Napadený svchost.exe
Napsal: 03 úno 2014 09:16
Dobrý den, mám napadený soubor svchost.exe Po zapnutí PC se tento proces spustí a začne vytěžovat grafiku na 100% Po vypnutí ve správci úloh přestane vytěžovat grafiku, ale dnes ráno mi přestala fungovat i wifi. Před spuštěním tohoto procesu se ještě spustí chybová hláška viz. přílohy. Kaspersky, ccleaner, advanced system care, spybot terminator nepomohly.
------------------------------------------------------------------------------------------------------------------------------------------------------------------
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 04
Ran by Lupi (administrator) on LUPIK on 03-02-2014 09:08:18
Running from C:\Users\Lupi\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RobustIntelligentCompanion\LenovoR.I.C.Tray.exe
() C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Cerulean Studios) D:\Program Files (x86)\Trillian\trillian.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() D:\Program Files (x86)\Trillian\plugins\skypekit.exe
() C:\Program Files (x86)\IObit\Advanced SystemCare 7\RealTimeProtector.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Ghisler Software GmbH) D:\Program Files\totalcmd\TOTALCMD.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Lupi\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2841896 2011-10-28] (Synaptics Incorporated)
HKLM\...\Run: [OnekeyStudio] - C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2011-12-20] (Lenovo)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-12-20] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-12-20] (Lenovo(beijing) Limited)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation)
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab)
HKLM-x32\...\Run: [VeriFaceManager] - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-12-20] (Lenovo)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun_KL_notset] 1
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [DAEMON Tools Lite] - D:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [LenovoR.I.C.Tray] - C:\Program Files (x86)\Lenovo\RobustIntelligentCompanion\LenovoR.I.C.Tray.exe [2569568 2011-12-20] (Lenovo)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [OscarX7Mouse5Mode] - C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe [3571712 2013-02-01] ()
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-18] (IObit)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [SmartRAM] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe [549184 2013-10-22] (IObit)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20728480 2014-01-14] (Skype Technologies S.A.)
AppInit_DLLs: C:\windows\system32\nvinitx.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\x64\kloehk.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\x64\adialhk.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\x64\adialhk.dll [88784 2013-11-14] (Kaspersky Lab ZAO)
AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\adialhk.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\kloehk.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\kloehk.dll [13056 2013-11-14] (Kaspersky Lab ZAO)
Startup: C:\Users\Lupi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk
ShortcutTarget: Trillian.lnk -> D:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENN
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.2
FireFox:
========
FF ProfilePath: C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default
FF user.js: detected! => C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default\user.js
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - D:\Program Files\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - D:\Program Files\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ads Removal - C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default\Extensions\adsremoval@adsremoval.net [2014-02-01]
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default\Extensions\ascsurfingprotection@iobit.com [2014-02-01]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Extension: (Angry Birds) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2013-11-14]
CHR Extension: (Dokumenty Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-14]
CHR Extension: (Disk Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-14]
CHR Extension: (Turn Off the Lights) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-11-14]
CHR Extension: (YouTube) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-14]
CHR Extension: (Adblock Plus) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-14]
CHR Extension: (Vyhledávání Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-14]
CHR Extension: (Daum Equation Editor) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dinfmiceliiomokeofbocegmacmagjhe [2013-11-14]
CHR Extension: (Kingdoms Of Camelot) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkadejngfdiifodimfhejphllfecigmm [2013-11-14]
CHR Extension: (Motocross Nitro) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdikdnjblenkgleaedpepneeafbljagc [2013-11-14]
CHR Extension: (Hodiny) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo [2013-11-14]
CHR Extension: (AdBlock) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-14]
CHR Extension: (Ads Removal) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod [2014-02-01]
CHR Extension: (Crash Bandicoot Online) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\goppebjnofdelbhehnoeghgaioapnhgl [2013-11-14]
CHR Extension: (Battlestar Galactica Online) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihbmdfdhanakpfoiaomnelodiejioflb [2013-11-14]
CHR Extension: (Pocket) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2013-11-14]
CHR Extension: (Hodiny) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg [2013-11-14]
CHR Extension: (Plants vs Zombies) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-12-30]
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd [2014-02-01]
CHR Extension: (Peněženka Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-14]
CHR Extension: (Gmail) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-14]
CHR Extension: (Space Planet) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcocpoeoiajndepaaimnnglicichmbb [2013-11-14]
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx [2014-02-01]
==================== Services (Whitelisted) =================
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [970016 2011-05-12] (Broadcom Corporation.)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
==================== Drivers (Whitelisted) ====================
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-13] (Broadcom Corporation.)
R3 DelayMan; C:\Windows\System32\DRIVERS\delayman.sys [20064 2011-12-20] (Ensurebit Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-14] (DT Soft Ltd)
R1 hybridcfile; C:\Windows\System32\DRIVERS\HybridCFileX64.sys [13920 2010-03-02] (Lenovo.)
R0 HybridDisk; C:\Windows\System32\DRIVERS\HybridDiskX64.sys [38496 2010-03-02] (Lenovo.)
R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [157712 2009-11-11] (Kaspersky Lab)
R3 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [30736 2009-09-03] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [268376 2013-11-14] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27736 2013-11-14] (Kaspersky Lab ZAO)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8199016 2011-03-23] (Realtek Semiconductor Corp.)
