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Users\Default User\AppData\Local\Temp
2016-03-27 13:56:43 -------- d-----w- C:\Users\Vitek\AppData\Local\CrashDumps
====== C:\Users\Vitek ======
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
====== C: exe-files ==
2016-04-17 09:05:35 D1C9F7E9FA346B9BA4A96D4A3B2EC42C 1039928 ----a-w- C:\ProgramData\GOG.com\Galaxy\temp\desktop-galaxy-updater\GalaxyUpdater.exe
2016-04-16 20:24:19 879FCBC50F2EE8E03BAA4556BE43FF32 10241000 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7113\Battle.net.exe
2016-04-16 20:24:14 927DEC83447D92E672C004967A88B432 1334760 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7113\Battle.net Helper.exe
2016-04-16 14:21:49 7B983DB7CD5238A4C1D3A07AAA3115EA 7720656 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\Packages\0000896b\DAO.20650245.exe
2016-04-16 10:30:41 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Vitek\Desktop\Vitek\Programy\Antiviry-čištění počítače\mbam-setup-2.2.1.1043.exe
2016-04-15 17:50:53 2F9C7FDA92C346CB5AA32091536AE0CB 43520 ----a-w- C:\Users\Vitek\AppData\Local\Temp\jrt\nfo\nircmdc.exe
2016-04-15 16:26:40 C769A60785C62EA5B810737EE260D0FD 686520 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
2016-04-15 16:26:36 F6B79602122F6C6E4AF0BF47E0A2CBE4 254904 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\System32\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\System32\rstrui.exe
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\System32\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\System32\lsass.exe
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\System32\conhost.exe
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\System32\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2016-04-13 08:20:04 2D98A2C9EC46ADE57B04DE54672DB205 49664 ----a-w- C:\Windows\servicing\GC64\tzupd.exe
=== C: other files ==
2016-04-16 10:33:37 78488AF2AB2111D67B3C4044707A519B 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2016-04-16 10:33:02 78BFF5425E044086E74E78650A359FBB 27008 ----a-w- C:\Windows\System32\drivers\mbam.sys
2016-04-16 10:33:02 452ACB7A9914398D9E18CCCFFCF92208 64896 ----a-w- C:\Windows\System32\drivers\mwac.sys
2016-04-16 10:33:02 1239597BAB7EED2BB16D035AF87E65D9 140672 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\System32\drivers\disk.sys
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\System32\win32k.sys
==== Orphaned Tasks deleted from Registry ======================
avast Emergency Update deleted
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"="C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [08.04.2016 13:34]
==== Other Scheduled Tasks ======================
"C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\AVAST Software\Avast settings backup" [C:\Program Files\Common Files\AV\avast Antivirus\backup.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [04.01.2016 12:52]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14.12.2015 15:22]
Avast Online Security - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Web Store Payments - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IESR02
HKCU\SearchScopes\{1D471673-7264-48B6-BB80-C994666E090B} - http://encyklopedie.seznam.cz/search?q= ... arch_12454
HKCU\SearchScopes\{343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} - http://www.mapy.cz/?query={searchTerms} ... arch_12454
HKCU\SearchScopes\{7570738B-2C59-4B16-82E3-9561343343AB} - http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
HKCU\SearchScopes\{75C2D683-8397-4749-9C4B-6BD774DA884B} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{A952281E-129E-4FCF-BBB8-D342E792185D} - http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
HKCU\SearchScopes\{B52B511D-2CBA-4900-996B-8FB7992F92C3} - http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
HKCU\SearchScopes\{FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} - http://www.novinky.cz/hledej?w={searchT ... arch_12454
==== Reset Google Chrome ======================
Nothing found to reset
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\4a0ako7w.default\cache2 emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome Cache found
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1350 folders=556 152628822 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Vitek\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Vitek\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\pornreactor.cc" not found
==== EOF on ne 17.04.2016 at 15:57:40,19 ======================
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Vitek on ne 17.04.2016 at 14:20:21,50.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vitek\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used]
==== Older Logs ======================
C:\zoek-results2016-04-15-104306.log 10271 bytes
C:\zoek-results2016-04-15-125407.log 4366 bytes
C:\zoek-results2016-04-15-174446.log 32520 bytes
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultenginename", "yessearches");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Added to C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_17.04.2016_1456_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_17.04.2016_1456_.backup
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_17.04.2016_1456_.backup
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\Vitek\AppData\Local\Temp ====
2016-04-15 17:50:53 2F9C7FDA92C346CB5AA32091536AE0CB 43520 ----a-w- C:\Users\Vitek\AppData\Local\Temp\jrt\nfo\nircmdc.exe
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2016-04-13 08:20:45 C86AFCDD4584CFDF7B57335FEC7546E4 111616 ----a-w- C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 08:20:45 936AF75B1A7A663C24F999029A84142C 176128 ----a-w- C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 08:20:37 D25FCA441C69C3E6E78DE1BBCBF97BBC 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 08:20:37 8007E4C5C9B40FB30F816F6E74284DF1 1240576 ----a-w- C:\Windows\SysWOW64\msxml3.dll
2016-04-13 08:20:34 E518B37F8C82A4320732352E4DA9BF41 1414144 ----a-w- C:\Windows\SysWOW64\ole32.dll
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:33 40A0F37C85DFA5D6E963FFD496439661 1314112 ----a-w- C:\Windows\SysWOW64\ntdll.dll
2016-04-13 08:20:32 F7DF39F60CCB70AD4551BAC41C18ACA1 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll
2016-04-13 08:20:32 E8618EF4CB8D38462D4D8A4ED7DA9850 171520 ----a-w- C:\Windows\SysWOW64\wdigest.dll
2016-04-13 08:20:32 C8AE40931A2AC87E30E05C75E4A61796 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll
2016-04-13 08:20:32 B782F44A047D0D9459F0078A98AA8542 36352 ----a-w- C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 08:20:32 B52C499A81A73E8F74938ACA42734331 275456 ----a-w- C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 08:20:32 AAF65CD3A15EF6ECB0F4EF32F0D461B8 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 08:20:32 A3ECF0CFA0BFE509A77F0514885EA608 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll
2016-04-13 08:20:32 9F55E7A647A793A4D8C89A32B9543799 644096 ----a-w- C:\Windows\SysWOW64\advapi32.dll
