přeji pěkný den ,zde přidám logy
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by milan (administrator) on MILAN-PC92 (14-03-2016 07:37:12)
Running from C:\Users\milan\Desktop
Loaded Profiles: milan (Available Profiles: milan)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(BitTorrent Inc.) C:\Users\milan\AppData\Roaming\uTorrent\uTorrent.exe
(BitTorrent Inc.) C:\Users\milan\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(BitTorrent Inc.) C:\Users\milan\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7137664 2016-03-13] (AVAST Software)
HKU\S-1-5-21-970700664-739145876-1605578078-1001\...\Run: [uTorrent] => C:\Users\milan\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-05] (BitTorrent Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-03-13] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\milan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.254
Tcpip\..\Interfaces\{0F399F2C-76CF-45F5-BD8D-CB10351F63CD}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A69B7D48-CC23-4C8B-9B73-5A5ADCD2F6C9}: [DhcpNameServer] 192.168.2.254
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-970700664-739145876-1605578078-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-13] (AVAST Software)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-970700664-739145876-1605578078-1001: @tools.google.com/Google Update;version=3 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-970700664-739145876-1605578078-1001: @tools.google.com/Google Update;version=9 -> C:\Users\milan\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-02] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-13]
Chrome:
=======
CHR HomePage: Default -> hxxps://
www.seznam.cz/
CHR Profile: C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-27]
CHR Extension: (Dokumenty Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-27]
CHR Extension: (Disk Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-06]
CHR Extension: (Tabulky Google) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-20]
CHR Extension: (AdBlock) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-12]
CHR Extension: (Avast Online Security) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-03-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-13]
StartMenuInternet: Google Chrome.MKCNDVG6DVYBTZV7TSRNF4RZEY - C:\Users\milan\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-13] (AVAST Software)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
R2 TeamViewer9; D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2449624 2015-08-04] (AVG Technologies)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [36568 2015-08-04] (AVG Technologies)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [32792 2016-03-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91168 2016-03-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [91232 2016-03-13] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [58776 2016-03-13] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [816304 2016-03-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447848 2016-03-13] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [127432 2016-03-13] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [221240 2016-03-13] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-06-28] (Disc Soft Ltd)
S3 KYEGKB; C:\Windows\System32\Drivers\KYEGKB.sys [27648 2011-07-31] ( )
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-13] (NXP Semiconductors)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [184192 2014-10-13] (DEVGURU Co., LTD.(
www.devguru.co.kr))
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [30632 2015-06-25] (TuneUp Software)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [15872 2013-02-12] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\milan\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-14 07:37 - 2016-03-14 07:37 - 00010875 _____ C:\Users\milan\Desktop\FRST.txt
2016-03-14 07:36 - 2016-03-14 07:36 - 00112640 _____ (forum.viry.cz) C:\Users\milan\Desktop\FRSTLauncher.exe
2016-03-14 07:35 - 2016-03-14 07:35 - 01725440 _____ (Farbar) C:\Users\milan\Desktop\FRST.exe
2016-03-13 18:48 - 2016-03-13 18:46 - 00334280 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-03-13 18:47 - 2016-03-13 18:47 - 00002035 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-13 18:47 - 2016-03-13 18:47 - 00000000 ____D C:\Users\milan\AppData\Roaming\AVAST Software