R1 winioex; C:\Windows\System32\drivers\winioex.sys [15456 2011-12-20] (Ensurebit Inc.)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
U3 BcmSqlStartupSvc;
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-03 09:08 - 2014-02-03 09:08 - 00021772 _____ () C:\Users\Lupi\Desktop\FRST.txt
2014-02-03 09:07 - 2014-02-03 09:07 - 00112640 _____ (forum.viry.cz) C:\Users\Lupi\Desktop\FRSTLauncher.exe
2014-02-03 09:07 - 2014-02-03 09:07 - 00029696 _____ () C:\Users\Lupi\AppData\Local\MSGBOX.EXE
2014-02-03 09:07 - 2014-02-03 09:07 - 00015327 _____ () C:\Users\Lupi\Desktop\LM.bat
2014-02-03 09:03 - 2014-02-03 09:08 - 00000000 ____D () C:\FRST
2014-02-03 09:03 - 2014-02-03 09:02 - 02080256 _____ (Farbar) C:\Users\Lupi\Desktop\FRST64.exe
2014-02-02 14:12 - 2014-02-02 14:12 - 00000672 _____ () C:\Users\Public\Desktop\JPG To PDF.lnk
2014-02-02 14:10 - 2014-02-02 14:10 - 00000719 _____ () C:\Users\Lupi\Desktop\Convert Image To PDF.lnk
2014-02-02 14:10 - 2007-03-14 14:25 - 01289162 _____ () C:\windows\SysWOW64\CONVERTITP.HLP
2014-02-02 14:10 - 2007-03-14 14:25 - 00002930 _____ () C:\windows\SysWOW64\CONVERTITP.CNT
2014-02-02 14:10 - 2006-07-28 14:38 - 00053248 _____ () C:\windows\SysWOW64\RegisterExe.exe
2014-02-02 14:10 - 2005-03-18 18:01 - 00626688 _____ (Online Media Technologies Ltd.) C:\windows\SysWOW64\NCTImageFile.dll
2014-02-02 14:10 - 2005-03-12 21:46 - 01418224 _____ () C:\windows\SysWOW64\CONVERTITP-DEUTSCH.HLP
2014-02-02 14:10 - 2005-03-12 21:46 - 00003040 _____ () C:\windows\SysWOW64\CONVERTITP-DEUTSCH.CNT
2014-02-02 14:10 - 2005-01-24 16:23 - 00069632 _____ (Gateway Software Productions) C:\windows\SysWOW64\PDFOCX.ocx
2014-02-02 14:10 - 2004-09-19 01:55 - 00278528 _____ (Wilson Media) C:\windows\SysWOW64\AdvImgLib.dll
2014-02-02 14:10 - 2004-07-29 04:14 - 01313280 _____ (SEDTech (Pty) Ltd.) C:\windows\SysWOW64\ISED.DLL
2014-02-02 14:10 - 2004-07-09 03:45 - 00761856 _____ () C:\windows\SysWOW64\FreeImage3.dll
2014-02-02 14:10 - 2004-07-09 03:45 - 00761856 _____ () C:\windows\SysWOW64\FreeImage.dll
2014-02-02 14:10 - 2003-07-08 18:50 - 00344064 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVCR70.DLL
2014-02-02 14:10 - 2003-06-11 02:27 - 00106496 _____ (Skogen) C:\windows\SysWOW64\SeeThroughPicture.ocx
2014-02-02 14:10 - 2001-08-23 20:00 - 01700352 _____ (Microsoft Corporation) C:\windows\SysWOW64\GdiPlus.dll
2014-02-02 14:10 - 2000-05-22 04:00 - 00244416 _____ (Microsoft Corporation) C:\windows\SysWOW64\Msflxgrd.ocx
2014-02-02 14:10 - 1999-05-07 04:00 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\comdlg32.ocx
2014-02-01 20:56 - 2014-02-01 21:03 - 00000000 ____D () C:\Users\Lupi\AppData\Local\PokerStars
2014-02-01 20:56 - 2014-02-01 20:56 - 00000640 _____ () C:\Users\Public\Desktop\PokerStars.lnk
2014-02-01 18:05 - 2014-02-01 18:05 - 00000085 _____ () C:\windows\wininit.ini
2014-02-01 16:02 - 2014-02-03 09:05 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\ProgramData\Skype
2014-02-01 12:04 - 2014-02-01 12:04 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-02-01 00:47 - 2014-02-01 00:47 - 00003158 _____ () C:\windows\System32\Tasks\Game_Booster_AutoUpdate
2014-02-01 00:47 - 2014-02-01 00:47 - 00001186 _____ () C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
2014-02-01 00:47 - 2014-02-01 00:47 - 00001174 _____ () C:\Users\Public\Desktop\Game Booster 3.lnk
2014-02-01 00:44 - 2014-02-01 00:44 - 00001189 _____ () C:\Users\Public\Desktop\ManageMyMobile.lnk
2014-02-01 00:31 - 2014-02-01 00:47 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-02-01 00:31 - 2014-02-01 00:44 - 00000000 ____D () C:\ProgramData\ProductData
2014-02-01 00:31 - 2014-02-01 00:33 - 00002209 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00003092 _____ () C:\windows\System32\Tasks\ASC7_PerformanceMonitor
2014-02-01 00:31 - 2014-02-01 00:31 - 00002848 _____ () C:\windows\System32\Tasks\ASC7_SkipUac_Lupi
2014-02-01 00:31 - 2014-02-01 00:31 - 00001217 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Apple Computer
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-01 00:29 - 2014-02-01 20:32 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-01 00:29 - 2014-02-01 18:05 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-01 00:29 - 2014-02-01 00:29 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
2014-02-01 00:19 - 2014-02-01 00:47 - 00000000 ____D () C:\ProgramData\IObit
2014-02-01 00:19 - 2014-02-01 00:31 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\IObit
2014-02-01 00:17 - 2014-02-01 00:18 - 00002338 _____ () C:\Users\Lupi\Desktop\Rkill.txt
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\Users\Lupi\AppData\Local\LogMeIn
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-01-31 22:38 - 2014-01-31 22:38 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2014-01-31 22:38 - 2014-01-27 19:48 - 07054336 _____ () C:\Users\Lupi\Desktop\XNA Framework 4.0 Full.msi
2014-01-31 22:38 - 2014-01-27 19:48 - 00889416 _____ (Microsoft Corporation) C:\Users\Lupi\Desktop\.Net Framework 4.0 Full.exe
2014-01-31 22:32 - 2014-01-31 22:32 - 00000729 _____ () C:\Users\Public\Desktop\Terraria.lnk
2014-01-31 22:31 - 2014-01-31 22:31 - 00003294 _____ () C:\windows\System32\Tasks\Microsoft System Certificates
2014-01-31 22:08 - 2009-03-18 17:35 - 00033856 ____H (LogMeIn, Inc.) C:\windows\system32\hamachi.sys
2014-01-31 21:58 - 2014-01-31 22:01 - 00000000 ____D () C:\Users\Lupi\Documents\Battlefield 2
2014-01-31 21:58 - 2014-01-31 21:58 - 00000877 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-01-31 21:58 - 2014-01-31 21:58 - 00000855 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\Documents\Youcam
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\ProgramData\CyberLink
2014-01-29 18:36 - 2014-01-29 18:36 - 00000000 ____D () C:\Users\Lupi\Documents\4A Games
2014-01-29 18:35 - 2014-01-29 18:35 - 00000000 ____D () C:\Users\Lupi\AppData\Local\4A Games
2014-01-27 10:24 - 2014-01-27 10:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-01-26 01:10 - 2014-01-26 01:10 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard
2014-01-26 01:05 - 2014-01-26 01:05 - 00000865 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-01-25 13:47 - 2014-01-25 13:47 - 00000000 ____D () C:\Users\Lupi\Desktop\Camera
2014-01-25 10:12 - 2014-01-25 10:12 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\mrrescue
2014-01-24 21:38 - 2014-01-24 21:38 - 00049064 _____ () C:\Users\Lupi\Desktop\tv-cesnet-vlc.htm
2014-01-24 21:38 - 2014-01-24 21:38 - 00004982 _____ () C:\Users\Lupi\Desktop\TV_cesnet_0.vlc
2014-01-20 23:30 - 2014-01-20 23:30 - 00000737 _____ () C:\Users\Lupi\Desktop\AC4BFSP – zástupce.lnk
2014-01-17 00:20 - 2014-01-17 00:20 - 00000879 _____ () C:\Users\Public\Desktop\Legend of Grimrock.lnk
2014-01-17 00:20 - 2014-01-17 00:20 - 00000000 ____D () C:\Users\Lupi\Documents\Almost Human
2014-01-16 13:34 - 2014-01-16 13:34 - 00000754 _____ () C:\Users\Public\Desktop\Brány Skeldalu.lnk
2014-01-15 09:44 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2014-01-15 09:44 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2014-01-15 09:44 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-01-14 22:08 - 2014-01-14 22:08 - 00000000 ____D () C:\windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2014-01-14 22:07 - 2014-01-14 22:07 - 00000784 _____ () C:\Users\Public\Desktop\Unreal Tournament 3.lnk
2014-01-14 22:07 - 2014-01-14 22:07 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\InstallShield Installation Information
2014-01-14 21:36 - 2014-01-14 21:36 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-01-14 21:36 - 2014-01-14 21:36 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-14 20:39 - 2014-01-14 20:40 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Mozilla
2014-01-14 20:39 - 2014-01-14 20:40 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-01-14 17:35 - 2014-01-31 21:58 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-01-14 17:33 - 2014-01-14 17:33 - 00000890 _____ () C:\Users\Lupi\Desktop\Play UT2004.lnk
2014-01-14 16:05 - 2014-01-14 16:05 - 00000000 ____D () C:\Users\Lupi\Documents\Diablo III