2016-04-13 08:20:32 972332B4F1AC8EF3A42AE45BF65D3B60 141312 ----a-w- C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 88B9000A87883C908F927AF5036B8309 223232 ----a-w- C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 08:20:32 6B69810EDAEBBC68B205F5BBFD625E84 553984 ----a-w- C:\Windows\SysWOW64\kerberos.dll
2016-04-13 08:20:32 6B0E139FEF3B7C0061983C1502AE0CA3 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll
2016-04-13 08:20:32 47B6BE9CDF6888B7F9FDC5B2DB41B107 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 08:20:32 405B50ED43C2D73B32056168494DEA24 666112 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 08:20:32 361F32EEFC326C7D34CD2CCF05C469FC 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll
2016-04-13 08:20:32 28B998D3ACC5AF930B78A982B4698CB8 260608 ----a-w- C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 08:20:32 2610C8EF506344326F7250691093A3B9 251392 ----a-w- C:\Windows\SysWOW64\schannel.dll
2016-04-13 08:20:32 2347F9D5227F8751527C0AA0CDBA7375 342528 ----a-w- C:\Windows\SysWOW64\certcli.dll
2016-04-13 08:20:32 19E838D8DD2CB5576707259C8281EA78 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll
2016-04-13 08:20:32 002E17D37479281C5D241A189F973C5F 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 F5042159B95FD2748F55D89E08A89B48 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:28 4DD90351DB68847F9048133E45004B2F 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll
2016-04-13 08:20:28 38958A47AEE19E4CD89A0850640217C3 690688 ----a-w- C:\Windows\SysWOW64\adtschema.dll
2016-04-13 08:20:28 1FCAFC14E7B1BA3569DD1E483E486998 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 08:20:15 C2E392F3CE66FE21ADB7CA1158790BAA 15360 ----a-w- C:\Windows\SysWOW64\tbs.dll
2016-04-13 08:20:07 795F356F6027FCA3FD4AD5F3CCD904B7 60416 ----a-w- C:\Windows\SysWOW64\samlib.dll
2016-04-13 08:20:04 386E748E484BA802FCCBF00FC90729C4 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2016-04-13 08:20:46 A575C471CCFC7CBF32F446FA305E7341 156672 ----a-w- C:\Windows\Sysnative\mtxoci.dll
2016-04-13 08:20:38 622C96AFB07BB82C8650B47172137AC4 511488 ----a-w- C:\Windows\Sysnative\rpcss.dll
2016-04-13 08:20:37 F8A05F48B79CB5C087F089BA6C0659FB 1885696 ----a-w- C:\Windows\Sysnative\msxml3.dll
2016-04-13 08:20:37 D303AC584429678DB27DEBD4282CA1DF 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll
2016-04-13 08:20:35 10F466EF4048CA32CAF98FE4A3A16982 2084864 ----a-w- C:\Windows\Sysnative\ole32.dll
2016-04-13 08:20:34 7BE74B8A4BA6D27137E5557229EB83E3 631176 ----a-w- C:\Windows\Sysnative\winresume.efi
2016-04-13 08:20:34 6FCB62DDF2575ADFFD577A6648B25377 1464320 ----a-w- C:\Windows\Sysnative\lsasrv.dll
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe
2016-04-13 08:20:33 7AE8440A7C8B7E7078EE2654DDB8D21F 1732864 ----a-w- C:\Windows\Sysnative\ntdll.dll
2016-04-13 08:20:33 5817A07A72436A5658E48BF98A91137D 706280 ----a-w- C:\Windows\Sysnative\winload.efi
2016-04-13 08:20:32 EF34A098DD383766689A2F21BA2A990E 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll
2016-04-13 08:20:32 CB7E479501BC4C55328D242D41C1D074 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll
2016-04-13 08:20:32 C9F6BB175A7392A851FD86F2A3359088 463872 ----a-w- C:\Windows\Sysnative\certcli.dll
2016-04-13 08:20:32 C47B6624AF9AEE4146743DCB133A159D 34816 ----a-w- C:\Windows\Sysnative\appidsvc.dll
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe
2016-04-13 08:20:32 BEAD4B03B375B8F02C8C205E25A7CF0A 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll
2016-04-13 08:20:32 B46D03BABD31B23E6FCB226CB22D4D6B 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll
2016-04-13 08:20:32 B3A62D12B93A49189EA8CE51D186FC61 880640 ----a-w- C:\Windows\Sysnative\advapi32.dll
2016-04-13 08:20:32 AE9981D722DA386FBDDC78BEE6E41E56 419840 ----a-w- C:\Windows\Sysnative\KernelBase.dll
2016-04-13 08:20:32 9D8F5EBE48750AF80C5EB5542BEC448B 59904 ----a-w- C:\Windows\Sysnative\appidapi.dll
2016-04-13 08:20:32 9C73710485E2E1540D869BDB8A8A68CA 43520 ----a-w- C:\Windows\Sysnative\cryptbase.dll
2016-04-13 08:20:32 97C1D81250E9E73F7FC8568EF622017A 22016 ----a-w- C:\Windows\Sysnative\credssp.dll
2016-04-13 08:20:32 841BF993597DCD498247684B5D3AE845 215552 ----a-w- C:\Windows\Sysnative\winsrv.dll
2016-04-13 08:20:32 81AA2961530A4F036046CC627B4A90BC 28160 ----a-w- C:\Windows\Sysnative\secur32.dll
2016-04-13 08:20:32 811D9D4242A3E53D6DA86A400CCD63D0 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll
2016-04-13 08:20:32 7F9ADD80DE0B27B5EF2ACA7B19EAA3E5 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll
2016-04-13 08:20:32 7BBBB5DE05EFEEF2E45A48F9A943B6B0 243712 ----a-w- C:\Windows\Sysnative\wow64.dll
2016-04-13 08:20:32 77372D87A1A5E170C366E436990C6CB5 312320 ----a-w- C:\Windows\Sysnative\ncrypt.dll
2016-04-13 08:20:32 7407A5C092DAD554A3FC768B9859A847 210432 ----a-w- C:\Windows\Sysnative\wdigest.dll
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\Sysnative\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\Sysnative\lsass.exe
2016-04-13 08:20:32 6199722CB619A0887BE81F16A4474538 190464 ----a-w- C:\Windows\Sysnative\rpchttp.dll
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe
2016-04-13 08:20:32 593BC0F0D33A1905B5DC37FA756EB2BA 50176 ----a-w- C:\Windows\Sysnative\srclient.dll
2016-04-13 08:20:32 54D7B147EB4E7691AA5A2FA110A38363 1212928 ----a-w- C:\Windows\Sysnative\rpcrt4.dll
2016-04-13 08:20:32 4F374ED543FC9F3BB17EC6A7C8DF39A1 344064 ----a-w- C:\Windows\Sysnative\schannel.dll
2016-04-13 08:20:32 487D19B284DAFCBAE811AE785CC8B603 731136 ----a-w- C:\Windows\Sysnative\kerberos.dll
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\Sysnative\conhost.exe
2016-04-13 08:20:32 3B44D778B4719B1D5650FC6B1D90AA19 503808 ----a-w- C:\Windows\Sysnative\srcore.dll
2016-04-13 08:20:32 3B38C2EDA0D4854ED0E72BA3CBE8D72E 316416 ----a-w- C:\Windows\Sysnative\msv1_0.dll
2016-04-13 08:20:32 3A2DF0CC19D68C60F434DA02E1ED01B3 28672 ----a-w- C:\Windows\Sysnative\sspisrv.dll
2016-04-13 08:20:32 2D99A0ECE8475367798F1313197C933D 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe
2016-04-13 08:20:32 0CBD4E2DBBADABB79BFB8289E6E6227F 135680 ----a-w- C:\Windows\Sysnative\sspicli.dll
2016-04-13 08:20:28 DB651F0E6AC20C42348A9F0E8E7C42D5 690688 ----a-w- C:\Windows\Sysnative\adtschema.dll
2016-04-13 08:20:28 800AA696A0A773C039D1568F5828EFDE 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll
2016-04-13 08:20:28 6A019F8581D13BC1637DF9F2C92849DB 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll
2016-04-13 08:20:28 3D347AF86D2FDDEC5F30844537C355D1 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\Sysnative\win32k.sys
2016-04-13 08:20:15 D99F8968C0C5CAD46A6B93A1FA6738B2 109568 ----a-w- C:\Windows\Sysnative\fveapibase.dll
2016-04-13 08:20:15 D1035B8EFC83165612F7AAB1816A81B4 451080 ----a-w- C:\Windows\Sysnative\fveapi.dll
2016-04-13 08:20:15 8F39E301AD8B219DADF83BD7DBE9842E 20480 ----a-w- C:\Windows\Sysnative\tbs.dll
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe
2016-04-13 08:20:10 9282C7B69C15B072A9D9F9EDE0AA9C40 1169408 ----a-w- C:\Windows\Sysnative\aeinv.dll
2016-04-13 08:20:10 6E613496CC7CFAD37FA3D1EA86229A26 76800 ----a-w- C:\Windows\Sysnative\acmigration.dll
2016-04-13 08:20:10 4AAF4B88EDABA4CA3ACA82C1A248A3F4 279040 ----a-w- C:\Windows\Sysnative\invagent.dll
2016-04-13 08:20:10 453EEF8F903DE266D9CB16313B5FA796 215040 ----a-w- C:\Windows\Sysnative\aepic.dll
