Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-02-2017
Ran by Toshiba (administrator) on TOSH (14-02-2017 07:34:36)
Running from C:\Users\Toshiba\Desktop
Loaded Profiles: Toshiba (Available Profiles: Toshiba)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe
(Opera Software) C:\Program Files (x86)\Opera\41.0.2353.56\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\41.0.2353.56\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\41.0.2353.56\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\41.0.2353.56\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\41.0.2353.56\opera.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-808137394-3989240724-1605283320-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [26414208 2016-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-808137394-3989240724-1605283320-1000\...\Run: [Google Update] => C:\Users\Toshiba\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-17] (Google Inc.)
HKU\S-1-5-21-808137394-3989240724-1605283320-1000\...\MountPoints2: F - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-808137394-3989240724-1605283320-1000\...\MountPoints2: {6ad94e18-4290-11e6-a4d4-00266c7c5f10} - F:\autorun.exe
HKU\S-1-5-18\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2014-12-31] (AVAST Software)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2010-04-21]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2010-04-21]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{B8533C26-E6B1-4FED-95EA-A55F0DC1494F}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-808137394-3989240724-1605283320-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=27368
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> DefaultScope {F5D6F02F-F53E-4A79-8855-3E209C76F8A2} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> 079B45E8534F983BE4F584287D046DFD URL = hxxp://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> 41A39C2DE31D958A4B89BABFF9DAA1B6 URL =
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> 7F01D70BFEFB934BA161B9AD8979F1FD URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> A2B396AC96C168442F43A5113A588BAF URL = hxxp://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> F5C907575233E8D73E504F986286A271 URL = hxxp://www.mapy.cz/?sourceid=quicksearch_6826& ... earchTerms}
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {2F37C187-BEF3-4EAB-80AB-EA5297A43D98} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {4DF69133-72A6-4808-BC21-5AB08FBDCE48} URL = hxxp://www.amazon.co.uk/gp/search?ie=UTF8&keyw ... nkCode=ur2
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {5D31D73E-3D80-45BC-A41E-E465884FB20E} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {8F578E91-1464-458C-9FBB-26B222EED7F6} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {B029E542-AE52-42A1-A8A3-C0E671CFA0C2} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {B172F16F-2868-426C-BC25-184CB9AD7B62} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {B384E0C5-F75F-4A6E-82B5-C5A61D33602F} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {E0D10DFF-E459-47D1-B0AD-E34FDFEDE9C7} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {E1BD3646-F74B-403F-8645-4F14AFA24831} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_27368
SearchScopes: HKU\S-1-5-21-808137394-3989240724-1605283320-1000 -> {F5D6F02F-F53E-4A79-8855-3E209C76F8A2} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_27368
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-31] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-30] (Adobe Systems Incorporated)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-31] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-02] (<TOSHIBA>)
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\9nhpqzea.default [2016-08-20]
FF Homepage: Mozilla\Firefox\Profiles\9nhpqzea.default -> hxxp://www.seznam.cz/?clid=6826
FF Extension: (Avira Browser Safety) - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\9nhpqzea.default\Extensions\abs@avira.com [2014-12-29] [not signed]
FF Extension: (Seznam lištička) - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\9nhpqzea.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2016-08-15]
FF Extension: (No Name) - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha5336\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1413\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha577\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3874\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home266\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode6712\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release7823\ff [not found]
FF Extension: (No Name) - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha1603\ff [not found]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll [2013-10-25] (Adobe Systems, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-808137394-3989240724-1605283320-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Toshiba\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-808137394-3989240724-1605283320-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Toshiba\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-808137394-3989240724-1605283320-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Toshiba\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-03-05] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.yandex.ru/?__PARAM__from=chromehp