2014-01-14 15:47 - 2014-01-14 15:47 - 00000836 _____ () C:\Users\Public\Desktop\Diablo III.lnk
2014-01-14 15:41 - 2014-02-01 00:58 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Battle.net
2014-01-14 15:41 - 2014-01-26 01:05 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-01-14 15:41 - 2014-01-14 15:44 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Battle.net
2014-01-14 15:41 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard Entertainment
2014-01-10 23:48 - 2014-01-10 23:48 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\VitySoft
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\.objectdb
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Sun
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-10 13:06 - 2014-01-10 13:06 - 00000000 ____D () C:\Users\Lupi\AppData\Local\DayZCommander
2014-01-09 15:48 - 2014-01-14 21:37 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Winamp
2014-01-09 15:48 - 2014-01-09 15:49 - 00000000 ____D () C:\Program Files (x86)\Winamp
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\SysWOW64\NV
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\system32\NV
2014-01-08 22:04 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 18310112 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 15877216 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 15230352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2014-01-08 22:04 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvenc.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvenc.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6433221.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6433221.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00032544 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvpciflt.sys
2014-01-08 22:03 - 2014-01-08 22:03 - 00000000 ____D () C:\NVIDIA
2014-01-06 20:54 - 2014-01-06 20:54 - 00001100 _____ () C:\Users\Lupi\Desktop\swkotor2 – zástupce.lnk
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\Users\Lupi\AppData\Local\WarThunder
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\ProgramData\WarThunder
2014-01-06 19:49 - 2014-01-06 19:49 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-01-05 21:07 - 2014-01-05 21:07 - 00098304 _____ (Sony DADC Austria AG.) C:\windows\SysWOW64\CmdLineExt.dll
2014-01-05 11:25 - 2014-01-06 20:52 - 00000000 ____D () C:\Program Files (x86)\Anti-Vibrate Oscar Editor
==================== One Month Modified Files and Folders =======
2014-02-03 09:08 - 2014-02-03 09:08 - 00021772 _____ () C:\Users\Lupi\Desktop\FRST.txt
2014-02-03 09:08 - 2014-02-03 09:03 - 00000000 ____D () C:\FRST
2014-02-03 09:07 - 2014-02-03 09:07 - 00112640 _____ (forum.viry.cz) C:\Users\Lupi\Desktop\FRSTLauncher.exe
2014-02-03 09:07 - 2014-02-03 09:07 - 00029696 _____ () C:\Users\Lupi\AppData\Local\MSGBOX.EXE
2014-02-03 09:07 - 2014-02-03 09:07 - 00015327 _____ () C:\Users\Lupi\Desktop\LM.bat
2014-02-03 09:05 - 2014-02-01 16:02 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Skype
2014-02-03 09:03 - 2013-12-03 14:10 - 00000000 ____D () C:\Users\Lupi\AppData\Local\CrashDumps
2014-02-03 09:02 - 2014-02-03 09:03 - 02080256 _____ (Farbar) C:\Users\Lupi\Desktop\FRST64.exe
2014-02-03 08:57 - 2011-12-20 11:38 - 00000966 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-03 08:55 - 2009-07-14 05:45 - 00021280 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-03 08:55 - 2009-07-14 05:45 - 00021280 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-03 08:54 - 2011-12-20 02:46 - 00669736 _____ () C:\windows\system32\perfh005.dat
2014-02-03 08:54 - 2011-12-20 02:46 - 00141336 _____ () C:\windows\system32\perfc005.dat
2014-02-03 08:54 - 2009-07-14 06:13 - 01585238 _____ () C:\windows\system32\PerfStringBackup.INI
2014-02-03 08:53 - 2011-12-20 11:43 - 00423750 _____ () C:\FaceProv.log
2014-02-03 08:51 - 2011-12-20 10:59 - 01749618 ____N () C:\windows\WindowsUpdate.log
2014-02-03 08:48 - 2013-11-14 12:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-02-03 08:48 - 2011-12-20 11:43 - 00000000 ____D () C:\ProgramData\VeriFace
2014-02-03 08:48 - 2011-12-20 11:38 - 00000962 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-03 08:48 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-02-02 20:55 - 2013-11-14 21:54 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Foxit Software
2014-02-02 14:12 - 2014-02-02 14:12 - 00000672 _____ () C:\Users\Public\Desktop\JPG To PDF.lnk
2014-02-02 14:10 - 2014-02-02 14:10 - 00000719 _____ () C:\Users\Lupi\Desktop\Convert Image To PDF.lnk
2014-02-01 21:03 - 2014-02-01 20:56 - 00000000 ____D () C:\Users\Lupi\AppData\Local\PokerStars
2014-02-01 20:56 - 2014-02-01 20:56 - 00000640 _____ () C:\Users\Public\Desktop\PokerStars.lnk
2014-02-01 20:32 - 2014-02-01 00:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-01 18:05 - 2014-02-01 18:05 - 00000085 _____ () C:\windows\wininit.ini
2014-02-01 18:05 - 2014-02-01 00:29 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-01 16:02 - 2014-02-01 16:02 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\ProgramData\Skype
2014-02-01 12:50 - 2013-11-14 22:17 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\DAEMON Tools Lite
2014-02-01 12:04 - 2014-02-01 12:04 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-02-01 01:06 - 2013-11-14 12:08 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\vlc
2014-02-01 00:58 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Battle.net
2014-02-01 00:57 - 2011-12-20 11:38 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-01 00:49 - 2013-12-27 15:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-01 00:49 - 2013-12-24 15:14 - 00000000 ____D () C:\Program Files (x86)\OscarX7Editor5Mode
2014-02-01 00:49 - 2013-11-17 12:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-02-01 00:49 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-02-01 00:49 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker
2014-02-01 00:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-02-01 00:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-02-01 00:47 - 2014-02-01 00:47 - 00003158 _____ () C:\windows\System32\Tasks\Game_Booster_AutoUpdate
2014-02-01 00:47 - 2014-02-01 00:47 - 00001186 _____ () C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
2014-02-01 00:47 - 2014-02-01 00:47 - 00001174 _____ () C:\Users\Public\Desktop\Game Booster 3.lnk
2014-02-01 00:47 - 2014-02-01 00:31 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-02-01 00:47 - 2014-02-01 00:19 - 00000000 ____D () C:\ProgramData\IObit
2014-02-01 00:44 - 2014-02-01 00:44 - 00001189 _____ () C:\Users\Public\Desktop\ManageMyMobile.lnk
2014-02-01 00:44 - 2014-02-01 00:31 - 00000000 ____D () C:\ProgramData\ProductData
2014-02-01 00:40 - 2011-02-22 12:19 - 00000000 ____D () C:\windows\Panther
2014-02-01 00:33 - 2014-02-01 00:31 - 00002209 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00003092 _____ () C:\windows\System32\Tasks\ASC7_PerformanceMonitor
2014-02-01 00:31 - 2014-02-01 00:31 - 00002848 _____ () C:\windows\System32\Tasks\ASC7_SkipUac_Lupi
2014-02-01 00:31 - 2014-02-01 00:31 - 00001217 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Apple Computer
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-01 00:31 - 2014-02-01 00:19 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\IObit
2014-02-01 00:29 - 2014-02-01 00:29 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
2014-02-01 00:18 - 2014-02-01 00:17 - 00002338 _____ () C:\Users\Lupi\Desktop\Rkill.txt
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\Users\Lupi\AppData\Local\LogMeIn
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-01-31 22:42 - 2013-11-15 00:53 - 00000000 ____D () C:\Users\Lupi\Documents\My Games
2014-01-31 22:38 - 2014-01-31 22:38 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2014-01-31 22:32 - 2014-01-31 22:32 - 00000729 _____ () C:\Users\Public\Desktop\Terraria.lnk
2014-01-31 22:31 - 2014-01-31 22:31 - 00003294 _____ () C:\windows\System32\Tasks\Microsoft System Certificates
2014-01-31 22:01 - 2014-01-31 21:58 - 00000000 ____D () C:\Users\Lupi\Documents\Battlefield 2