2016-04-13 08:20:10 2A0822070B416170A690D5E061194907 698368 ----a-w- C:\Windows\Sysnative\generaltel.dll
2016-04-13 08:20:10 2816C405CD465CB1D3559D017284FD31 1386496 ----a-w- C:\Windows\Sysnative\appraiser.dll
2016-04-13 08:20:10 24AAC7624C0114C5DAC7DA794D38E18A 499200 ----a-w- C:\Windows\Sysnative\devinv.dll
2016-04-13 08:20:07 C91E969FDEB819E63E7D6BECF5A8B8D0 106496 ----a-w- C:\Windows\Sysnative\samlib.dll
2016-04-13 08:20:07 48AF282E07C70E053D4E3EE2C732AD0D 760320 ----a-w- C:\Windows\Sysnative\samsrv.dll
2016-04-13 08:20:04 83250E0CE090E705B826C17F3345C758 2048 ----a-w- C:\Windows\Sysnative\tzres.dll
====== C:\Windows\Sysnative\drivers =====
2016-04-16 10:33:37 78488AF2AB2111D67B3C4044707A519B 192216 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys
2016-04-16 10:33:02 78BFF5425E044086E74E78650A359FBB 27008 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys
2016-04-16 10:33:02 452ACB7A9914398D9E18CCCFFCF92208 64896 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys
2016-04-16 10:33:02 1239597BAB7EED2BB16D035AF87E65D9 140672 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\Sysnative\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\Sysnative\drivers\disk.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
======= C: =====
====== C:\Users\Vitek\AppData\Roaming ======
2016-04-16 08:43:50 CA4D31C9AD8FA745C6D194E85AF1C494 7600 ----a-w- C:\Users\Vitek\AppData\Local\Resmon.ResmonCfg
2016-04-15 17:31:45 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Users\Vitek\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Users\Default\AppData\Local\Temp
2016-04-15 17:31:45 -------- d-----w- C:\Users\Default User\AppData\Local\Temp
2016-03-27 13:56:43 -------- d-----w- C:\Users\Vitek\AppData\Local\CrashDumps
====== C:\Users\Vitek ======
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
====== C: exe-files ==
2016-04-17 09:05:35 D1C9F7E9FA346B9BA4A96D4A3B2EC42C 1039928 ----a-w- C:\ProgramData\GOG.com\Galaxy\temp\desktop-galaxy-updater\GalaxyUpdater.exe
2016-04-16 20:24:19 879FCBC50F2EE8E03BAA4556BE43FF32 10241000 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7113\Battle.net.exe
2016-04-16 20:24:14 927DEC83447D92E672C004967A88B432 1334760 ----a-w- C:\Program Files (x86)\Battle.net\Battle.net.7113\Battle.net Helper.exe
2016-04-16 14:21:49 7B983DB7CD5238A4C1D3A07AAA3115EA 7720656 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\Packages\0000896b\DAO.20650245.exe
2016-04-16 10:30:41 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Vitek\Desktop\Vitek\Programy\Antiviry-čištění počítače\mbam-setup-2.2.1.1043.exe
2016-04-15 17:50:53 2F9C7FDA92C346CB5AA32091536AE0CB 43520 ----a-w- C:\Users\Vitek\AppData\Local\Temp\jrt\nfo\nircmdc.exe
2016-04-15 16:26:40 C769A60785C62EA5B810737EE260D0FD 686520 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
2016-04-15 16:26:36 F6B79602122F6C6E4AF0BF47E0A2CBE4 254904 ----a-w- C:\Users\Vitek\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe
2016-04-15 08:46:48 E91D834A4B986A8B665BF1AE78B7F4A7 1610352 ----a-w- C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 07:24:59 DC74E06F01898F482C8F1C2C70BE5C9D 2375168 ----a-w- C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 07:23:38 5B63FB4CB5E438FB8D165BFDDB7BB94D 3677760 ----a-w- C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 08:20:33 F1CA4530A435A6741346A1ECF3FE10E9 3943144 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 08:20:33 ADFFC3B4418247A562E8727C66DE4428 5551336 ----a-w- C:\Windows\System32\ntoskrnl.exe
2016-04-13 08:20:33 5C47821CC760ED48EA66A28465BD35E4 3998952 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 08:20:32 BEEC56A8B8B5707B0E7139C6D9D57217 296960 ----a-w- C:\Windows\System32\rstrui.exe
2016-04-13 08:20:32 8DCFB284FC896E2F6F02134298A8F1E1 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2016-04-13 08:20:32 682586CACD78EF53EF7301B4180EB595 112640 ----a-w- C:\Windows\System32\smss.exe
2016-04-13 08:20:32 626BE7CD27F44185AA4DCD3603830312 30720 ----a-w- C:\Windows\System32\lsass.exe
2016-04-13 08:20:32 59738954027D75A282D82680C8AFBC54 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2016-04-13 08:20:32 3D6AE177FAF7E3296251DDB05773618E 338432 ----a-w- C:\Windows\System32\conhost.exe
2016-04-13 08:20:32 1F8F134C7350EF16C79E1C42005BCDE9 64000 ----a-w- C:\Windows\System32\auditpol.exe
2016-04-13 08:20:32 0E4019A26AE3DB40461B5AA0C3AD6A68 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2016-04-13 08:20:31 BCF50CD5076E765200740A97FCB4D74F 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2016-04-13 08:20:31 6DB3EFE1174B79571A28355A732B3337 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2016-04-13 08:20:28 866254892512D27510475080EEC15748 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2016-04-13 08:20:10 9AD833027AF42AEFCA1FE6CD64F31B22 38120 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2016-04-13 08:20:04 2D98A2C9EC46ADE57B04DE54672DB205 49664 ----a-w- C:\Windows\servicing\GC64\tzupd.exe
=== C: other files ==
2016-04-16 10:33:37 78488AF2AB2111D67B3C4044707A519B 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2016-04-16 10:33:02 78BFF5425E044086E74E78650A359FBB 27008 ----a-w- C:\Windows\System32\drivers\mbam.sys
2016-04-16 10:33:02 452ACB7A9914398D9E18CCCFFCF92208 64896 ----a-w- C:\Windows\System32\drivers\mwac.sys
2016-04-16 10:33:02 1239597BAB7EED2BB16D035AF87E65D9 140672 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2016-04-13 08:20:33 FB4397DDCC732DB6A7B33B747C7EB708 154344 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2016-04-13 08:20:33 B6C2FA7F5E5BC1A488A57C6344D29D64 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2016-04-13 08:20:33 ACEC16415275E1AD6F7983EF472810E3 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2016-04-13 08:20:32 A9FB80B0BBA6F765F4E691B7AD4963A7 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2016-04-13 08:20:32 1D4B7972375052F5B7877A6FD9BE33A0 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2016-04-13 08:20:32 0F276F2F2018296FABC7BD2BCCAAB40B 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2016-04-13 08:20:20 616387BBD83372220B09DE95F4E67BBC 73664 ----a-w- C:\Windows\System32\drivers\disk.sys
2016-04-13 08:20:18 1D0A5FF3C7C7EA7480429D16D38B60EA 3216896 ----a-w- C:\Windows\System32\win32k.sys
==== Orphaned Tasks deleted from Registry ======================
avast Emergency Update deleted
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"="C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe -c"
"cz.seznam.software.szndesktop"="C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"USB Safely Remove"="C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup"
"GalaxyClient"="C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [08.04.2016 13:34]
==== Other Scheduled Tasks ======================
"C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\AVAST Software\Avast settings backup" [C:\Program Files\Common Files\AV\avast Antivirus\backup.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [04.01.2016 12:52]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- Auto Refresh em:version1.0.2.1-signed em:creatorGrizzly Ape em:descriptionRefresh tabs automatically at set intervals em:homepageURLhttp:www.grizzlyape.comaddonsauto-refresh em:iconURLchrome:autorefreshskinAuto Refresh 32X32.png em:optionsURLchrome:autorefreshcontentprefs-dialog.xul - %ProfilePath%\extensions\autorefresh@plugin.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