2016-03-13 18:47 - 2016-03-13 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-03-13 18:46 - 2016-03-13 18:47 - 00816304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-03-13 18:46 - 2016-03-13 18:47 - 00091168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00447848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00221240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00127432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00091232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00058776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-03-13 18:46 - 2016-03-13 18:46 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-03-13 18:46 - 2016-03-13 18:46 - 00032792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-03-13 18:45 - 2016-03-13 18:45 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-13 18:42 - 2016-03-13 18:43 - 05207096 _____ (AVAST Software) C:\Users\milan\Downloads\avast_free_antivirus_setup_online.exe
2016-03-13 18:33 - 2016-03-13 18:33 - 00000000 ____D C:\Users\milan\AppData\Local\CrashDumps
2016-03-13 18:23 - 2016-03-13 18:23 - 00000000 ____D C:\ProgramData\SMR501
2016-03-13 17:41 - 2016-03-13 17:41 - 00000000 _____ C:\Users\milan\Desktop\Nový textový dokument (2).txt
2016-03-13 17:37 - 2016-03-13 18:23 - 00000537 _____ C:\Users\milan\Desktop\Fixlog.txt
2016-03-13 17:37 - 2016-03-13 17:37 - 00155765 _____ C:\Users\milan\Desktop\Upload.zip
2016-03-13 17:37 - 2016-03-13 17:37 - 00029696 _____ C:\Users\milan\AppData\Local\MSGBOX.EXE
2016-03-13 17:37 - 2016-03-13 17:37 - 00015327 _____ C:\Users\milan\Desktop\LM.bat
2016-03-13 15:35 - 2015-08-04 13:25 - 00036568 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll
2016-03-13 15:33 - 2016-03-14 07:32 - 00252654 _____ C:\Windows\ntbtlog.txt
2016-03-13 15:33 - 2015-08-04 13:25 - 00037080 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe
2016-03-13 15:33 - 2015-08-04 13:25 - 00025816 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll
2016-03-13 15:32 - 2016-03-13 15:32 - 00002135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk
2016-03-13 15:32 - 2016-03-13 15:32 - 00002123 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2015.lnk
2016-03-13 15:32 - 2016-03-13 15:32 - 00002109 _____ C:\Users\Public\Desktop\AVG údržba 1 kliknutím.lnk
2016-03-13 15:32 - 2016-03-13 15:32 - 00000000 ____D C:\Users\milan\AppData\Roaming\AVG
2016-03-13 15:32 - 2016-03-13 15:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015
2016-03-13 15:32 - 2016-03-13 15:32 - 00000000 ____D C:\Program Files\AVG
2016-03-13 15:29 - 2016-03-13 15:41 - 00000000 ____D C:\ProgramData\AVG
2016-03-13 15:26 - 2016-03-13 15:27 - 90844984 _____ (AVG Technologies) C:\Users\milan\Downloads\avg_tuht_stf_all_2015_238.exe
2016-03-13 15:18 - 2016-03-13 15:18 - 00700104 _____ (ESET) C:\Users\milan\Downloads\ESETUninstaller.exe
2016-03-13 15:00 - 2016-03-13 15:03 - 00000000 ____D C:\AVG_Remover
2016-03-13 14:57 - 2016-03-14 07:32 - 00000000 ____D C:\Users\milan\AppData\LocalLow\uTorrent
2016-03-13 14:52 - 2016-03-13 14:52 - 00326144 _____ (AVAST Software) C:\Users\milan\Downloads\aswclear.exe
2016-03-13 14:40 - 2016-03-13 14:40 - 00000000 ____H C:\Users\milan\Documents\Default.rdp
2016-03-13 14:12 - 2016-03-13 14:12 - 00013707 _____ C:\ComboFix.txt
2016-03-13 13:56 - 2016-03-13 13:56 - 00000000 _____ C:\Users\milan\Desktop\Nový textový dokument.txt
2016-03-13 09:25 - 2016-03-13 14:12 - 00000000 ____D C:\Qoobox
2016-03-13 09:25 - 2016-03-13 14:06 - 00000000 ____D C:\Windows\erdnt
2016-03-13 09:25 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2016-03-13 09:25 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2016-03-13 09:25 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2016-03-13 09:25 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2016-03-13 09:16 - 2016-03-13 09:18 - 00003620 _____ C:\Users\milan\Desktop\Rkill.txt
2016-03-13 09:14 - 2016-03-13 09:14 - 05658088 ____R (Swearware) C:\Users\milan\Desktop\ComboFix.exe
2016-03-13 09:13 - 2016-03-13 09:13 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\milan\Desktop\rkill.exe
2016-03-13 01:12 - 2016-03-13 09:09 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-13 01:10 - 2016-03-13 01:33 - 00000000 ____D C:\Users\milan\Desktop\mbar
2016-03-13 01:09 - 2016-03-13 01:09 - 16563352 _____ (Malwarebytes Corp.) C:\Users\milan\Desktop\mbar-1.09.3.1001.exe
2016-03-13 01:06 - 2016-03-13 01:06 - 00008934 _____ C:\Users\milan\Desktop\Addition.rar