2014-01-31 21:58 - 2014-01-31 21:58 - 00000877 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-01-31 21:58 - 2014-01-31 21:58 - 00000855 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-01-31 21:58 - 2014-01-14 17:35 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-01-31 21:53 - 2011-12-20 11:05 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\Documents\Youcam
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\ProgramData\CyberLink
2014-01-29 18:36 - 2014-01-29 18:36 - 00000000 ____D () C:\Users\Lupi\Documents\4A Games
2014-01-29 18:35 - 2014-01-29 18:35 - 00000000 ____D () C:\Users\Lupi\AppData\Local\4A Games
2014-01-29 18:34 - 2013-12-27 15:51 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\NVIDIA
2014-01-27 19:48 - 2014-01-31 22:38 - 07054336 _____ () C:\Users\Lupi\Desktop\XNA Framework 4.0 Full.msi
2014-01-27 19:48 - 2014-01-31 22:38 - 00889416 _____ (Microsoft Corporation) C:\Users\Lupi\Desktop\.Net Framework 4.0 Full.exe
2014-01-27 10:24 - 2014-01-27 10:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-01-26 01:10 - 2014-01-26 01:10 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard
2014-01-26 01:05 - 2014-01-26 01:05 - 00000865 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-01-26 01:05 - 2014-01-14 15:41 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-01-25 13:47 - 2014-01-25 13:47 - 00000000 ____D () C:\Users\Lupi\Desktop\Camera
2014-01-25 10:12 - 2014-01-25 10:12 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\mrrescue
2014-01-24 21:38 - 2014-01-24 21:38 - 00049064 _____ () C:\Users\Lupi\Desktop\tv-cesnet-vlc.htm
2014-01-24 21:38 - 2014-01-24 21:38 - 00004982 _____ () C:\Users\Lupi\Desktop\TV_cesnet_0.vlc
2014-01-20 23:30 - 2014-01-20 23:30 - 00000737 _____ () C:\Users\Lupi\Desktop\AC4BFSP – zástupce.lnk
2014-01-18 13:06 - 2013-12-01 16:58 - 00000000 ____D () C:\Users\Lupi\Desktop\reaktance synchronniho
2014-01-18 12:59 - 2013-11-14 12:00 - 00000000 __SHD () C:\windows\SysWOW64\AI_RecycleBin
2014-01-18 12:43 - 2013-12-25 16:30 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-01-17 00:20 - 2014-01-17 00:20 - 00000879 _____ () C:\Users\Public\Desktop\Legend of Grimrock.lnk
2014-01-17 00:20 - 2014-01-17 00:20 - 00000000 ____D () C:\Users\Lupi\Documents\Almost Human
2014-01-16 13:34 - 2014-01-16 13:34 - 00000754 _____ () C:\Users\Public\Desktop\Brány Skeldalu.lnk
2014-01-16 13:00 - 2009-07-14 05:45 - 04989048 _____ () C:\windows\system32\FNTCACHE.DAT
2014-01-16 08:43 - 2013-11-17 12:56 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-16 08:43 - 2013-11-14 13:26 - 00000000 ____D () C:\windows\system32\MRT
2014-01-16 08:41 - 2013-11-14 13:26 - 86054176 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-01-15 00:18 - 2013-11-14 11:28 - 00000000 ____D () C:\Users\Lupi
2014-01-14 22:08 - 2014-01-14 22:08 - 00000000 ____D () C:\windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2014-01-14 22:07 - 2014-01-14 22:07 - 00000784 _____ () C:\Users\Public\Desktop\Unreal Tournament 3.lnk
2014-01-14 22:07 - 2014-01-14 22:07 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\InstallShield Installation Information
2014-01-14 21:37 - 2014-01-09 15:48 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Winamp
2014-01-14 21:37 - 2013-12-31 00:30 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\TS3Client
2014-01-14 21:36 - 2014-01-14 21:36 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-01-14 21:36 - 2014-01-14 21:36 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-14 20:40 - 2014-01-14 20:39 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Mozilla
2014-01-14 20:40 - 2014-01-14 20:39 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-01-14 17:33 - 2014-01-14 17:33 - 00000890 _____ () C:\Users\Lupi\Desktop\Play UT2004.lnk
2014-01-14 16:05 - 2014-01-14 16:05 - 00000000 ____D () C:\Users\Lupi\Documents\Diablo III
2014-01-14 15:47 - 2014-01-14 15:47 - 00000836 _____ () C:\Users\Public\Desktop\Diablo III.lnk
2014-01-14 15:44 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Battle.net
2014-01-14 15:41 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard Entertainment
2014-01-13 20:55 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-01-10 23:48 - 2014-01-10 23:48 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\VitySoft
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\.objectdb
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Sun
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-10 13:06 - 2014-01-10 13:06 - 00000000 ____D () C:\Users\Lupi\AppData\Local\DayZCommander
2014-01-09 15:49 - 2014-01-09 15:48 - 00000000 ____D () C:\Program Files (x86)\Winamp
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\SysWOW64\NV
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\system32\NV
2014-01-08 22:07 - 2011-12-20 11:09 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-01-08 22:03 - 2014-01-08 22:03 - 00000000 ____D () C:\NVIDIA
2014-01-06 20:54 - 2014-01-06 20:54 - 00001100 _____ () C:\Users\Lupi\Desktop\swkotor2 – zástupce.lnk
2014-01-06 20:52 - 2014-01-05 11:25 - 00000000 ____D () C:\Program Files (x86)\Anti-Vibrate Oscar Editor
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\Users\Lupi\AppData\Local\WarThunder
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\ProgramData\WarThunder
2014-01-06 19:49 - 2014-01-06 19:49 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-01-05 21:07 - 2014-01-05 21:07 - 00098304 _____ (Sony DADC Austria AG.) C:\windows\SysWOW64\CmdLineExt.dll
Some content of TEMP:
====================
C:\Users\Lupi\AppData\Local\Temp\Checkupdate.exe
C:\Users\Lupi\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Lupi\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Lupi\AppData\Local\Temp\gtapi_signed.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-29 14:01
==================== End Of Log ============================
------------------------------------------------------------------------------------------------------------------------------------------------------------------
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 04
Ran by Lupi (administrator) on LUPIK on 03-02-2014 09:08:18
Running from C:\Users\Lupi\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RobustIntelligentCompanion\LenovoR.I.C.Tray.exe
() C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Cerulean Studios) D:\Program Files (x86)\Trillian\trillian.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() D:\Program Files (x86)\Trillian\plugins\skypekit.exe
() C:\Program Files (x86)\IObit\Advanced SystemCare 7\RealTimeProtector.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Ghisler Software GmbH) D:\Program Files\totalcmd\TOTALCMD.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Lupi\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2841896 2011-10-28] (Synaptics Incorporated)
HKLM\...\Run: [OnekeyStudio] - C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2011-12-20] (Lenovo)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-12-20] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-12-20] (Lenovo(beijing) Limited)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation)
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab)
HKLM-x32\...\Run: [VeriFaceManager] - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-12-20] (Lenovo)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun_KL_notset] 1
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [DAEMON Tools Lite] - D:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [LenovoR.I.C.Tray] - C:\Program Files (x86)\Lenovo\RobustIntelligentCompanion\LenovoR.I.C.Tray.exe [2569568 2011-12-20] (Lenovo)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [OscarX7Mouse5Mode] - C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe [3571712 2013-02-01] ()
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-18] (IObit)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [SmartRAM] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe [549184 2013-10-22] (IObit)
HKU\S-1-5-21-2252928422-1377067979-2010445673-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20728480 2014-01-14] (Skype Technologies S.A.)
