Preventivka
Napsal: 20 črc 2014 20:13
Zdravím, poprosil bych o preventivní kontrolu logu.
Ps. W7 se při nabíhání freezne v té chvíly kdy se má zobrazit animace "okna" a je tam pouze napsané starting windows..
Poté musím pc restartovat a vše je ok, nevím jestli to může být virem, jestli ne tak si to někde vygoogluju.
Jinak dodávám log z mbam a roguekiller(nic nebylo smazáno), také svůj nastavený temp jsem promazal.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by Lopatak (administrator) on LOPATAK-PC on 20-07-2014 21:05:14
Running from C:\Users\Lopatak\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Angličtina (Spojené státy)
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(StarWind Software) C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
() C:\Program Files\Core Temp\Core Temp.exe
(Petr Laštovička) D:\hotke\HotkeyP.exe
() C:\Program Files (x86)\X7 Oscar Keyboard Editor\OscarEditor.exe
(TP-LINK TECHNOLOGIES CO., LTD.) C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Client Utility\ZDWlan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(forum.viry.cz) C:\Users\Lopatak\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [ZDWlan.EXE] => C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Client Utility\ZDWlan.EXE [491520 2009-01-14] (TP-LINK TECHNOLOGIES CO., LTD.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [186408 2014-02-04] (Geek Software GmbH)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Run: [HotkeyP] => D:\hotke\HotkeyP.exe [60928 2011-07-30] (Petr Laštovička)
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Run: [OscarKeyboard] => C:\Program Files (x86)\X7 Oscar Keyboard Editor\OscarEditor.exe [3536896 2010-12-24] ()
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\MountPoints2: {d08ca785-ebea-11e3-91be-a069dd09ca49} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\MountPoints2: {f26f03c0-d10c-11e1-9c65-806e6f6e6963} - K:\autorun.exe
Startup: C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: AutoCAD Digital Signatures Icon Overlay Handler -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
GroupPolicyUsers\S-1-5-21-2900694688-1406637510-3004938718-1017\User: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Hosts: 127.0.0.1 localhost
FireFox:
========
FF ProfilePath: C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll ()
FF Plugin: @java.com/DTPlugin,version=11.5.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.5.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Lopatak\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Lopatak\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: DownloadHelper - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-04-06]
FF Extension: AutoPager - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\autopager@mozilla.org.xpi [2012-11-25]
FF Extension: MEGA - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\firefox@mega.co.nz.xpi [2013-12-22]
FF Extension: Firefox Security Component - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\iseekdeal@iseekdeal.com.xpi [2012-12-19]
FF Extension: TS Magic Player - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\magicplayer@torrentstream.org.xpi [2014-02-26]
FF Extension: ImTranslator - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2012-11-25]
FF Extension: Adblock Plus - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-25]
==================== Services (Whitelisted) =================
ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-15] (LogMeIn, Inc.)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [625816 2012-06-22] (Pandora.TV)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-12-26] ()
R2 StarWindServiceAE; C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
==================== Drivers (Whitelisted) ====================
S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-08-22] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
S3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [151552 2005-08-03] (Creative Technology Ltd)
S3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [695808 2005-08-03] (Creative Technology Ltd)
S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [208896 2005-08-03] (Creative Technology Ltd)
S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [316928 2005-08-03] (Creative Technology Ltd)
S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [169472 2005-08-03] (Creative Technology Ltd)
S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [356864 2005-08-03] (Creative Technology Ltd)
S3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [676864 2005-08-03] (Creative Technology Ltd)
S3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-08-22] ()
R1 networx; C:\Windows\System32\drivers\networx.sys [59384 2013-11-20] (NetFilterSDK.com)
S2 nxsIO32; C:\Windows\SysWOW64\DRIVERS\nxsIO32.sys [2208 2013-06-18] ()
S4 RAMDiskVE; C:\Windows\System32\Drivers\RAMDiskVE.sys [86768 2014-01-07] (Dataram, Inc.)
S3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [60416 2008-07-22] (Realtek Semiconductor Corporation )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-07-18] (Duplex Secure Ltd.)