57C7E359ED8D049132EED23EFA444C63 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll - Shockwave Flash
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14.12.2015 15:22]
Avast Online Security - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Web Store Payments - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... 0000000000"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IESR02
HKCU\SearchScopes\{1D471673-7264-48B6-BB80-C994666E090B} - http://encyklopedie.seznam.cz/search?q= ... arch_12454
HKCU\SearchScopes\{343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} - http://www.mapy.cz/?query={searchTerms} ... arch_12454
HKCU\SearchScopes\{7570738B-2C59-4B16-82E3-9561343343AB} - http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
HKCU\SearchScopes\{75C2D683-8397-4749-9C4B-6BD774DA884B} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} - http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{A952281E-129E-4FCF-BBB8-D342E792185D} - http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
HKCU\SearchScopes\{B52B511D-2CBA-4900-996B-8FB7992F92C3} - http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
HKCU\SearchScopes\{FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} - http://www.novinky.cz/hledej?w={searchT ... arch_12454
==== Reset Google Chrome ======================
Nothing found to reset
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vitek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully
C:\Users\Vitek\AppData\Local\Mozilla\Firefox\Profiles\4a0ako7w.default\cache2 emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\storage\default\https+++www.diablofans.cz\cache emptied successfully
C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome Cache found
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1350 folders=556 152628822 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Vitek\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Vitek\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Vitek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2ELGTTQC\pornreactor.cc" not found
==== EOF on ne 17.04.2016 at 15:57:40,19 ======================
Re: kontrola logu chytil jsem trojana 2 stránky
Vloz aktualny log FRST
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: kontrola logu chytil jsem trojana 2 stránky
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016
Ran by Vitek (administrator) on VITEK-PC (17-04-2016 16:48:59)
Running from C:\Users\Vitek\Desktop
Loaded Profiles: Vitek (Available Profiles: Vitek)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSRService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-23] (NVIDIA Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-14] (AVAST Software)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [USB Safely Remove] => C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe [2468664 2013-03-13] (Crystal Rich Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [3931192 2016-03-26] (GOG.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-14] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224 2014-12-06] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424 2013-09-08] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{499A0B31-2460-439B-8906-899F1BEC8498}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131043123621972670&GUID=00000000-0000-0000-0000-000000000000
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {1D471673-7264-48B6-BB80-C994666E090B} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {7570738B-2C59-4B16-82E3-9561343343AB} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {75C2D683-8397-4749-9C4B-6BD774DA884B} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {A952281E-129E-4FCF-BBB8-D342E792185D} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {B52B511D-2CBA-4900-996B-8FB7992F92C3} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-02] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-14] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-02] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-14] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: about:newtab
FF DefaultSearchEngine: yessearches
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-04]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-01-04]
Chrome:
=======
CHR Profile: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-25]
CHR Extension: (Gmail) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-02]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-14] (AVAST Software)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [227896 2016-03-26] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6133816 2016-04-13] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-23] (NVIDIA Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-23] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-23] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-03-28] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-04-15] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [103736 2014-04-15] ()
R2 USBSafelyRemoveService; C:\Program Files (x86)\USB Safely Remove\USBSRService.exe [1521464 2013-03-13] (Crystal Rich Ltd)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-14] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-03-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [464256 2016-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-14] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-17] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Marvell Semiconductor, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-12-31] () [File not signed]
U3 a3ume4ui; C:\Windows\System32\Drivers\a3ume4ui.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 usbbus; system32\DRIVERS\lgx64bus.sys [X]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-17 16:48 - 2016-04-17 16:49 - 00019548 _____ C:\Users\Vitek\Desktop\FRST.txt
2016-04-17 15:14 - 2016-04-17 14:20 - 00024064 _____ C:\Windows\zoek-delete.exe
2016-04-16 18:58 - 2016-04-09 16:27 - 00051485 _____ C:\Users\Vitek\Desktop\Survivor.S32E08.HDTV.x264-FUM.srt
2016-04-16 18:14 - 2016-04-16 18:20 - 430134729 _____ C:\Users\Vitek\Desktop\Survivor.S32E08.HDTV.x264-FUM.mp4
2016-04-16 18:01 - 2016-04-16 18:01 - 00046786 _____ C:\Users\Vitek\Desktop\Agents of SHIELD - S03E16 Paradise Lost (KILLERS).srt
2016-04-16 17:16 - 2016-04-16 17:37 - 285132423 _____ C:\Users\Vitek\Desktop\Agents.of.S.H.I.E.L.D.S03E16.Paradise.Lost.HDTV.x264-KILLERS.mkv
2016-04-16 12:33 - 2016-04-17 16:03 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-16 12:33 - 2016-04-16 13:24 - 00001096 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-16 12:33 - 2016-04-16 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-16 12:33 - 2016-04-16 12:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-16 12:33 - 2016-04-16 12:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-04-16 12:33 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-04-16 12:33 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-04-16 12:33 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-04-16 10:43 - 2016-04-16 10:43 - 00007600 _____ C:\Users\Vitek\AppData\Local\Resmon.ResmonCfg