AppInit_DLLs: C:\windows\system32\nvinitx.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\x64\kloehk.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\x64\adialhk.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\x64\adialhk.dll [88784 2013-11-14] (Kaspersky Lab ZAO)
AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\adialhk.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0FO\kloehk.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\kloehk.dll [13056 2013-11-14] (Kaspersky Lab ZAO)
Startup: C:\Users\Lupi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk
ShortcutTarget: Trillian.lnk -> D:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENN
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.2
FireFox:
========
FF ProfilePath: C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default
FF user.js: detected! => C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default\user.js
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - D:\Program Files\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - D:\Program Files\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ads Removal - C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default\Extensions\adsremoval@adsremoval.net [2014-02-01]
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Lupi\AppData\Roaming\Mozilla\Firefox\Profiles\g532ato1.default\Extensions\ascsurfingprotection@iobit.com [2014-02-01]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Extension: (Angry Birds) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2013-11-14]
CHR Extension: (Dokumenty Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-14]
CHR Extension: (Disk Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-14]
CHR Extension: (Turn Off the Lights) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-11-14]
CHR Extension: (YouTube) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-14]
CHR Extension: (Adblock Plus) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-14]
CHR Extension: (Vyhledávání Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-14]
CHR Extension: (Daum Equation Editor) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dinfmiceliiomokeofbocegmacmagjhe [2013-11-14]
CHR Extension: (Kingdoms Of Camelot) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkadejngfdiifodimfhejphllfecigmm [2013-11-14]
CHR Extension: (Motocross Nitro) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdikdnjblenkgleaedpepneeafbljagc [2013-11-14]
CHR Extension: (Hodiny) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo [2013-11-14]
CHR Extension: (AdBlock) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-14]
CHR Extension: (Ads Removal) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod [2014-02-01]
CHR Extension: (Crash Bandicoot Online) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\goppebjnofdelbhehnoeghgaioapnhgl [2013-11-14]
CHR Extension: (Battlestar Galactica Online) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihbmdfdhanakpfoiaomnelodiejioflb [2013-11-14]
CHR Extension: (Pocket) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2013-11-14]
CHR Extension: (Hodiny) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg [2013-11-14]
CHR Extension: (Plants vs Zombies) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-12-30]
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd [2014-02-01]
CHR Extension: (Peněženka Google) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-14]
CHR Extension: (Gmail) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-14]
CHR Extension: (Space Planet) - C:\Users\Lupi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcocpoeoiajndepaaimnnglicichmbb [2013-11-14]
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx [2014-02-01]
==================== Services (Whitelisted) =================
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [970016 2011-05-12] (Broadcom Corporation.)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
==================== Drivers (Whitelisted) ====================
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-13] (Broadcom Corporation.)
R3 DelayMan; C:\Windows\System32\DRIVERS\delayman.sys [20064 2011-12-20] (Ensurebit Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-14] (DT Soft Ltd)
R1 hybridcfile; C:\Windows\System32\DRIVERS\HybridCFileX64.sys [13920 2010-03-02] (Lenovo.)
R0 HybridDisk; C:\Windows\System32\DRIVERS\HybridDiskX64.sys [38496 2010-03-02] (Lenovo.)
R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [157712 2009-11-11] (Kaspersky Lab)
R3 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [30736 2009-09-03] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [268376 2013-11-14] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27736 2013-11-14] (Kaspersky Lab ZAO)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8199016 2011-03-23] (Realtek Semiconductor Corp.)
R1 winioex; C:\Windows\System32\drivers\winioex.sys [15456 2011-12-20] (Ensurebit Inc.)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
U3 BcmSqlStartupSvc;
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-03 09:08 - 2014-02-03 09:08 - 00021772 _____ () C:\Users\Lupi\Desktop\FRST.txt
2014-02-03 09:07 - 2014-02-03 09:07 - 00112640 _____ (forum.viry.cz) C:\Users\Lupi\Desktop\FRSTLauncher.exe
2014-02-03 09:07 - 2014-02-03 09:07 - 00029696 _____ () C:\Users\Lupi\AppData\Local\MSGBOX.EXE
2014-02-03 09:07 - 2014-02-03 09:07 - 00015327 _____ () C:\Users\Lupi\Desktop\LM.bat
2014-02-03 09:03 - 2014-02-03 09:08 - 00000000 ____D () C:\FRST
2014-02-03 09:03 - 2014-02-03 09:02 - 02080256 _____ (Farbar) C:\Users\Lupi\Desktop\FRST64.exe
2014-02-02 14:12 - 2014-02-02 14:12 - 00000672 _____ () C:\Users\Public\Desktop\JPG To PDF.lnk
2014-02-02 14:10 - 2014-02-02 14:10 - 00000719 _____ () C:\Users\Lupi\Desktop\Convert Image To PDF.lnk
2014-02-02 14:10 - 2007-03-14 14:25 - 01289162 _____ () C:\windows\SysWOW64\CONVERTITP.HLP
2014-02-02 14:10 - 2007-03-14 14:25 - 00002930 _____ () C:\windows\SysWOW64\CONVERTITP.CNT
2014-02-02 14:10 - 2006-07-28 14:38 - 00053248 _____ () C:\windows\SysWOW64\RegisterExe.exe
2014-02-02 14:10 - 2005-03-18 18:01 - 00626688 _____ (Online Media Technologies Ltd.) C:\windows\SysWOW64\NCTImageFile.dll
2014-02-02 14:10 - 2005-03-12 21:46 - 01418224 _____ () C:\windows\SysWOW64\CONVERTITP-DEUTSCH.HLP
2014-02-02 14:10 - 2005-03-12 21:46 - 00003040 _____ () C:\windows\SysWOW64\CONVERTITP-DEUTSCH.CNT
2014-02-02 14:10 - 2005-01-24 16:23 - 00069632 _____ (Gateway Software Productions) C:\windows\SysWOW64\PDFOCX.ocx
2014-02-02 14:10 - 2004-09-19 01:55 - 00278528 _____ (Wilson Media) C:\windows\SysWOW64\AdvImgLib.dll
2014-02-02 14:10 - 2004-07-29 04:14 - 01313280 _____ (SEDTech (Pty) Ltd.) C:\windows\SysWOW64\ISED.DLL
2014-02-02 14:10 - 2004-07-09 03:45 - 00761856 _____ () C:\windows\SysWOW64\FreeImage3.dll
2014-02-02 14:10 - 2004-07-09 03:45 - 00761856 _____ () C:\windows\SysWOW64\FreeImage.dll