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 ZD1211BU(TP-LINK); C:\Windows\System32\DRIVERS\zd1211Bu.sys [602880 2009-01-05] (Atheros Technology Corporation)
U3 amfahbts; C:\Windows\System32\Drivers\amfahbts.sys [0 ] (Advanced Micro Devices)
U3 awrc4bs1; C:\Windows\System32\Drivers\awrc4bs1.sys [0 ] (Advanced Micro Devices)
S3 ALSysIO; \??\F:\TEMP\ALSysIO64.sys [X]
S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 kxwdmdrv; system32\drivers\kx.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 RTHDMIAzAudService; system32\drivers\RtHDMIVX.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WEASEL; \??\C:\Windows\system32\drivers\WEASEL.SYS [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-20 21:05 - 2014-07-20 21:05 - 00015172 _____ () C:\Users\Lopatak\Desktop\FRST.txt
2014-07-20 21:04 - 2014-07-20 21:05 - 00000000 ____D () C:\FRST
2014-07-20 21:04 - 2014-07-20 21:04 - 00015327 _____ () C:\Users\Lopatak\Desktop\LM.bat
2014-07-20 21:02 - 2014-07-20 21:03 - 00112640 _____ (forum.viry.cz) C:\Users\Lopatak\Desktop\FRSTLauncher.exe
2014-07-20 21:02 - 2014-07-20 21:02 - 02089984 _____ (Farbar) C:\Users\Lopatak\Desktop\FRST64.exe
2014-07-20 20:49 - 2014-07-20 20:49 - 00006701 _____ () C:\Users\Lopatak\Desktop\RKreport_SCN_07202014_204839.log
2014-07-20 20:13 - 2014-07-20 20:13 - 00001401 _____ () C:\Users\Lopatak\Desktop\dsfds.txt
2014-07-20 19:54 - 2014-07-20 20:40 - 00030312 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-20 19:45 - 2014-07-20 19:46 - 05336664 _____ () C:\Users\Lopatak\Desktop\RogueKillerX64.exe
2014-07-19 12:23 - 2014-07-19 12:23 - 00000834 _____ () C:\Users\Lopatak\Desktop\NASA Space Program.lnk
2014-07-17 20:28 - 2014-07-17 21:03 - 159512048 _____ () C:\Users\Lopatak\Downloads\Hemi-Sync_-_Journeys_Out_Of_The_Body_-_Condition_C.flac
2014-07-16 21:02 - 2014-07-16 21:04 - 10863236 _____ () C:\Users\Lopatak\Desktop\125599.flv
2014-07-16 17:44 - 2014-07-16 21:04 - 122718118 _____ () C:\Users\Lopatak\Downloads\I-Doser.Pack.allin1.rar
2014-07-15 19:31 - 2014-07-15 19:31 - 00001671 _____ () C:\Users\Public\Desktop\SSDlife Pro.lnk
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDlife
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Licenses
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Binarysense
2014-07-15 19:09 - 2012-12-22 21:09 - 00444928 _____ (Alex Schepeljanski) C:\Users\Lopatak\Desktop\AS SSD Benchmark.exe
2014-07-14 20:40 - 2014-07-14 21:11 - 155290087 _____ () C:\Users\Lopatak\Desktop\Hemi-Sync-OM-The-reverberation-of-source-(Alpha).mp4
2014-07-14 19:33 - 2014-07-14 19:34 - 00018758 _____ () C:\Users\Lopatak\Downloads\[CzT]Kerbal_Space_Program_0_23_5_Asteroid_Redirect_Mission.torrent
2014-07-11 22:10 - 2014-07-11 22:17 - 31088558 ____H () C:\Users\Lopatak\Desktop\0560519.flv
2014-07-11 12:14 - 2014-07-11 20:33 - 10485934 _____ () C:\Users\Lopatak\HardwareMonitoring.hml
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Ostatní\Desktop\MAFIA II .lnk
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Lopatak\Desktop\MAFIA II .lnk
2014-07-08 10:48 - 2014-06-15 13:23 - 00346468 ____N () C:\Users\Lopatak\Desktop\Video0016.mp4
2014-07-07 10:16 - 2014-07-10 11:13 - 00002129 _____ () C:\Windows\WindowsUpdate.log
2014-07-03 09:46 - 2014-07-20 19:42 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-03 09:45 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-03 09:44 - 2014-07-03 09:44 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-03 06:43 - 2014-07-03 06:43 - 00000274 _____ () C:\Windows\PFRO.log
2014-07-02 22:57 - 2014-07-02 22:57 - 00494311 _____ () C:\Users\Lopatak\Desktop\starmade-build_20140702_161216.zip
2014-07-02 19:32 - 2014-07-02 19:32 - 00001537 _____ () C:\Users\Public\Desktop\Start Lock On.lnk
2014-07-02 19:32 - 2014-07-02 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XviD
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Program Files (x86)\XviD
2014-07-02 19:18 - 2003-11-06 20:26 - 00518416 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSXML.DLL