2016-03-12 23:45 - 2016-03-13 01:50 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-12 23:45 - 2016-03-13 01:10 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-12 23:45 - 2016-03-12 23:45 - 22908888 _____ (Malwarebytes ) C:\Users\milan\Downloads\mbam-setup-2.2.0.1024.exe
2016-03-12 23:45 - 2016-03-12 23:45 - 00001020 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-12 23:45 - 2016-03-12 23:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-12 23:45 - 2016-03-12 23:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-12 23:45 - 2016-03-12 23:45 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-03-12 23:45 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-12 23:45 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-12 23:43 - 2016-03-12 23:43 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-03-12 23:38 - 2016-03-12 23:41 - 00000000 ____D C:\Users\milan\AppData\Local\NPE
2016-03-12 23:15 - 2016-03-13 18:41 - 00000000 ____D C:\ProgramData\Norton
2016-03-12 22:49 - 2016-03-12 23:37 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-03-12 22:15 - 2016-03-12 22:15 - 00000000 ____D C:\ProgramData\ESET
2016-03-12 21:56 - 2016-03-12 21:56 - 00000000 ____D C:\RegBackup
2016-03-12 21:45 - 2016-03-12 21:46 - 18025373 _____ C:\Users\milan\Downloads\tweaking.com_windows_repair_aio.zip
2016-03-12 21:40 - 2016-03-12 21:40 - 00359656 _____ (Microsoft Corporation) C:\Users\milan\Downloads\msicuu2.exe
2016-03-11 15:26 - 2016-03-13 17:41 - 00000000 ____D C:\Users\milan\Desktop\Nová složka
2016-03-08 15:17 - 2016-03-12 23:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PRTG Network Monitor
2016-03-08 15:17 - 2016-03-08 15:17 - 00001024 _____ C:\.rnd
2016-03-08 15:17 - 2016-03-08 15:17 - 00000000 ____D C:\ProgramData\TEMP
2016-03-08 15:15 - 2016-03-12 23:20 - 00000000 ____D C:\Program Files\PRTG Network Monitor
2016-03-08 15:10 - 2016-03-08 15:10 - 130301427 _____ C:\Users\milan\Documents\prtg.zip
2016-03-08 12:06 - 2016-03-08 12:06 - 01524224 _____ C:\Users\milan\Downloads\adwcleaner_5.101.exe
2016-03-08 11:55 - 2016-03-13 00:13 - 00000000 ____D C:\Program Files\AdwCleaner
2016-03-08 11:47 - 2016-03-08 11:47 - 01524224 _____ C:\Users\milan\Desktop\adwcleaner_5.101.exe
2016-03-08 11:33 - 2016-03-13 00:11 - 00009528 _____ C:\Users\milan\Desktop\JRT.txt
2016-03-08 11:29 - 2016-03-08 11:29 - 01609216 _____ (Malwarebytes) C:\Users\milan\Desktop\JRT.exe
2016-03-08 01:08 - 2016-03-08 01:08 - 00000000 ____D C:\Users\milan\Downloads\Nová složka (2)
2016-03-07 12:06 - 2016-03-07 12:06 - 00009255 _____ C:\Users\milan\Desktop\Addition1.rar
2016-03-07 11:50 - 2016-03-14 07:37 - 00000000 ____D C:\FRST
2016-03-06 21:09 - 2016-03-07 00:56 - 00000000 ____D C:\Users\milan\AppData\Roaming\vlc
2016-03-06 21:09 - 2016-03-06 21:09 - 00000984 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-06 21:09 - 2016-03-06 21:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-06 21:08 - 2016-03-06 21:08 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-06 21:03 - 2016-03-06 21:07 - 30510920 _____ C:\Users\milan\Downloads\vlc-2.2.2-win32.exe
2016-03-05 10:21 - 2016-03-05 10:21 - 00000000 ____D C:\Users\milan\Downloads\Nová složka
2016-03-05 10:20 - 2016-03-05 10:20 - 01783800 _____ C:\Users\milan\Downloads\healbot.rar
2016-03-04 23:57 - 2016-03-04 23:57 - 02211428 _____ C:\Users\milan\Downloads\HealBot_5.4.2.0_ALL.zip
2016-03-04 20:27 - 2016-03-04 20:45 - 00000000 ____D C:\Users\milan\AppData\Local\PokerStars
2016-03-04 20:27 - 2016-03-04 20:27 - 00000802 _____ C:\Users\Public\Desktop\PokerStars.lnk
2016-03-04 20:27 - 2016-03-04 20:27 - 00000802 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.lnk
2016-03-04 17:09 - 2016-03-04 17:09 - 00000000 ____D C:\ProgramData\BlueStacks
2016-03-04 17:08 - 2016-03-04 17:09 - 10125176 _____ (BlueStack Systems, Inc.) C:\Users\milan\Downloads\BlueStacks-SplitInstaller.exe
2016-03-04 16:29 - 2016-03-08 15:04 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-03-04 16:28 - 2016-03-04 16:28 - 00000000 ____D C:\Users\milan\AppData\Local\Bluestacks
2016-03-04 14:40 - 2016-03-04 14:47 - 275097952 _____ (BlueStack Systems Inc.) C:\Users\milan\Downloads\BlueStacks2_native.exe
2016-03-03 21:22 - 2016-03-04 20:23 - 00000691 _____ C:\dude.conf
2016-03-03 21:21 - 2016-03-03 21:21 - 03702898 _____ C:\Users\milan\Downloads\dude-install-3.6.exe
2016-03-03 20:07 - 2016-03-03 20:07 - 00000000 ____D C:\Users\milan\AppData\Local\Mumble
2016-03-03 13:20 - 2016-03-05 10:22 - 00000000 ____D C:\Users\milan\Downloads\World of Warcraft - The Burning Crusade
2016-03-01 14:00 - 2016-03-01 14:03 - 264113064 _____ (NVIDIA Corporation) C:\Users\milan\Downloads\Nepotvrzeno 110044.crdownload