2014-02-02 14:10 - 2003-07-08 18:50 - 00344064 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVCR70.DLL
2014-02-02 14:10 - 2003-06-11 02:27 - 00106496 _____ (Skogen) C:\windows\SysWOW64\SeeThroughPicture.ocx
2014-02-02 14:10 - 2001-08-23 20:00 - 01700352 _____ (Microsoft Corporation) C:\windows\SysWOW64\GdiPlus.dll
2014-02-02 14:10 - 2000-05-22 04:00 - 00244416 _____ (Microsoft Corporation) C:\windows\SysWOW64\Msflxgrd.ocx
2014-02-02 14:10 - 1999-05-07 04:00 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\comdlg32.ocx
2014-02-01 20:56 - 2014-02-01 21:03 - 00000000 ____D () C:\Users\Lupi\AppData\Local\PokerStars
2014-02-01 20:56 - 2014-02-01 20:56 - 00000640 _____ () C:\Users\Public\Desktop\PokerStars.lnk
2014-02-01 18:05 - 2014-02-01 18:05 - 00000085 _____ () C:\windows\wininit.ini
2014-02-01 16:02 - 2014-02-03 09:05 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\ProgramData\Skype
2014-02-01 12:04 - 2014-02-01 12:04 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-02-01 00:47 - 2014-02-01 00:47 - 00003158 _____ () C:\windows\System32\Tasks\Game_Booster_AutoUpdate
2014-02-01 00:47 - 2014-02-01 00:47 - 00001186 _____ () C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
2014-02-01 00:47 - 2014-02-01 00:47 - 00001174 _____ () C:\Users\Public\Desktop\Game Booster 3.lnk
2014-02-01 00:44 - 2014-02-01 00:44 - 00001189 _____ () C:\Users\Public\Desktop\ManageMyMobile.lnk
2014-02-01 00:31 - 2014-02-01 00:47 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-02-01 00:31 - 2014-02-01 00:44 - 00000000 ____D () C:\ProgramData\ProductData
2014-02-01 00:31 - 2014-02-01 00:33 - 00002209 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00003092 _____ () C:\windows\System32\Tasks\ASC7_PerformanceMonitor
2014-02-01 00:31 - 2014-02-01 00:31 - 00002848 _____ () C:\windows\System32\Tasks\ASC7_SkipUac_Lupi
2014-02-01 00:31 - 2014-02-01 00:31 - 00001217 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Apple Computer
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-01 00:29 - 2014-02-01 20:32 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-01 00:29 - 2014-02-01 18:05 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-01 00:29 - 2014-02-01 00:29 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
2014-02-01 00:19 - 2014-02-01 00:47 - 00000000 ____D () C:\ProgramData\IObit
2014-02-01 00:19 - 2014-02-01 00:31 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\IObit
2014-02-01 00:17 - 2014-02-01 00:18 - 00002338 _____ () C:\Users\Lupi\Desktop\Rkill.txt
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\Users\Lupi\AppData\Local\LogMeIn
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-01-31 22:38 - 2014-01-31 22:38 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2014-01-31 22:38 - 2014-01-27 19:48 - 07054336 _____ () C:\Users\Lupi\Desktop\XNA Framework 4.0 Full.msi
2014-01-31 22:38 - 2014-01-27 19:48 - 00889416 _____ (Microsoft Corporation) C:\Users\Lupi\Desktop\.Net Framework 4.0 Full.exe
2014-01-31 22:32 - 2014-01-31 22:32 - 00000729 _____ () C:\Users\Public\Desktop\Terraria.lnk
2014-01-31 22:31 - 2014-01-31 22:31 - 00003294 _____ () C:\windows\System32\Tasks\Microsoft System Certificates
2014-01-31 22:08 - 2009-03-18 17:35 - 00033856 ____H (LogMeIn, Inc.) C:\windows\system32\hamachi.sys
2014-01-31 21:58 - 2014-01-31 22:01 - 00000000 ____D () C:\Users\Lupi\Documents\Battlefield 2
2014-01-31 21:58 - 2014-01-31 21:58 - 00000877 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-01-31 21:58 - 2014-01-31 21:58 - 00000855 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\Documents\Youcam
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\ProgramData\CyberLink
2014-01-29 18:36 - 2014-01-29 18:36 - 00000000 ____D () C:\Users\Lupi\Documents\4A Games
2014-01-29 18:35 - 2014-01-29 18:35 - 00000000 ____D () C:\Users\Lupi\AppData\Local\4A Games
2014-01-27 10:24 - 2014-01-27 10:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-01-26 01:10 - 2014-01-26 01:10 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard
2014-01-26 01:05 - 2014-01-26 01:05 - 00000865 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-01-25 13:47 - 2014-01-25 13:47 - 00000000 ____D () C:\Users\Lupi\Desktop\Camera
2014-01-25 10:12 - 2014-01-25 10:12 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\mrrescue
2014-01-24 21:38 - 2014-01-24 21:38 - 00049064 _____ () C:\Users\Lupi\Desktop\tv-cesnet-vlc.htm
2014-01-24 21:38 - 2014-01-24 21:38 - 00004982 _____ () C:\Users\Lupi\Desktop\TV_cesnet_0.vlc
2014-01-20 23:30 - 2014-01-20 23:30 - 00000737 _____ () C:\Users\Lupi\Desktop\AC4BFSP – zástupce.lnk
2014-01-17 00:20 - 2014-01-17 00:20 - 00000879 _____ () C:\Users\Public\Desktop\Legend of Grimrock.lnk
2014-01-17 00:20 - 2014-01-17 00:20 - 00000000 ____D () C:\Users\Lupi\Documents\Almost Human
2014-01-16 13:34 - 2014-01-16 13:34 - 00000754 _____ () C:\Users\Public\Desktop\Brány Skeldalu.lnk
2014-01-15 09:44 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2014-01-15 09:44 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2014-01-15 09:44 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2014-01-15 09:44 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-01-14 22:08 - 2014-01-14 22:08 - 00000000 ____D () C:\windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2014-01-14 22:07 - 2014-01-14 22:07 - 00000784 _____ () C:\Users\Public\Desktop\Unreal Tournament 3.lnk
2014-01-14 22:07 - 2014-01-14 22:07 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\InstallShield Installation Information
2014-01-14 21:36 - 2014-01-14 21:36 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-01-14 21:36 - 2014-01-14 21:36 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-14 20:39 - 2014-01-14 20:40 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Mozilla
2014-01-14 20:39 - 2014-01-14 20:40 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-01-14 17:35 - 2014-01-31 21:58 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-01-14 17:33 - 2014-01-14 17:33 - 00000890 _____ () C:\Users\Lupi\Desktop\Play UT2004.lnk
2014-01-14 16:05 - 2014-01-14 16:05 - 00000000 ____D () C:\Users\Lupi\Documents\Diablo III
2014-01-14 15:47 - 2014-01-14 15:47 - 00000836 _____ () C:\Users\Public\Desktop\Diablo III.lnk
2014-01-14 15:41 - 2014-02-01 00:58 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Battle.net
2014-01-14 15:41 - 2014-01-26 01:05 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-01-14 15:41 - 2014-01-14 15:44 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Battle.net
2014-01-14 15:41 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard Entertainment
2014-01-10 23:48 - 2014-01-10 23:48 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\VitySoft
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\.objectdb
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Sun
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-10 13:06 - 2014-01-10 13:06 - 00000000 ____D () C:\Users\Lupi\AppData\Local\DayZCommander