2014-07-02 19:15 - 2005-11-23 10:48 - 00002858 _____ () C:\Users\Lopatak\Desktop\LOCKON.mds
2014-07-02 19:12 - 2005-11-23 10:48 - 749961072 _____ () C:\Users\Lopatak\Desktop\LOCKON.mdf
2014-07-01 20:35 - 2014-07-01 20:35 - 00288968 _____ () C:\Windows\Minidump\070114-9094-01.dmp
2014-07-01 19:45 - 2014-07-01 19:48 - 00000000 ____D () C:\Program Files (x86)\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 17:58 - 2014-07-01 17:59 - 02337260 _____ () C:\Users\Lopatak\Downloads\VODAFONE_LINKA.mp3.crdownload
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3.0
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\Program Files\MSI Kombustor 3.0
2014-06-29 20:41 - 2014-07-20 20:39 - 00005948 _____ () C:\Windows\setupact.log
2014-06-29 20:41 - 2014-06-29 20:41 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-29 14:20 - 2014-06-29 14:24 - 00000000 ____D () C:\Users\Lopatak\Desktop\SHIPS
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
==================== One Month Modified Files and Folders =======
2014-07-20 21:05 - 2014-07-20 21:05 - 00015172 _____ () C:\Users\Lopatak\Desktop\FRST.txt
2014-07-20 21:05 - 2014-07-20 21:04 - 00000000 ____D () C:\FRST
2014-07-20 21:04 - 2014-07-20 21:04 - 00015327 _____ () C:\Users\Lopatak\Desktop\LM.bat
2014-07-20 21:03 - 2014-07-20 21:02 - 00112640 _____ (forum.viry.cz) C:\Users\Lopatak\Desktop\FRSTLauncher.exe
2014-07-20 21:02 - 2014-07-20 21:02 - 02089984 _____ (Farbar) C:\Users\Lopatak\Desktop\FRST64.exe
2014-07-20 20:49 - 2014-07-20 20:49 - 00006701 _____ () C:\Users\Lopatak\Desktop\RKreport_SCN_07202014_204839.log
2014-07-20 20:47 - 2013-12-18 21:59 - 00003030 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2014-07-20 20:47 - 2013-03-22 22:29 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-07-20 20:44 - 2009-07-14 06:45 - 00017264 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-20 20:44 - 2009-07-14 06:45 - 00017264 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-20 20:40 - 2014-07-20 19:54 - 00030312 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-20 20:40 - 2013-02-20 16:15 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-20 20:39 - 2014-06-29 20:41 - 00005948 _____ () C:\Windows\setupact.log
2014-07-20 20:39 - 2010-01-03 05:25 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-20 20:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-20 20:13 - 2014-07-20 20:13 - 00001401 _____ () C:\Users\Lopatak\Desktop\dsfds.txt
2014-07-20 20:10 - 2013-02-20 16:15 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-20 19:46 - 2014-07-20 19:45 - 05336664 _____ () C:\Users\Lopatak\Desktop\RogueKillerX64.exe
2014-07-20 19:42 - 2014-07-03 09:46 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-19 20:17 - 2012-11-17 20:07 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\vlc
2014-07-19 12:23 - 2014-07-19 12:23 - 00000834 _____ () C:\Users\Lopatak\Desktop\NASA Space Program.lnk
2014-07-17 21:03 - 2014-07-17 20:28 - 159512048 _____ () C:\Users\Lopatak\Downloads\Hemi-Sync_-_Journeys_Out_Of_The_Body_-_Condition_C.flac
2014-07-17 20:26 - 2013-02-27 19:30 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-16 22:21 - 2012-11-25 20:30 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\BitTorrent
2014-07-16 21:04 - 2014-07-16 21:02 - 10863236 _____ () C:\Users\Lopatak\Desktop\125599.flv
2014-07-16 21:04 - 2014-07-16 17:44 - 122718118 _____ () C:\Users\Lopatak\Downloads\I-Doser.Pack.allin1.rar
2014-07-15 19:31 - 2014-07-15 19:31 - 00001671 _____ () C:\Users\Public\Desktop\SSDlife Pro.lnk
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDlife
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Licenses
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Binarysense
2014-07-14 21:11 - 2014-07-14 20:40 - 155290087 _____ () C:\Users\Lopatak\Desktop\Hemi-Sync-OM-The-reverberation-of-source-(Alpha).mp4
2014-07-14 19:34 - 2014-07-14 19:33 - 00018758 _____ () C:\Users\Lopatak\Downloads\[CzT]Kerbal_Space_Program_0_23_5_Asteroid_Redirect_Mission.torrent