CHR DefaultSearchURL: Default -> hxxp://yandex.ru/yandsearch?__PARAM__from=chromesearch&text={searchTerms}
CHR DefaultSearchKeyword: Default -> yandex.ru
CHR DefaultSuggestURL: Default -> hxxp://suggest.yandex.net/suggest-ff.cgi?uil=ru&part={searchTerms}
CHR Profile: C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default [2017-02-14]
CHR Extension: (Dokumenty Google) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Volání přes Skype) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2016-08-25]
CHR Extension: (Avast Online Security) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Chrome Media Router) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-09]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-31]
StartMenuInternet: Google Chrome.TXZ3EZMFRXESRW2SL4IWG7NJV4 - C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-31] (AVAST Software)
S4 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-02-11] (Toshiba Europe GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-31] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-31] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-31] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-31] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-31] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-31] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-31] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-05-07] () [File not signed]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-14 07:34 - 2017-02-14 07:35 - 00016129 _____ C:\Users\Toshiba\Desktop\FRST.txt
2017-02-14 07:34 - 2017-02-14 07:34 - 00000000 ____D C:\FRST
2017-02-14 07:33 - 2017-02-14 07:33 - 00025660 _____ C:\Users\Toshiba\Desktop\info.txt
2017-02-14 07:22 - 2017-02-14 07:22 - 02422272 _____ (Farbar) C:\Users\Toshiba\Desktop\FRST64.exe
2017-02-14 07:20 - 2017-02-14 07:21 - 00000000 ____D C:\rsit
2017-02-14 07:20 - 2017-02-14 07:21 - 00000000 ____D C:\Program Files\trend micro
2017-02-14 07:20 - 2017-02-14 07:20 - 01323520 _____ C:\Users\Toshiba\Desktop\RSITx64.exe
2017-02-14 07:18 - 2017-02-14 07:18 - 00008895 _____ C:\Users\Toshiba\Desktop\dds.txt
2017-02-14 07:18 - 2017-02-14 07:18 - 00003728 _____ C:\Users\Toshiba\Desktop\attach.txt
2017-02-14 07:13 - 2017-02-14 07:14 - 00688992 ____R (Swearware) C:\Users\Toshiba\Desktop\dds.exe
2017-02-14 07:10 - 2017-02-14 07:10 - 00003838 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1409078827
2017-01-29 11:32 - 2017-01-29 11:32 - 00388452 _____ C:\Users\Toshiba\Downloads\vypoved-z-najmu-vzor.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-14 07:31 - 2013-09-18 08:44 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-14 07:14 - 2009-07-14 05:45 - 00016080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-02-14 07:14 - 2009-07-14 05:45 - 00016080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-02-14 07:11 - 2014-08-26 19:47 - 00000000 ____D C:\Program Files (x86)\Opera
2017-02-14 07:06 - 2014-12-31 11:29 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2017-02-14 07:06 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-12 10:46 - 2009-07-14 16:18 - 00623104 _____ C:\Windows\system32\perfh005.dat
2017-02-12 10:46 - 2009-07-14 16:18 - 00118996 _____ C:\Windows\system32\perfc005.dat
2017-02-12 10:46 - 2009-07-14 06:13 - 01447310 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-12 10:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2017-02-11 20:49 - 2016-02-25 22:22 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-02-07 17:02 - 2014-12-20 20:03 - 00002386 _____ C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-28 21:58 - 2012-04-12 16:37 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\SoftGrid Client
2017-01-28 13:47 - 2015-07-25 14:50 - 00000000 ___SD C:\Users\Toshiba\AppData\LocalLow\Temp
==================== Files in the root of some directories =======
2014-08-27 19:23 - 2014-08-27 19:23 - 0000029 _____ () C:\Users\Toshiba\AppData\Roaming\msjfecf.dat
2014-08-19 16:54 - 2014-08-19 16:54 - 0009488 _____ () C:\Users\Toshiba\AppData\Roaming\msjnhtjj.dat
2014-08-27 19:23 - 2014-08-27 19:23 - 0008342 _____ () C:\Users\Toshiba\AppData\Roaming\mslcoh.dat
2014-08-19 16:54 - 2014-08-26 20:54 - 0000028 _____ () C:\Users\Toshiba\AppData\Roaming\msrccbr.dat
2014-06-18 00:29 - 2014-06-18 00:29 - 0007602 _____ () C:\Users\Toshiba\AppData\Local\Resmon.ResmonCfg
2013-07-12 13:49 - 2013-07-12 13:49 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2013-09-06 12:49 - 2013-09-06 12:49 - 0064604 ____T (Microsoft Corporation) C:\ProgramData\wlwlbngla.pzz
Some files in TEMP:
====================
2017-01-26 18:05 - 2017-01-26 18:05 - 0000000 _____ () C:\Users\Toshiba\AppData\Local\Temp\GUR3DE9.exe
2016-08-20 16:04 - 2016-08-11 12:33 - 5168856 _____ (Mail.Ru) C:\Users\Toshiba\AppData\Local\Temp\MailRuUpdater.exe
2016-08-20 16:17 - 2016-08-20 16:17 - 1972224 _____ (BitTorrent Inc.) C:\Users\Toshiba\AppData\Local\Temp\utt1393.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-08-12 10:49
==================== End of FRST.txt ============================



Přispějete na provoz fóra?