2014-01-09 15:48 - 2014-01-14 21:37 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Winamp
2014-01-09 15:48 - 2014-01-09 15:49 - 00000000 ____D () C:\Program Files (x86)\Winamp
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\SysWOW64\NV
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\system32\NV
2014-01-08 22:04 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 18310112 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 15877216 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 15230352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2014-01-08 22:04 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvenc.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvenc.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6433221.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6433221.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2014-01-08 22:04 - 2013-12-19 21:33 - 00032544 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvpciflt.sys
2014-01-08 22:03 - 2014-01-08 22:03 - 00000000 ____D () C:\NVIDIA
2014-01-06 20:54 - 2014-01-06 20:54 - 00001100 _____ () C:\Users\Lupi\Desktop\swkotor2 – zástupce.lnk
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\Users\Lupi\AppData\Local\WarThunder
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\ProgramData\WarThunder
2014-01-06 19:49 - 2014-01-06 19:49 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-01-05 21:07 - 2014-01-05 21:07 - 00098304 _____ (Sony DADC Austria AG.) C:\windows\SysWOW64\CmdLineExt.dll
2014-01-05 11:25 - 2014-01-06 20:52 - 00000000 ____D () C:\Program Files (x86)\Anti-Vibrate Oscar Editor
==================== One Month Modified Files and Folders =======
2014-02-03 09:08 - 2014-02-03 09:08 - 00021772 _____ () C:\Users\Lupi\Desktop\FRST.txt
2014-02-03 09:08 - 2014-02-03 09:03 - 00000000 ____D () C:\FRST
2014-02-03 09:07 - 2014-02-03 09:07 - 00112640 _____ (forum.viry.cz) C:\Users\Lupi\Desktop\FRSTLauncher.exe
2014-02-03 09:07 - 2014-02-03 09:07 - 00029696 _____ () C:\Users\Lupi\AppData\Local\MSGBOX.EXE
2014-02-03 09:07 - 2014-02-03 09:07 - 00015327 _____ () C:\Users\Lupi\Desktop\LM.bat
2014-02-03 09:05 - 2014-02-01 16:02 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Skype
2014-02-03 09:03 - 2013-12-03 14:10 - 00000000 ____D () C:\Users\Lupi\AppData\Local\CrashDumps
2014-02-03 09:02 - 2014-02-03 09:03 - 02080256 _____ (Farbar) C:\Users\Lupi\Desktop\FRST64.exe
2014-02-03 08:57 - 2011-12-20 11:38 - 00000966 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-03 08:55 - 2009-07-14 05:45 - 00021280 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-03 08:55 - 2009-07-14 05:45 - 00021280 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-03 08:54 - 2011-12-20 02:46 - 00669736 _____ () C:\windows\system32\perfh005.dat
2014-02-03 08:54 - 2011-12-20 02:46 - 00141336 _____ () C:\windows\system32\perfc005.dat
2014-02-03 08:54 - 2009-07-14 06:13 - 01585238 _____ () C:\windows\system32\PerfStringBackup.INI
2014-02-03 08:53 - 2011-12-20 11:43 - 00423750 _____ () C:\FaceProv.log
2014-02-03 08:51 - 2011-12-20 10:59 - 01749618 ____N () C:\windows\WindowsUpdate.log
2014-02-03 08:48 - 2013-11-14 12:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-02-03 08:48 - 2011-12-20 11:43 - 00000000 ____D () C:\ProgramData\VeriFace
2014-02-03 08:48 - 2011-12-20 11:38 - 00000962 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-03 08:48 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-02-02 20:55 - 2013-11-14 21:54 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Foxit Software
2014-02-02 14:12 - 2014-02-02 14:12 - 00000672 _____ () C:\Users\Public\Desktop\JPG To PDF.lnk
2014-02-02 14:10 - 2014-02-02 14:10 - 00000719 _____ () C:\Users\Lupi\Desktop\Convert Image To PDF.lnk
2014-02-01 21:03 - 2014-02-01 20:56 - 00000000 ____D () C:\Users\Lupi\AppData\Local\PokerStars
2014-02-01 20:56 - 2014-02-01 20:56 - 00000640 _____ () C:\Users\Public\Desktop\PokerStars.lnk
2014-02-01 20:32 - 2014-02-01 00:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-01 18:05 - 2014-02-01 18:05 - 00000085 _____ () C:\windows\wininit.ini
2014-02-01 18:05 - 2014-02-01 00:29 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-01 16:02 - 2014-02-01 16:02 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Skype
2014-02-01 16:02 - 2014-02-01 16:02 - 00000000 ____D () C:\ProgramData\Skype
2014-02-01 12:50 - 2013-11-14 22:17 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\DAEMON Tools Lite
2014-02-01 12:04 - 2014-02-01 12:04 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-02-01 01:06 - 2013-11-14 12:08 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\vlc
2014-02-01 00:58 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Battle.net
2014-02-01 00:57 - 2011-12-20 11:38 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-01 00:49 - 2013-12-27 15:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-01 00:49 - 2013-12-24 15:14 - 00000000 ____D () C:\Program Files (x86)\OscarX7Editor5Mode
2014-02-01 00:49 - 2013-11-17 12:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-02-01 00:49 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-02-01 00:49 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker
2014-02-01 00:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-02-01 00:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-02-01 00:47 - 2014-02-01 00:47 - 00003158 _____ () C:\windows\System32\Tasks\Game_Booster_AutoUpdate
2014-02-01 00:47 - 2014-02-01 00:47 - 00001186 _____ () C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
2014-02-01 00:47 - 2014-02-01 00:47 - 00001174 _____ () C:\Users\Public\Desktop\Game Booster 3.lnk
2014-02-01 00:47 - 2014-02-01 00:31 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-02-01 00:47 - 2014-02-01 00:19 - 00000000 ____D () C:\ProgramData\IObit
2014-02-01 00:44 - 2014-02-01 00:44 - 00001189 _____ () C:\Users\Public\Desktop\ManageMyMobile.lnk
2014-02-01 00:44 - 2014-02-01 00:31 - 00000000 ____D () C:\ProgramData\ProductData
2014-02-01 00:40 - 2011-02-22 12:19 - 00000000 ____D () C:\windows\Panther
2014-02-01 00:33 - 2014-02-01 00:31 - 00002209 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00003092 _____ () C:\windows\System32\Tasks\ASC7_PerformanceMonitor
2014-02-01 00:31 - 2014-02-01 00:31 - 00002848 _____ () C:\windows\System32\Tasks\ASC7_SkipUac_Lupi
2014-02-01 00:31 - 2014-02-01 00:31 - 00001217 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Apple Computer
2014-02-01 00:31 - 2014-02-01 00:31 - 00000000 ____D () C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-01 00:31 - 2014-02-01 00:19 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\IObit
2014-02-01 00:29 - 2014-02-01 00:29 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
2014-02-01 00:18 - 2014-02-01 00:17 - 00002338 _____ () C:\Users\Lupi\Desktop\Rkill.txt