2014-07-12 09:17 - 2012-12-03 23:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-11 22:17 - 2014-07-11 22:10 - 31088558 ____H () C:\Users\Lopatak\Desktop\0560519.flv
2014-07-11 22:09 - 2013-06-17 22:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-11 20:33 - 2014-07-11 12:14 - 10485934 _____ () C:\Users\Lopatak\HardwareMonitoring.hml
2014-07-11 12:14 - 2012-06-26 19:07 - 00000000 ____D () C:\Users\Lopatak
2014-07-10 22:15 - 2013-12-26 13:17 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-10 11:13 - 2014-07-07 10:16 - 00002129 _____ () C:\Windows\WindowsUpdate.log
2014-07-09 10:21 - 2013-11-27 01:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-07-08 23:47 - 2013-01-05 20:10 - 00000000 ____D () C:\Program Files (x86)\AMD
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Ostatní\Desktop\MAFIA II .lnk
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Lopatak\Desktop\MAFIA II .lnk
2014-07-08 23:25 - 2013-04-25 20:48 - 00000000 ____D () C:\Hudba II
2014-07-08 23:21 - 2012-11-17 20:21 - 00000000 ____D () C:\GAMES
2014-07-08 10:47 - 2013-12-22 21:50 - 00000000 ___RD () C:\Users\Lopatak\Desktop\Bordel
2014-07-07 23:56 - 2014-05-31 14:29 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-07-07 21:06 - 2014-04-15 21:30 - 00000000 ___HD () C:\Users\Lopatak\Desktop\StarMade
2014-07-03 18:33 - 2014-01-11 21:34 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2013-12-19 00:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-07-03 09:45 - 2013-03-26 21:54 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Malwarebytes
2014-07-03 09:45 - 2013-03-26 21:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-03 09:44 - 2014-07-03 09:44 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-03 06:43 - 2014-07-03 06:43 - 00000274 _____ () C:\Windows\PFRO.log
2014-07-02 22:57 - 2014-07-02 22:57 - 00494311 _____ () C:\Users\Lopatak\Desktop\starmade-build_20140702_161216.zip
2014-07-02 19:32 - 2014-07-02 19:32 - 00001537 _____ () C:\Users\Public\Desktop\Start Lock On.lnk
2014-07-02 19:32 - 2014-07-02 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-07-02 19:32 - 2012-12-06 20:34 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-02 19:29 - 2012-06-27 17:10 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XviD
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Program Files (x86)\XviD
2014-07-02 18:54 - 2012-07-18 21:14 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\DAEMON Tools Lite
2014-07-01 20:35 - 2014-07-01 20:35 - 00288968 _____ () C:\Windows\Minidump\070114-9094-01.dmp
2014-07-01 20:35 - 2012-07-08 10:27 - 00000000 ____D () C:\Windows\Minidump
2014-07-01 19:54 - 2013-12-24 21:15 - 00000000 ____D () C:\Users\Lopatak\Documents\OCCT
2014-07-01 19:48 - 2014-07-01 19:45 - 00000000 ____D () C:\Program Files (x86)\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 17:59 - 2014-07-01 17:58 - 02337260 _____ () C:\Users\Lopatak\Downloads\VODAFONE_LINKA.mp3.crdownload
2014-07-01 09:16 - 2009-07-14 07:08 - 00032572 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3.0
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\Program Files\MSI Kombustor 3.0
2014-06-29 20:41 - 2014-06-29 20:41 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-29 14:33 - 2014-03-15 18:38 - 00000000 ____D () C:\Users\Lopatak\Desktop\NEW
2014-06-29 14:24 - 2014-06-29 14:20 - 00000000 ____D () C:\Users\Lopatak\Desktop\SHIPS
2014-06-29 13:11 - 2013-06-08 12:03 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-29 13:11 - 2012-06-26 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-06-22 11:34 - 2012-12-22 15:45 - 00000000 ___RD () C:\Users\Lopatak\Desktop\škola
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-07-18 22:11
==================== End Of Log ============================
Ps. W7 se při nabíhání freezne v té chvíly kdy se má zobrazit animace "okna" a je tam pouze napsané starting windows..
Poté musím pc restartovat a vše je ok, nevím jestli to může být virem, jestli ne tak si to někde vygoogluju.