2016-04-15 19:54 - 2016-04-15 19:54 - 00003053 _____ C:\Users\Vitek\Desktop\JRT.txt
2016-04-15 12:01 - 2016-04-17 14:56 - 00000000 ____D C:\zoek_backup
2016-04-15 10:46 - 2016-04-15 10:46 - 01610352 _____ (Malwarebytes) C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 10:46 - 2016-04-15 10:46 - 01309184 _____ C:\Users\Vitek\Desktop\zoek.exe
2016-04-15 09:38 - 2016-04-15 09:40 - 00000000 ____D C:\AdwCleaner
2016-04-15 09:27 - 2016-04-17 16:48 - 00000000 ____D C:\FRST
2016-04-15 09:24 - 2016-04-15 09:25 - 02375168 _____ (Farbar) C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 09:23 - 2016-04-15 09:23 - 03677760 _____ C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 10:20 - 2016-04-04 20:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-04-13 10:20 - 2016-04-04 20:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-04-13 10:20 - 2016-04-02 15:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-04-13 10:20 - 2016-03-29 19:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-04-13 10:20 - 2016-03-23 16:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-04-13 10:20 - 2016-03-18 01:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 01:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-04-13 10:20 - 2016-03-18 01:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-04-13 10:20 - 2016-03-18 01:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-04-13 10:20 - 2016-03-18 01:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-13 10:20 - 2016-03-18 01:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-04-13 10:20 - 2016-03-18 00:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 10:20 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 00:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-04-13 10:20 - 2016-03-17 23:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-04-13 10:20 - 2016-03-17 23:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-04-13 10:20 - 2016-03-17 23:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-13 10:20 - 2016-03-17 23:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-04-13 10:20 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-04-13 10:20 - 2016-03-17 23:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-13 10:20 - 2016-03-17 23:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 10:20 - 2016-03-17 23:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-04-13 10:20 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-04-13 10:20 - 2016-03-16 20:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-04-13 10:20 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-04-13 10:20 - 2016-03-11 20:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-04-13 10:20 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 10:20 - 2016-02-05 20:56 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2016-04-13 10:20 - 2016-02-05 20:54 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-04-13 10:20 - 2016-02-05 19:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2016-04-13 10:20 - 2016-02-02 20:57 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-04-13 10:20 - 2016-01-21 02:51 - 00073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2016-04-13 10:20 - 2015-06-03 22:21 - 00451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-04-07 13:04 - 2016-04-07 13:11 - 354084323 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.mp4
2016-04-07 13:03 - 2016-04-02 21:17 - 00053363 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.srt
2016-03-29 19:43 - 2016-03-29 19:51 - 00244810 _____ C:\Users\Vitek\Desktop\Daně Dana.xlsx
2016-03-29 19:43 - 2016-03-29 19:43 - 00238031 _____ C:\Users\Vitek\Desktop\Daňe Víťa.xlsx
2016-03-27 15:56 - 2016-03-27 15:56 - 00000000 ____D C:\Users\Vitek\AppData\Local\CrashDumps
2016-03-27 15:52 - 2013-10-27 15:58 - 00073728 _____ ( ) C:\Windows\system\vdremote.dll
2016-03-27 15:52 - 2013-10-27 15:58 - 00065536 _____ ( ) C:\Windows\system\vdsvrlnk.dll
2016-03-21 16:22 - 2016-04-16 19:02 - 00000000 ____D C:\Users\Vitek\Desktop\Army
2016-03-20 19:42 - 2016-03-21 10:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-17 16:34 - 2014-02-12 15:08 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-17 16:04 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-17 16:04 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-17 16:02 - 2013-12-31 13:00 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Seznam.cz
2016-04-17 15:59 - 2013-12-31 14:24 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-17 15:57 - 2014-11-09 12:41 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\USBSafelyRemove
2016-04-17 15:56 - 2013-12-31 13:18 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-17 15:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-17 15:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2016-04-17 11:05 - 2013-12-31 13:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-16 23:06 - 2013-12-31 13:16 - 01559268 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-04-16 23:06 - 2011-04-12 10:34 - 00668866 _____ C:\Windows\system32\perfh005.dat
2016-04-16 23:06 - 2011-04-12 10:34 - 00141526 _____ C:\Windows\system32\perfc005.dat
2016-04-16 23:06 - 2009-07-14 07:13 - 01559268 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-16 23:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-16 22:55 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Local\Battle.net
2016-04-16 22:25 - 2014-02-27 10:16 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-04-16 22:25 - 2014-01-05 18:58 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-04-16 13:24 - 2016-01-03 15:50 - 00001920 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-16 13:24 - 2015-11-27 17:20 - 00000790 _____ C:\Users\Vitek\Desktop\World of Tanks - Common Test.lnk
2016-04-16 13:24 - 2015-07-02 10:07 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-04-16 13:24 - 2015-05-22 13:47 - 00001049 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
2016-04-16 13:24 - 2015-04-28 18:20 - 00000848 _____ C:\Users\Public\Desktop\World of Tanks.lnk
2016-04-16 13:24 - 2014-12-27 12:38 - 00001105 _____ C:\Users\Vitek\Desktop\USB Safely Remove.lnk
2016-04-16 13:24 - 2014-11-25 14:54 - 00001318 _____ C:\Users\Public\Desktop\Dragon Age Inquisition.lnk
2016-04-16 13:24 - 2014-11-25 13:27 - 00000973 _____ C:\Users\Public\Desktop\Origin.lnk
2016-04-16 13:24 - 2014-11-20 19:08 - 00001665 _____ C:\Users\Public\Desktop\The Battle for Middle-earth (tm).lnk
2016-04-16 13:24 - 2014-03-30 15:27 - 00001107 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software602 Form Filler.lnk
2016-04-16 13:24 - 2014-02-27 10:16 - 00001140 _____ C:\Users\Public\Desktop\Battle.net.lnk
2016-04-16 13:24 - 2014-02-11 13:29 - 00001865 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
2016-04-16 13:24 - 2014-01-21 20:25 - 00002710 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
2016-04-16 13:24 - 2014-01-05 18:58 - 00001134 _____ C:\Users\Public\Desktop\Diablo III.lnk
2016-04-16 13:24 - 2013-12-31 14:24 - 00000911 _____ C:\Users\Public\Desktop\Steam.lnk