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\Users\Lupi\AppData\Local\LogMeIn
2014-02-01 00:13 - 2014-02-01 00:13 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-01-31 22:42 - 2013-11-15 00:53 - 00000000 ____D () C:\Users\Lupi\Documents\My Games
2014-01-31 22:38 - 2014-01-31 22:38 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2014-01-31 22:32 - 2014-01-31 22:32 - 00000729 _____ () C:\Users\Public\Desktop\Terraria.lnk
2014-01-31 22:31 - 2014-01-31 22:31 - 00003294 _____ () C:\windows\System32\Tasks\Microsoft System Certificates
2014-01-31 22:01 - 2014-01-31 21:58 - 00000000 ____D () C:\Users\Lupi\Documents\Battlefield 2
2014-01-31 21:58 - 2014-01-31 21:58 - 00000877 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-01-31 21:58 - 2014-01-31 21:58 - 00000855 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-01-31 21:58 - 2014-01-14 17:35 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-01-31 21:53 - 2011-12-20 11:05 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\Documents\Youcam
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\Users\Lupi\AppData\Local\CyberLink
2014-01-29 20:02 - 2014-01-29 20:02 - 00000000 ____D () C:\ProgramData\CyberLink
2014-01-29 18:36 - 2014-01-29 18:36 - 00000000 ____D () C:\Users\Lupi\Documents\4A Games
2014-01-29 18:35 - 2014-01-29 18:35 - 00000000 ____D () C:\Users\Lupi\AppData\Local\4A Games
2014-01-29 18:34 - 2013-12-27 15:51 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\NVIDIA
2014-01-27 19:48 - 2014-01-31 22:38 - 07054336 _____ () C:\Users\Lupi\Desktop\XNA Framework 4.0 Full.msi
2014-01-27 19:48 - 2014-01-31 22:38 - 00889416 _____ (Microsoft Corporation) C:\Users\Lupi\Desktop\.Net Framework 4.0 Full.exe
2014-01-27 10:24 - 2014-01-27 10:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-01-26 01:10 - 2014-01-26 01:10 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard
2014-01-26 01:05 - 2014-01-26 01:05 - 00000865 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-01-26 01:05 - 2014-01-14 15:41 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-01-25 13:47 - 2014-01-25 13:47 - 00000000 ____D () C:\Users\Lupi\Desktop\Camera
2014-01-25 10:12 - 2014-01-25 10:12 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\mrrescue
2014-01-24 21:38 - 2014-01-24 21:38 - 00049064 _____ () C:\Users\Lupi\Desktop\tv-cesnet-vlc.htm
2014-01-24 21:38 - 2014-01-24 21:38 - 00004982 _____ () C:\Users\Lupi\Desktop\TV_cesnet_0.vlc
2014-01-20 23:30 - 2014-01-20 23:30 - 00000737 _____ () C:\Users\Lupi\Desktop\AC4BFSP – zástupce.lnk
2014-01-18 13:06 - 2013-12-01 16:58 - 00000000 ____D () C:\Users\Lupi\Desktop\reaktance synchronniho
2014-01-18 12:59 - 2013-11-14 12:00 - 00000000 __SHD () C:\windows\SysWOW64\AI_RecycleBin
2014-01-18 12:43 - 2013-12-25 16:30 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-01-17 00:20 - 2014-01-17 00:20 - 00000879 _____ () C:\Users\Public\Desktop\Legend of Grimrock.lnk
2014-01-17 00:20 - 2014-01-17 00:20 - 00000000 ____D () C:\Users\Lupi\Documents\Almost Human
2014-01-16 13:34 - 2014-01-16 13:34 - 00000754 _____ () C:\Users\Public\Desktop\Brány Skeldalu.lnk
2014-01-16 13:00 - 2009-07-14 05:45 - 04989048 _____ () C:\windows\system32\FNTCACHE.DAT
2014-01-16 08:43 - 2013-11-17 12:56 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-16 08:43 - 2013-11-14 13:26 - 00000000 ____D () C:\windows\system32\MRT
2014-01-16 08:41 - 2013-11-14 13:26 - 86054176 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-01-15 00:18 - 2013-11-14 11:28 - 00000000 ____D () C:\Users\Lupi
2014-01-14 22:08 - 2014-01-14 22:08 - 00000000 ____D () C:\windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2014-01-14 22:07 - 2014-01-14 22:07 - 00000784 _____ () C:\Users\Public\Desktop\Unreal Tournament 3.lnk
2014-01-14 22:07 - 2014-01-14 22:07 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\InstallShield Installation Information
2014-01-14 21:37 - 2014-01-09 15:48 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Winamp
2014-01-14 21:37 - 2013-12-31 00:30 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\TS3Client
2014-01-14 21:36 - 2014-01-14 21:36 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-01-14 21:36 - 2014-01-14 21:36 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-14 20:40 - 2014-01-14 20:39 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Mozilla
2014-01-14 20:40 - 2014-01-14 20:39 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-14 20:30 - 2014-01-14 20:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-01-14 17:33 - 2014-01-14 17:33 - 00000890 _____ () C:\Users\Lupi\Desktop\Play UT2004.lnk
2014-01-14 16:05 - 2014-01-14 16:05 - 00000000 ____D () C:\Users\Lupi\Documents\Diablo III
2014-01-14 15:47 - 2014-01-14 15:47 - 00000836 _____ () C:\Users\Public\Desktop\Diablo III.lnk
2014-01-14 15:44 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\Battle.net
2014-01-14 15:41 - 2014-01-14 15:41 - 00000000 ____D () C:\Users\Lupi\AppData\Local\Blizzard Entertainment
2014-01-13 20:55 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-01-10 23:48 - 2014-01-10 23:48 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-01-10 23:48 - 2014-01-10 23:48 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\AppData\Roaming\VitySoft
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Users\Lupi\.objectdb
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Sun
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-10 23:48 - 2014-01-10 23:48 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-10 13:06 - 2014-01-10 13:06 - 00000000 ____D () C:\Users\Lupi\AppData\Local\DayZCommander
2014-01-09 15:49 - 2014-01-09 15:48 - 00000000 ____D () C:\Program Files (x86)\Winamp
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\SysWOW64\NV
2014-01-08 22:07 - 2014-01-08 22:07 - 00000000 ____D () C:\windows\system32\NV
2014-01-08 22:07 - 2011-12-20 11:09 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-01-08 22:03 - 2014-01-08 22:03 - 00000000 ____D () C:\NVIDIA
2014-01-06 20:54 - 2014-01-06 20:54 - 00001100 _____ () C:\Users\Lupi\Desktop\swkotor2 – zástupce.lnk
2014-01-06 20:52 - 2014-01-05 11:25 - 00000000 ____D () C:\Program Files (x86)\Anti-Vibrate Oscar Editor
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\Users\Lupi\AppData\Local\WarThunder
2014-01-06 19:57 - 2014-01-06 19:57 - 00000000 ____D () C:\ProgramData\WarThunder
2014-01-06 19:49 - 2014-01-06 19:49 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-01-05 21:07 - 2014-01-05 21:07 - 00098304 _____ (Sony DADC Austria AG.) C:\windows\SysWOW64\CmdLineExt.dll
Some content of TEMP:
====================
C:\Users\Lupi\AppData\Local\Temp\Checkupdate.exe
C:\Users\Lupi\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Lupi\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Lupi\AppData\Local\Temp\gtapi_signed.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-29 14:01
==================== End Of Log ============================