Jinak dodávám log z mbam a roguekiller(nic nebylo smazáno), také svůj nastavený temp jsem promazal.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by Lopatak (administrator) on LOPATAK-PC on 20-07-2014 21:05:14
Running from C:\Users\Lopatak\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Angličtina (Spojené státy)
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(StarWind Software) C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
() C:\Program Files\Core Temp\Core Temp.exe
(Petr Laštovička) D:\hotke\HotkeyP.exe
() C:\Program Files (x86)\X7 Oscar Keyboard Editor\OscarEditor.exe
(TP-LINK TECHNOLOGIES CO., LTD.) C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Client Utility\ZDWlan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(forum.viry.cz) C:\Users\Lopatak\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [ZDWlan.EXE] => C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Client Utility\ZDWlan.EXE [491520 2009-01-14] (TP-LINK TECHNOLOGIES CO., LTD.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [186408 2014-02-04] (Geek Software GmbH)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Run: [HotkeyP] => D:\hotke\HotkeyP.exe [60928 2011-07-30] (Petr Laštovička)
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Run: [OscarKeyboard] => C:\Program Files (x86)\X7 Oscar Keyboard Editor\OscarEditor.exe [3536896 2010-12-24] ()
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\MountPoints2: {d08ca785-ebea-11e3-91be-a069dd09ca49} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-2900694688-1406637510-3004938718-1001\...\MountPoints2: {f26f03c0-d10c-11e1-9c65-806e6f6e6963} - K:\autorun.exe
Startup: C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: AutoCAD Digital Signatures Icon Overlay Handler -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
GroupPolicyUsers\S-1-5-21-2900694688-1406637510-3004938718-1017\User: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Hosts: 127.0.0.1 localhost
FireFox:
========
FF ProfilePath: C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll ()
FF Plugin: @java.com/DTPlugin,version=11.5.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.5.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Lopatak\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Lopatak\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: DownloadHelper - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-04-06]
FF Extension: AutoPager - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\autopager@mozilla.org.xpi [2012-11-25]
FF Extension: MEGA - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\firefox@mega.co.nz.xpi [2013-12-22]
FF Extension: Firefox Security Component - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\iseekdeal@iseekdeal.com.xpi [2012-12-19]
FF Extension: TS Magic Player - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\magicplayer@torrentstream.org.xpi [2014-02-26]
FF Extension: ImTranslator - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2012-11-25]
FF Extension: Adblock Plus - C:\Users\Lopatak\AppData\Roaming\Mozilla\Firefox\Profiles\27efvmfz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-25]
==================== Services (Whitelisted) =================
ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-15] (LogMeIn, Inc.)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [625816 2012-06-22] (Pandora.TV)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-12-26] ()
R2 StarWindServiceAE; C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
==================== Drivers (Whitelisted) ====================
S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-08-22] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
S3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [151552 2005-08-03] (Creative Technology Ltd)
S3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [695808 2005-08-03] (Creative Technology Ltd)
S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [208896 2005-08-03] (Creative Technology Ltd)
S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [316928 2005-08-03] (Creative Technology Ltd)
S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [169472 2005-08-03] (Creative Technology Ltd)
S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [356864 2005-08-03] (Creative Technology Ltd)
S3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [676864 2005-08-03] (Creative Technology Ltd)
S3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-08-22] ()
R1 networx; C:\Windows\System32\drivers\networx.sys [59384 2013-11-20] (NetFilterSDK.com)
S2 nxsIO32; C:\Windows\SysWOW64\DRIVERS\nxsIO32.sys [2208 2013-06-18] ()
S4 RAMDiskVE; C:\Windows\System32\Drivers\RAMDiskVE.sys [86768 2014-01-07] (Dataram, Inc.)
S3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [60416 2008-07-22] (Realtek Semiconductor Corporation )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-07-18] (Duplex Secure Ltd.)