2016-04-16 13:24 - 2013-12-31 13:56 - 00000973 _____ C:\Users\Public\Desktop\Winamp.lnk
2016-04-16 13:24 - 2013-12-31 13:49 - 00001944 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-04-16 13:24 - 2013-12-31 13:47 - 00000860 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-04-16 13:24 - 2013-12-31 13:43 - 00001573 _____ C:\Users\Vitek\Desktop\bsplayer.lnk
2016-04-16 13:24 - 2013-12-31 13:00 - 00000632 _____ C:\Users\Vitek\Desktop\Total Commander.lnk
2016-04-16 13:24 - 2013-12-31 12:58 - 00001861 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-16 13:24 - 2013-12-31 12:58 - 00001855 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-16 13:24 - 2013-12-31 12:38 - 00001393 _____ C:\Users\Vitek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-16 13:24 - 2013-12-31 12:35 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-04-16 13:24 - 2013-12-31 12:35 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-04-16 13:24 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-04-16 13:24 - 2009-07-14 06:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-04-16 13:24 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-04-16 13:12 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-04-16 13:11 - 2014-11-18 18:29 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-04-14 11:46 - 2009-07-14 06:45 - 00417568 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-14 11:43 - 2014-12-11 22:58 - 00000000 ____D C:\Windows\system32\appraiser
2016-04-13 09:33 - 2014-03-23 17:45 - 00000000 ____D C:\Movie
2016-04-08 13:34 - 2014-02-12 15:08 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-08 13:34 - 2013-12-31 13:46 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-08 13:34 - 2013-12-31 13:46 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 13:13 - 2013-12-31 13:35 - 00000000 ____D C:\Program Files (x86)\Google
2016-04-07 12:46 - 2014-01-21 20:17 - 00000000 ____D C:\Hudba
2016-04-06 10:18 - 2010-11-21 05:27 - 00453280 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-05 17:36 - 2015-05-20 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-03-28 13:16 - 2014-11-25 13:27 - 00000000 ____D C:\ProgramData\Origin
2016-03-28 13:15 - 2014-11-25 13:26 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-27 15:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2016-03-27 14:24 - 2015-05-20 11:16 - 00000000 ____D C:\Users\Vitek\Documents\The Witcher 3
2016-03-26 11:58 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Battle.net
2016-03-26 11:58 - 2014-01-05 18:57 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2016-03-23 13:05 - 2014-01-03 21:50 - 00000000 ____D C:\Users\Vitek\Desktop\Práce
2016-03-21 16:32 - 2016-03-14 18:20 - 00000000 ____D C:\Users\Vitek\Desktop\Nová složka (2)
2016-03-21 16:23 - 2014-07-01 12:55 - 00000000 ____D C:\Users\Vitek\Desktop\Mamka
2016-03-21 16:22 - 2015-11-16 10:45 - 00000000 ____D C:\Users\Vitek\Desktop\Běh treninky
2016-03-21 16:22 - 2015-09-03 19:25 - 00000000 ____D C:\Users\Vitek\Desktop\Brácha
2016-03-21 14:04 - 2013-12-31 13:55 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Skype
2016-03-21 10:29 - 2013-12-31 12:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2014-08-03 11:14 - 2014-08-03 11:14 - 0000135 _____ () C:\Users\Vitek\AppData\Roaming\default.rss
2014-09-11 12:20 - 2014-09-11 12:20 - 0000001 _____ () C:\Users\Vitek\AppData\Local\llftool.4.40.agreement
2016-04-16 10:43 - 2016-04-16 10:43 - 0007600 _____ () C:\Users\Vitek\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 09:30
==================== End of FRST.txt ============================
Ran by Vitek (administrator) on VITEK-PC (17-04-2016 16:48:59)
Running from C:\Users\Vitek\Desktop
Loaded Profiles: Vitek (Available Profiles: Vitek)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSRService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Crystal Rich Ltd) C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-23] (NVIDIA Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-14] (AVAST Software)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Vitek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [USB Safely Remove] => C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe [2468664 2013-03-13] (Crystal Rich Ltd)
HKU\S-1-5-21-766063956-928861102-2534699601-1000\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [3931192 2016-03-26] (GOG.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-14] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Vitek\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224 2014-12-06] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424 2013-09-08] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992 2009-07-14] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{499A0B31-2460-439B-8906-899F1BEC8498}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-766063956-928861102-2534699601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131043123621972670&GUID=00000000-0000-0000-0000-000000000000
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {1D471673-7264-48B6-BB80-C994666E090B} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {343CAAFA-F5C8-4085-B2C6-CE8FFC07E8AC} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {7570738B-2C59-4B16-82E3-9561343343AB} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {75C2D683-8397-4749-9C4B-6BD774DA884B} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {8ADAEBB4-C5CD-4E35-8F4A-FD40E268E7B0} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {A952281E-129E-4FCF-BBB8-D342E792185D} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {B52B511D-2CBA-4900-996B-8FB7992F92C3} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-766063956-928861102-2534699601-1000 -> {FBCA484F-C0E7-4FCA-8DDE-78355FA3C028} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-02] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-14] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-02] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-14] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: about:newtab
FF DefaultSearchEngine: yessearches
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-02] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Auto Refresh - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\autorefresh@plugin.xpi [2015-05-31]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\4a0ako7w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF Extension: Adblock Plus - C:\Users\Vitek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-04]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-01-04]
Chrome:
=======
CHR Profile: C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-25]
CHR Extension: (Gmail) - C:\Users\Vitek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-02]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-14] (AVAST Software)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [227896 2016-03-26] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6133816 2016-04-13] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-23] (NVIDIA Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-23] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-23] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-03-28] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-04-15] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [103736 2014-04-15] ()