2016-02-29 18:32 - 2016-03-02 11:47 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2016-02-29 18:32 - 2016-02-29 18:32 - 00169218 _____ C:\Users\milan\Downloads\WoW_WotLK (1).torrent
2016-02-29 18:31 - 2016-02-29 18:31 - 00169218 _____ C:\Users\milan\Downloads\WoW_WotLK.torrent
2016-02-29 18:11 - 2016-03-12 23:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.EU
2016-02-29 17:15 - 2016-02-29 17:15 - 00000000 ____D C:\Users\milan\AppData\Local\AVAST Software
2016-02-29 16:37 - 2016-02-06 10:43 - 02280448 ____N (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-02-29 16:37 - 2016-02-06 09:54 - 01312256 ____N (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-02-29 16:37 - 2016-01-22 07:09 - 01310232 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00400896 ____N (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00171520 ____N (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00169984 ____N (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00099840 ____N (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-02-29 16:37 - 2016-01-22 07:06 - 00065536 ____N (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-02-29 16:37 - 2016-01-22 07:05 - 00654336 ____N (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-29 16:37 - 2016-01-22 07:05 - 00251392 ____N (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-29 16:37 - 2016-01-22 07:05 - 00022016 ____N (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 01060864 ____N (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00872448 ____N (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00553472 ____N (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00259584 ____N (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-02-29 16:37 - 2016-01-22 07:02 - 00223232 ____N (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-02-29 16:37 - 2016-01-22 07:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-02-29 16:37 - 2016-01-22 06:59 - 00642560 ____N (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00038912 ____N (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00017408 ____N (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-02-29 16:37 - 2016-01-22 06:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-29 16:37 - 2016-01-22 06:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-02-29 16:37 - 2016-01-22 06:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-02-29 16:37 - 2016-01-22 06:07 - 02120704 ____N (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-02-29 16:37 - 2016-01-22 05:53 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-02-29 16:37 - 2016-01-22 05:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-29 16:37 - 2016-01-22 05:51 - 00036352 ____N (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-02-29 16:37 - 2016-01-22 05:51 - 00022016 ____N (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-02-29 16:37 - 2016-01-22 05:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-02-29 12:57 - 2016-02-29 12:57 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images
2016-02-29 12:44 - 2016-03-02 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2016-02-29 12:44 - 2016-02-29 17:47 - 00000000 ____D C:\Users\milan\Documents\Bandicam
2016-02-23 13:37 - 2016-02-23 13:41 - 00000000 ____D C:\Users\milan\Documents\NFS Most Wanted
2016-02-23 13:12 - 2016-02-23 13:12 - 00001008 _____ C:\Users\Public\Desktop\Need for Speed™ Most Wanted.lnk
2016-02-22 21:49 - 2016-02-22 21:49 - 00000000 ___HD C:\Windows\PIF
2016-02-22 20:59 - 2005-05-26 14:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-02-19 16:41 - 2016-02-23 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RAR Password Recovery
2016-02-19 16:41 - 2016-02-19 16:41 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAR Password Recovery
2016-02-18 23:39 - 2016-02-23 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RAR Password Cracker
2016-02-18 23:39 - 2016-02-18 23:39 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAR Password Cracker
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-14 07:37 - 2014-06-28 12:44 - 00000000 ____D C:\Users\milan\AppData\Roaming\uTorrent
2016-03-14 07:31 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-14 07:30 - 2014-06-28 11:08 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-14 00:25 - 2009-07-14 05:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-14 00:25 - 2009-07-14 05:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-13 22:26 - 2015-02-13 21:18 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-13 18:43 - 2014-06-27 15:27 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-13 17:35 - 2014-06-27 15:58 - 00000000 ____D C:\Program Files\Mumble