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 ZD1211BU(TP-LINK); C:\Windows\System32\DRIVERS\zd1211Bu.sys [602880 2009-01-05] (Atheros Technology Corporation)
U3 amfahbts; C:\Windows\System32\Drivers\amfahbts.sys [0 ] (Advanced Micro Devices)
U3 awrc4bs1; C:\Windows\System32\Drivers\awrc4bs1.sys [0 ] (Advanced Micro Devices)
S3 ALSysIO; \??\F:\TEMP\ALSysIO64.sys [X]
S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 kxwdmdrv; system32\drivers\kx.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 RTHDMIAzAudService; system32\drivers\RtHDMIVX.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WEASEL; \??\C:\Windows\system32\drivers\WEASEL.SYS [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-20 21:05 - 2014-07-20 21:05 - 00015172 _____ () C:\Users\Lopatak\Desktop\FRST.txt
2014-07-20 21:04 - 2014-07-20 21:05 - 00000000 ____D () C:\FRST
2014-07-20 21:04 - 2014-07-20 21:04 - 00015327 _____ () C:\Users\Lopatak\Desktop\LM.bat
2014-07-20 21:02 - 2014-07-20 21:03 - 00112640 _____ (forum.viry.cz) C:\Users\Lopatak\Desktop\FRSTLauncher.exe
2014-07-20 21:02 - 2014-07-20 21:02 - 02089984 _____ (Farbar) C:\Users\Lopatak\Desktop\FRST64.exe
2014-07-20 20:49 - 2014-07-20 20:49 - 00006701 _____ () C:\Users\Lopatak\Desktop\RKreport_SCN_07202014_204839.log
2014-07-20 20:13 - 2014-07-20 20:13 - 00001401 _____ () C:\Users\Lopatak\Desktop\dsfds.txt
2014-07-20 19:54 - 2014-07-20 20:40 - 00030312 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-20 19:45 - 2014-07-20 19:46 - 05336664 _____ () C:\Users\Lopatak\Desktop\RogueKillerX64.exe
2014-07-19 12:23 - 2014-07-19 12:23 - 00000834 _____ () C:\Users\Lopatak\Desktop\NASA Space Program.lnk
2014-07-17 20:28 - 2014-07-17 21:03 - 159512048 _____ () C:\Users\Lopatak\Downloads\Hemi-Sync_-_Journeys_Out_Of_The_Body_-_Condition_C.flac
2014-07-16 21:02 - 2014-07-16 21:04 - 10863236 _____ () C:\Users\Lopatak\Desktop\125599.flv
2014-07-16 17:44 - 2014-07-16 21:04 - 122718118 _____ () C:\Users\Lopatak\Downloads\I-Doser.Pack.allin1.rar
2014-07-15 19:31 - 2014-07-15 19:31 - 00001671 _____ () C:\Users\Public\Desktop\SSDlife Pro.lnk
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDlife
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Licenses
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Binarysense
2014-07-15 19:09 - 2012-12-22 21:09 - 00444928 _____ (Alex Schepeljanski) C:\Users\Lopatak\Desktop\AS SSD Benchmark.exe
2014-07-14 20:40 - 2014-07-14 21:11 - 155290087 _____ () C:\Users\Lopatak\Desktop\Hemi-Sync-OM-The-reverberation-of-source-(Alpha).mp4
2014-07-14 19:33 - 2014-07-14 19:34 - 00018758 _____ () C:\Users\Lopatak\Downloads\[CzT]Kerbal_Space_Program_0_23_5_Asteroid_Redirect_Mission.torrent
2014-07-11 22:10 - 2014-07-11 22:17 - 31088558 ____H () C:\Users\Lopatak\Desktop\0560519.flv
2014-07-11 12:14 - 2014-07-11 20:33 - 10485934 _____ () C:\Users\Lopatak\HardwareMonitoring.hml
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Ostatní\Desktop\MAFIA II .lnk
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Lopatak\Desktop\MAFIA II .lnk
2014-07-08 10:48 - 2014-06-15 13:23 - 00346468 ____N () C:\Users\Lopatak\Desktop\Video0016.mp4
2014-07-07 10:16 - 2014-07-10 11:13 - 00002129 _____ () C:\Windows\WindowsUpdate.log
2014-07-03 09:46 - 2014-07-20 19:42 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-03 09:45 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-03 09:44 - 2014-07-03 09:44 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-03 06:43 - 2014-07-03 06:43 - 00000274 _____ () C:\Windows\PFRO.log
2014-07-02 22:57 - 2014-07-02 22:57 - 00494311 _____ () C:\Users\Lopatak\Desktop\starmade-build_20140702_161216.zip
2014-07-02 19:32 - 2014-07-02 19:32 - 00001537 _____ () C:\Users\Public\Desktop\Start Lock On.lnk
2014-07-02 19:32 - 2014-07-02 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XviD
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Program Files (x86)\XviD
2014-07-02 19:18 - 2003-11-06 20:26 - 00518416 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSXML.DLL