R2 USBSafelyRemoveService; C:\Program Files (x86)\USB Safely Remove\USBSRService.exe [1521464 2013-03-13] (Crystal Rich Ltd)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-20] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-14] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-03-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [464256 2016-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-14] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-17] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Marvell Semiconductor, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-12-31] () [File not signed]
U3 a3ume4ui; C:\Windows\System32\Drivers\a3ume4ui.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
S3 usbbus; system32\DRIVERS\lgx64bus.sys [X]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-17 16:48 - 2016-04-17 16:49 - 00019548 _____ C:\Users\Vitek\Desktop\FRST.txt
2016-04-17 15:14 - 2016-04-17 14:20 - 00024064 _____ C:\Windows\zoek-delete.exe
2016-04-16 18:58 - 2016-04-09 16:27 - 00051485 _____ C:\Users\Vitek\Desktop\Survivor.S32E08.HDTV.x264-FUM.srt
2016-04-16 18:14 - 2016-04-16 18:20 - 430134729 _____ C:\Users\Vitek\Desktop\Survivor.S32E08.HDTV.x264-FUM.mp4
2016-04-16 18:01 - 2016-04-16 18:01 - 00046786 _____ C:\Users\Vitek\Desktop\Agents of SHIELD - S03E16 Paradise Lost (KILLERS).srt
2016-04-16 17:16 - 2016-04-16 17:37 - 285132423 _____ C:\Users\Vitek\Desktop\Agents.of.S.H.I.E.L.D.S03E16.Paradise.Lost.HDTV.x264-KILLERS.mkv
2016-04-16 12:33 - 2016-04-17 16:03 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-16 12:33 - 2016-04-16 13:24 - 00001096 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-16 12:33 - 2016-04-16 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-16 12:33 - 2016-04-16 12:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-16 12:33 - 2016-04-16 12:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-04-16 12:33 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-04-16 12:33 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-04-16 12:33 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-04-16 10:43 - 2016-04-16 10:43 - 00007600 _____ C:\Users\Vitek\AppData\Local\Resmon.ResmonCfg
2016-04-15 19:54 - 2016-04-15 19:54 - 00003053 _____ C:\Users\Vitek\Desktop\JRT.txt
2016-04-15 12:01 - 2016-04-17 14:56 - 00000000 ____D C:\zoek_backup
2016-04-15 10:46 - 2016-04-15 10:46 - 01610352 _____ (Malwarebytes) C:\Users\Vitek\Desktop\JRT.exe
2016-04-15 10:46 - 2016-04-15 10:46 - 01309184 _____ C:\Users\Vitek\Desktop\zoek.exe
2016-04-15 09:38 - 2016-04-15 09:40 - 00000000 ____D C:\AdwCleaner
2016-04-15 09:27 - 2016-04-17 16:48 - 00000000 ____D C:\FRST
2016-04-15 09:24 - 2016-04-15 09:25 - 02375168 _____ (Farbar) C:\Users\Vitek\Desktop\FRST64.exe
2016-04-15 09:23 - 2016-04-15 09:23 - 03677760 _____ C:\Users\Vitek\Desktop\adwcleaner_5.111.exe
2016-04-13 10:20 - 2016-04-04 20:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-04-13 10:20 - 2016-04-04 20:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-04-13 10:20 - 2016-04-02 15:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-04-13 10:20 - 2016-03-29 19:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-04-13 10:20 - 2016-03-23 16:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-04-13 10:20 - 2016-03-18 01:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 01:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-04-13 10:20 - 2016-03-18 01:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-04-13 10:20 - 2016-03-18 01:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-04-13 10:20 - 2016-03-18 01:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-13 10:20 - 2016-03-18 01:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-04-13 10:20 - 2016-03-18 00:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-04-13 10:20 - 2016-03-18 00:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-04-13 10:20 - 2016-03-18 00:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 10:20 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 10:20 - 2016-03-18 00:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-04-13 10:20 - 2016-03-18 00:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 10:20 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 10:20 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-04-13 10:20 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-04-13 10:20 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-04-13 10:20 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-04-13 10:20 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 10:20 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-04-13 10:20 - 2016-03-17 23:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-04-13 10:20 - 2016-03-17 23:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-04-13 10:20 - 2016-03-17 23:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-13 10:20 - 2016-03-17 23:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-04-13 10:20 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-04-13 10:20 - 2016-03-17 23:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-04-13 10:20 - 2016-03-17 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-04-13 10:20 - 2016-03-17 23:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-13 10:20 - 2016-03-17 23:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 10:20 - 2016-03-17 23:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-04-13 10:20 - 2016-03-17 23:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-04-13 10:20 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-04-13 10:20 - 2016-03-17 20:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-04-13 10:20 - 2016-03-16 20:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 10:20 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-04-13 10:20 - 2016-03-16 02:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-04-13 10:20 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-04-13 10:20 - 2016-03-11 20:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-04-13 10:20 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-04-13 10:20 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 10:20 - 2016-02-05 20:56 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2016-04-13 10:20 - 2016-02-05 20:54 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-04-13 10:20 - 2016-02-05 19:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2016-04-13 10:20 - 2016-02-02 20:57 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-04-13 10:20 - 2016-01-21 02:51 - 00073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2016-04-13 10:20 - 2015-06-03 22:21 - 00451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-04-07 13:04 - 2016-04-07 13:11 - 354084323 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.mp4
2016-04-07 13:03 - 2016-04-02 21:17 - 00053363 _____ C:\Users\Vitek\Desktop\Chicago.Fire.S04E17.HDTV.x264-KILLERS.srt
2016-03-29 19:43 - 2016-03-29 19:51 - 00244810 _____ C:\Users\Vitek\Desktop\Daně Dana.xlsx
2016-03-29 19:43 - 2016-03-29 19:43 - 00238031 _____ C:\Users\Vitek\Desktop\Daňe Víťa.xlsx