2016-03-13 17:34 - 2014-06-28 19:04 - 00000000 ____D C:\ProgramData\Skype
2016-03-13 17:33 - 2015-04-20 12:03 - 00000000 ____D C:\Users\milan\AppData\Local\Samsung
2016-03-13 17:33 - 2015-04-20 11:57 - 00000000 ____D C:\Program Files\Samsung
2016-03-13 17:33 - 2014-06-28 10:43 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-03-13 17:11 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2016-03-13 17:04 - 2016-02-04 21:44 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Valve
2016-03-13 15:55 - 2015-02-19 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2016-03-13 15:55 - 2014-06-28 19:04 - 00000000 ____D C:\Users\milan\AppData\Roaming\Skype
2016-03-13 15:55 - 2014-06-26 20:44 - 00000000 ____D C:\Windows\Panther
2016-03-13 15:20 - 2014-06-29 19:52 - 00000000 ____D C:\Users\milan\AppData\Roaming\TS3Client
2016-03-13 15:02 - 2014-06-28 20:52 - 00000000 ____D C:\Users\milan\AppData\Local\AVG
2016-03-13 14:55 - 2009-07-14 03:04 - 00002577 _____ C:\Windows\system32\config.nt
2016-03-13 14:08 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2016-03-13 11:53 - 2015-01-19 20:46 - 00000000 ____D C:\Users\milan\AppData\Local\ElevatedDiagnostics
2016-03-13 01:34 - 2015-01-19 19:16 - 00000000 ____D C:\Windows\Minidump
2016-03-13 00:26 - 2015-02-13 21:18 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-03-13 00:26 - 2015-02-13 21:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-03-12 23:22 - 2014-06-26 19:52 - 00000000 ____D C:\Users\milan
2016-03-12 23:21 - 2015-02-13 21:18 - 00000000 ____D C:\Windows\system32\Macromed
2016-03-12 23:21 - 2014-07-01 10:34 - 00000000 ____D C:\Users\milan\AppData\Local\PokerStars.EU
2016-03-12 23:21 - 2014-06-27 15:55 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-03-12 23:21 - 2014-06-27 15:53 - 00000000 ____D C:\Users\milan\AppData\Roaming\Dropbox
2016-03-12 23:21 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2016-03-12 23:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\registration
2016-03-07 19:53 - 2011-04-12 02:37 - 00668138 _____ C:\Windows\system32\perfh005.dat
2016-03-07 19:53 - 2011-04-12 02:37 - 00140798 _____ C:\Windows\system32\perfc005.dat
2016-03-07 19:53 - 2010-11-20 22:01 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-03 20:07 - 2014-09-07 01:36 - 00000000 ____D C:\Users\milan\AppData\Roaming\Mumble
2016-03-02 11:50 - 2011-04-12 02:46 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-02 11:50 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-03-02 11:48 - 2014-11-15 00:32 - 00000000 ___RD C:\Users\milan\Documents\Notes
2016-03-02 11:48 - 2014-06-29 02:37 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-03-02 11:48 - 2014-06-28 20:44 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-03-02 11:47 - 2014-06-29 02:37 - 00000000 ____D C:\Program Files\3DO
2016-03-02 11:47 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-03-02 11:37 - 2014-06-28 20:45 - 00000000 ____D C:\Users\milan\AppData\Roaming\DAEMON Tools Lite
2016-02-29 16:14 - 2015-04-20 12:03 - 00000000 ____D C:\Users\milan\AppData\Roaming\Samsung
2016-02-29 16:14 - 2015-04-20 11:57 - 00000000 ____D C:\ProgramData\Samsung
2016-02-23 13:27 - 2014-06-28 20:33 - 00000000 ____D C:\Users\milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-02-23 13:12 - 2016-02-11 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2016-02-19 15:21 - 2009-07-14 05:33 - 00268128 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-18 14:59 - 2015-02-10 21:32 - 00000000 ____D C:\Users\milan\AppData\Local\Adobe
2016-02-17 13:57 - 2009-07-14 05:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-17 13:57 - 2009-07-14 05:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU(586).TXT
==================== Files in the root of some directories =======
2016-03-13 17:37 - 2016-03-13 17:37 - 0029696 _____ () C:\Users\milan\AppData\Local\MSGBOX.EXE
2014-11-19 17:18 - 2014-11-19 17:18 - 0000600 _____ () C:\Users\milan\AppData\Local\PUTTY.RND
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2015-12-26 18:40] - [2015-11-10 19:39] - 0811520 ____A (Microsoft Corporation) 8626F0C30D4E3564FFDD25C90F4426F1
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-09 22:55
==================== End of FRST.txt ============================