2014-07-02 19:15 - 2005-11-23 10:48 - 00002858 _____ () C:\Users\Lopatak\Desktop\LOCKON.mds
2014-07-02 19:12 - 2005-11-23 10:48 - 749961072 _____ () C:\Users\Lopatak\Desktop\LOCKON.mdf
2014-07-01 20:35 - 2014-07-01 20:35 - 00288968 _____ () C:\Windows\Minidump\070114-9094-01.dmp
2014-07-01 19:45 - 2014-07-01 19:48 - 00000000 ____D () C:\Program Files (x86)\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 17:58 - 2014-07-01 17:59 - 02337260 _____ () C:\Users\Lopatak\Downloads\VODAFONE_LINKA.mp3.crdownload
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3.0
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\Program Files\MSI Kombustor 3.0
2014-06-29 20:41 - 2014-07-20 20:39 - 00005948 _____ () C:\Windows\setupact.log
2014-06-29 20:41 - 2014-06-29 20:41 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-29 14:20 - 2014-06-29 14:24 - 00000000 ____D () C:\Users\Lopatak\Desktop\SHIPS
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
==================== One Month Modified Files and Folders =======
2014-07-20 21:05 - 2014-07-20 21:05 - 00015172 _____ () C:\Users\Lopatak\Desktop\FRST.txt
2014-07-20 21:05 - 2014-07-20 21:04 - 00000000 ____D () C:\FRST
2014-07-20 21:04 - 2014-07-20 21:04 - 00015327 _____ () C:\Users\Lopatak\Desktop\LM.bat
2014-07-20 21:03 - 2014-07-20 21:02 - 00112640 _____ (forum.viry.cz) C:\Users\Lopatak\Desktop\FRSTLauncher.exe
2014-07-20 21:02 - 2014-07-20 21:02 - 02089984 _____ (Farbar) C:\Users\Lopatak\Desktop\FRST64.exe
2014-07-20 20:49 - 2014-07-20 20:49 - 00006701 _____ () C:\Users\Lopatak\Desktop\RKreport_SCN_07202014_204839.log
2014-07-20 20:47 - 2013-12-18 21:59 - 00003030 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2014-07-20 20:47 - 2013-03-22 22:29 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-07-20 20:44 - 2009-07-14 06:45 - 00017264 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-20 20:44 - 2009-07-14 06:45 - 00017264 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-20 20:40 - 2014-07-20 19:54 - 00030312 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-20 20:40 - 2013-02-20 16:15 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-20 20:39 - 2014-06-29 20:41 - 00005948 _____ () C:\Windows\setupact.log
2014-07-20 20:39 - 2010-01-03 05:25 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-20 20:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-20 20:13 - 2014-07-20 20:13 - 00001401 _____ () C:\Users\Lopatak\Desktop\dsfds.txt
2014-07-20 20:10 - 2013-02-20 16:15 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-20 19:46 - 2014-07-20 19:45 - 05336664 _____ () C:\Users\Lopatak\Desktop\RogueKillerX64.exe
2014-07-20 19:42 - 2014-07-03 09:46 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-19 20:17 - 2012-11-17 20:07 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\vlc
2014-07-19 12:23 - 2014-07-19 12:23 - 00000834 _____ () C:\Users\Lopatak\Desktop\NASA Space Program.lnk
2014-07-17 21:03 - 2014-07-17 20:28 - 159512048 _____ () C:\Users\Lopatak\Downloads\Hemi-Sync_-_Journeys_Out_Of_The_Body_-_Condition_C.flac
2014-07-17 20:26 - 2013-02-27 19:30 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-16 22:21 - 2012-11-25 20:30 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\BitTorrent
2014-07-16 21:04 - 2014-07-16 21:02 - 10863236 _____ () C:\Users\Lopatak\Desktop\125599.flv
2014-07-16 21:04 - 2014-07-16 17:44 - 122718118 _____ () C:\Users\Lopatak\Downloads\I-Doser.Pack.allin1.rar
2014-07-15 19:31 - 2014-07-15 19:31 - 00001671 _____ () C:\Users\Public\Desktop\SSDlife Pro.lnk
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDlife
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Licenses
2014-07-15 19:31 - 2014-07-15 19:31 - 00000000 ____D () C:\ProgramData\Binarysense
2014-07-14 21:11 - 2014-07-14 20:40 - 155290087 _____ () C:\Users\Lopatak\Desktop\Hemi-Sync-OM-The-reverberation-of-source-(Alpha).mp4
2014-07-14 19:34 - 2014-07-14 19:33 - 00018758 _____ () C:\Users\Lopatak\Downloads\[CzT]Kerbal_Space_Program_0_23_5_Asteroid_Redirect_Mission.torrent