2016-03-27 15:56 - 2016-03-27 15:56 - 00000000 ____D C:\Users\Vitek\AppData\Local\CrashDumps
2016-03-27 15:52 - 2013-10-27 15:58 - 00073728 _____ ( ) C:\Windows\system\vdremote.dll
2016-03-27 15:52 - 2013-10-27 15:58 - 00065536 _____ ( ) C:\Windows\system\vdsvrlnk.dll
2016-03-21 16:22 - 2016-04-16 19:02 - 00000000 ____D C:\Users\Vitek\Desktop\Army
2016-03-20 19:42 - 2016-03-21 10:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-17 16:34 - 2014-02-12 15:08 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-17 16:04 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-17 16:04 - 2009-07-14 06:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-17 16:02 - 2013-12-31 13:00 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Seznam.cz
2016-04-17 15:59 - 2013-12-31 14:24 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-17 15:57 - 2014-11-09 12:41 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\USBSafelyRemove
2016-04-17 15:56 - 2013-12-31 13:18 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-17 15:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-17 15:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2016-04-17 11:05 - 2013-12-31 13:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-16 23:06 - 2013-12-31 13:16 - 01559268 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-04-16 23:06 - 2011-04-12 10:34 - 00668866 _____ C:\Windows\system32\perfh005.dat
2016-04-16 23:06 - 2011-04-12 10:34 - 00141526 _____ C:\Windows\system32\perfc005.dat
2016-04-16 23:06 - 2009-07-14 07:13 - 01559268 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-16 23:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-16 22:55 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Local\Battle.net
2016-04-16 22:25 - 2014-02-27 10:16 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-04-16 22:25 - 2014-01-05 18:58 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-04-16 13:24 - 2016-01-03 15:50 - 00001920 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-16 13:24 - 2015-11-27 17:20 - 00000790 _____ C:\Users\Vitek\Desktop\World of Tanks - Common Test.lnk
2016-04-16 13:24 - 2015-07-02 10:07 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-04-16 13:24 - 2015-05-22 13:47 - 00001049 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
2016-04-16 13:24 - 2015-04-28 18:20 - 00000848 _____ C:\Users\Public\Desktop\World of Tanks.lnk
2016-04-16 13:24 - 2014-12-27 12:38 - 00001105 _____ C:\Users\Vitek\Desktop\USB Safely Remove.lnk
2016-04-16 13:24 - 2014-11-25 14:54 - 00001318 _____ C:\Users\Public\Desktop\Dragon Age Inquisition.lnk
2016-04-16 13:24 - 2014-11-25 13:27 - 00000973 _____ C:\Users\Public\Desktop\Origin.lnk
2016-04-16 13:24 - 2014-11-20 19:08 - 00001665 _____ C:\Users\Public\Desktop\The Battle for Middle-earth (tm).lnk
2016-04-16 13:24 - 2014-03-30 15:27 - 00001107 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software602 Form Filler.lnk
2016-04-16 13:24 - 2014-02-27 10:16 - 00001140 _____ C:\Users\Public\Desktop\Battle.net.lnk
2016-04-16 13:24 - 2014-02-11 13:29 - 00001865 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
2016-04-16 13:24 - 2014-01-21 20:25 - 00002710 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
2016-04-16 13:24 - 2014-01-05 18:58 - 00001134 _____ C:\Users\Public\Desktop\Diablo III.lnk
2016-04-16 13:24 - 2013-12-31 14:24 - 00000911 _____ C:\Users\Public\Desktop\Steam.lnk
2016-04-16 13:24 - 2013-12-31 13:56 - 00000973 _____ C:\Users\Public\Desktop\Winamp.lnk
2016-04-16 13:24 - 2013-12-31 13:49 - 00001944 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-04-16 13:24 - 2013-12-31 13:47 - 00000860 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-04-16 13:24 - 2013-12-31 13:43 - 00001573 _____ C:\Users\Vitek\Desktop\bsplayer.lnk
2016-04-16 13:24 - 2013-12-31 13:00 - 00000632 _____ C:\Users\Vitek\Desktop\Total Commander.lnk
2016-04-16 13:24 - 2013-12-31 12:58 - 00001861 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-16 13:24 - 2013-12-31 12:58 - 00001855 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-16 13:24 - 2013-12-31 12:38 - 00001393 _____ C:\Users\Vitek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-16 13:24 - 2013-12-31 12:35 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-04-16 13:24 - 2013-12-31 12:35 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-04-16 13:24 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-04-16 13:24 - 2009-07-14 06:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-04-16 13:24 - 2009-07-14 06:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-04-16 13:24 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-04-16 13:12 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-04-16 13:11 - 2014-11-18 18:29 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-04-14 11:46 - 2009-07-14 06:45 - 00417568 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-14 11:43 - 2014-12-11 22:58 - 00000000 ____D C:\Windows\system32\appraiser
2016-04-13 09:33 - 2014-03-23 17:45 - 00000000 ____D C:\Movie
2016-04-08 13:34 - 2014-02-12 15:08 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-08 13:34 - 2013-12-31 13:46 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-08 13:34 - 2013-12-31 13:46 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 13:13 - 2013-12-31 13:35 - 00000000 ____D C:\Program Files (x86)\Google
2016-04-07 12:46 - 2014-01-21 20:17 - 00000000 ____D C:\Hudba
2016-04-06 10:18 - 2010-11-21 05:27 - 00453280 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-05 17:36 - 2015-05-20 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-03-28 13:16 - 2014-11-25 13:27 - 00000000 ____D C:\ProgramData\Origin
2016-03-28 13:15 - 2014-11-25 13:26 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-27 15:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2016-03-27 14:24 - 2015-05-20 11:16 - 00000000 ____D C:\Users\Vitek\Documents\The Witcher 3
2016-03-26 11:58 - 2014-02-27 10:16 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Battle.net
2016-03-26 11:58 - 2014-01-05 18:57 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-24 19:32 - 2015-04-04 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2016-03-23 13:05 - 2014-01-03 21:50 - 00000000 ____D C:\Users\Vitek\Desktop\Práce
2016-03-21 16:32 - 2016-03-14 18:20 - 00000000 ____D C:\Users\Vitek\Desktop\Nová složka (2)
2016-03-21 16:23 - 2014-07-01 12:55 - 00000000 ____D C:\Users\Vitek\Desktop\Mamka
2016-03-21 16:22 - 2015-11-16 10:45 - 00000000 ____D C:\Users\Vitek\Desktop\Běh treninky
2016-03-21 16:22 - 2015-09-03 19:25 - 00000000 ____D C:\Users\Vitek\Desktop\Brácha
2016-03-21 14:04 - 2013-12-31 13:55 - 00000000 ____D C:\Users\Vitek\AppData\Roaming\Skype
2016-03-21 10:29 - 2013-12-31 12:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2014-08-03 11:14 - 2014-08-03 11:14 - 0000135 _____ () C:\Users\Vitek\AppData\Roaming\default.rss
2014-09-11 12:20 - 2014-09-11 12:20 - 0000001 _____ () C:\Users\Vitek\AppData\Local\llftool.4.40.agreement
2016-04-16 10:43 - 2016-04-16 10:43 - 0007600 _____ () C:\Users\Vitek\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 09:30
==================== End of FRST.txt ============================


Přispějete na provoz fóra?