2014-07-12 09:17 - 2012-12-03 23:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-11 22:17 - 2014-07-11 22:10 - 31088558 ____H () C:\Users\Lopatak\Desktop\0560519.flv
2014-07-11 22:09 - 2013-06-17 22:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-11 20:33 - 2014-07-11 12:14 - 10485934 _____ () C:\Users\Lopatak\HardwareMonitoring.hml
2014-07-11 12:14 - 2012-06-26 19:07 - 00000000 ____D () C:\Users\Lopatak
2014-07-10 22:15 - 2013-12-26 13:17 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-10 11:13 - 2014-07-07 10:16 - 00002129 _____ () C:\Windows\WindowsUpdate.log
2014-07-09 10:21 - 2013-11-27 01:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-07-08 23:47 - 2013-01-05 20:10 - 00000000 ____D () C:\Program Files (x86)\AMD
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Ostatní\Desktop\MAFIA II .lnk
2014-07-08 23:27 - 2014-07-08 23:27 - 00001586 _____ () C:\Users\Lopatak\Desktop\MAFIA II .lnk
2014-07-08 23:25 - 2013-04-25 20:48 - 00000000 ____D () C:\Hudba II
2014-07-08 23:21 - 2012-11-17 20:21 - 00000000 ____D () C:\GAMES
2014-07-08 10:47 - 2013-12-22 21:50 - 00000000 ___RD () C:\Users\Lopatak\Desktop\Bordel
2014-07-07 23:56 - 2014-05-31 14:29 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-07-07 21:06 - 2014-04-15 21:30 - 00000000 ___HD () C:\Users\Lopatak\Desktop\StarMade
2014-07-03 18:33 - 2014-01-11 21:34 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2014-07-03 09:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-03 09:45 - 2013-12-19 00:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-07-03 09:45 - 2013-03-26 21:54 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Malwarebytes
2014-07-03 09:45 - 2013-03-26 21:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-03 09:44 - 2014-07-03 09:44 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-03 06:43 - 2014-07-03 06:43 - 00000274 _____ () C:\Windows\PFRO.log
2014-07-02 22:57 - 2014-07-02 22:57 - 00494311 _____ () C:\Users\Lopatak\Desktop\starmade-build_20140702_161216.zip
2014-07-02 19:32 - 2014-07-02 19:32 - 00001537 _____ () C:\Users\Public\Desktop\Start Lock On.lnk
2014-07-02 19:32 - 2014-07-02 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-07-02 19:32 - 2012-12-06 20:34 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-02 19:29 - 2012-06-27 17:10 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XviD
2014-07-02 19:24 - 2014-07-02 19:24 - 00000000 ____D () C:\Program Files (x86)\XviD
2014-07-02 18:54 - 2012-07-18 21:14 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\DAEMON Tools Lite
2014-07-01 20:35 - 2014-07-01 20:35 - 00288968 _____ () C:\Windows\Minidump\070114-9094-01.dmp
2014-07-01 20:35 - 2012-07-08 10:27 - 00000000 ____D () C:\Windows\Minidump
2014-07-01 19:54 - 2013-12-24 21:15 - 00000000 ____D () C:\Users\Lopatak\Documents\OCCT
2014-07-01 19:48 - 2014-07-01 19:45 - 00000000 ____D () C:\Program Files (x86)\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 19:45 - 2014-07-01 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prime95
2014-07-01 17:59 - 2014-07-01 17:58 - 02337260 _____ () C:\Users\Lopatak\Downloads\VODAFONE_LINKA.mp3.crdownload
2014-07-01 09:16 - 2009-07-14 07:08 - 00032572 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3.0
2014-06-29 22:01 - 2014-06-29 22:01 - 00000000 ____D () C:\Program Files\MSI Kombustor 3.0
2014-06-29 20:41 - 2014-06-29 20:41 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-29 14:33 - 2014-03-15 18:38 - 00000000 ____D () C:\Users\Lopatak\Desktop\NEW
2014-06-29 14:24 - 2014-06-29 14:20 - 00000000 ____D () C:\Users\Lopatak\Desktop\SHIPS
2014-06-29 13:11 - 2013-06-08 12:03 - 00000000 ____D () C:\Users\Lopatak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-29 13:11 - 2012-06-26 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-06-24 19:02 - 2014-06-24 19:02 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-06-22 11:34 - 2012-12-22 15:45 - 00000000 ___RD () C:\Users\Lopatak\Desktop\škola
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-07-18 22:11
==================== End Of Log ============================