Rundll32 - zvýšení výkonu procesoru
Napsal: 28 srp 2014 17:38
Dobrý den, mám takový problém. Neustále mi zvyšují výkon procesoru hostitelské soubory , konkrétně když to vyhledám ve složce je to nějaký problém s Rundll32.
ZDE FRST LOG :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by mimo (administrator) on MSI on 28-08-2014 18:38:43
Running from C:\Users\mimo\Desktop
Platform: Windows 8 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Enigma Software Group USA, LLC.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
() C:\Users\mimo\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\mimo\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Allstar Group, s.r.o.) C:\Program Files\GamePark2\gpcl.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
() C:\Program Files (x86)\Opera\23.0.1522.77\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-09-06] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2889072 2013-09-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-08-22] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [408232 2013-08-22] (MSI)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403288 2014-08-09] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5634800 2012-06-14] (ESET)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-07] (MSI)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-09] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [181208 2013-04-02] (cyberlink)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1974168 2014-08-14] (APN)
HKLM Group Policy restriction on software: C:\Program Files (x86)\Kaspersky Lab <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\AVG <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Common Files\Symantec Shared <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\AVG <====== ATTENTION
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\.DEFAULT\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\.DEFAULT\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [Advanced SystemCare 3] => C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe [2342608 2010-02-01] (IObit)
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [4287536 2014-01-09] ()
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21653096 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\mimo\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\mimo\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GamePark klient 2.lnk
ShortcutTarget: GamePark klient 2.lnk -> C:\Program Files\GamePark2\gpcl.exe (Allstar Group, s.r.o.)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {81011E39-A0F7-41EF-96CF-4802A9780789} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {81011E39-A0F7-41EF-96CF-4802A9780789} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {88F7F8C6-6326-4F41-B98B-503043F5E2CD} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {94D3294C-F6D5-4863-ACD0-4536F0459CD6} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {99E01646-4330-4DB3-9F04-9E7CD077F42E} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A734D46C-0FD7-4783-A21D-7EE9F70ED811} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {AE3DE580-CBEC-4FA5-A108-A4CC0D3820B3} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
SearchScopes: HKCU - {CABC489B-4019-487A-9102-91BF4D2C127F} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {D260BBB6-5678-4B02-8836-3D35B7C71B2D} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {EDCF6918-A47D-482B-854A-5DFDC1EFF90F} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
BHO: Ask Toolbar -> {41545534-2D56-3700-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport_x64.dll (APN LLC.)
BHO-x32: Ask Toolbar -> {41545534-2D56-3700-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport.dll (APN LLC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Ask Toolbar - {41545534-2D56-3700-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Ask Toolbar - {41545534-2D56-3700-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport.dll (APN LLC.)
Winsock: Catalog9 01 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 02 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 03 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 04 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 16 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 16 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-07-26]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-08-14] (APN LLC.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [File not signed]
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [247768 2013-04-03] (CyberLink)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1288104 2012-06-14] (ESET)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [98672 2013-09-06] (ELAN Microelectronics Corp.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-08-22] (Micro-Star International Co., Ltd.) [File not signed]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [154112 2013-02-08] (MSI) [File not signed]
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720792 2014-08-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18973144 2014-08-09] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-11-09] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [214520 2014-07-07] ()
S2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [503296 2013-05-17] () [File not signed]
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-12-07] (SolidWorks) [File not signed]
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [327064 2010-05-18] (Enigma Software Group USA, LLC.)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
R2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [143288 2014-04-04] (Stardock Software, Inc)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-09-07] (Microsoft Corporation)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2013-05-17] (Qualcomm Atheros, Inc.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-06-23] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [211344 2012-06-14] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [149592 2012-06-14] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [138232 2012-06-14] (ESET)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2013-11-29] (LogMeIn Inc.)
R3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [19952 2013-02-01] (Windows (R) Win 7 DDK provider)
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [174448 2013-05-17] (Qualcomm Atheros, Inc.)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20440 2014-08-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [532552 2013-09-06] (Realtek Semiconductor Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [407112 2013-09-06] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1549384 2013-09-06] (Realtek Semiconductor Corporation )
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 18:38 - 2014-08-28 18:38 - 00000000 ____D () C:\Users\mimo\Desktop\FRST-OlderVersion
2014-08-28 18:38 - 2014-08-28 18:38 - 00000000 _____ () C:\Users\mimo\Desktop\FRST.txt
2014-08-28 15:39 - 2014-08-28 15:39 - 00000000 ____D () C:\ProgramData\VS
2014-08-27 11:32 - 2014-08-27 11:32 - 00000000 ____D () C:\Users\mimo\aTubeCatcher
2014-08-27 11:31 - 2014-08-27 14:38 - 00000000 ____D () C:\Program Files (x86)\DsNET Corp
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Users\mimo\AppData\Local\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\APN
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-08-27 11:31 - 2014-03-06 01:31 - 00489392 _____ (Ask Partner Network) C:\Users\mimo\Documents\APNSetup1.exe
2014-08-27 11:23 - 2014-08-27 11:23 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Youtube to MP3 Converter
2014-08-25 15:56 - 2014-08-25 15:57 - 11864136 _____ () C:\Users\mimo\Documents\Corkscrew incoming.mp4
2014-08-23 17:10 - 2014-08-23 17:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Adobe
2014-08-23 15:39 - 2014-08-23 19:21 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-23 15:39 - 2014-08-23 15:39 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-08-23 15:39 - 2014-08-23 15:39 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-22 11:21 - 2014-08-22 11:21 - 00000103 _____ () C:\Windows\setupact.log
2014-08-22 11:21 - 2014-08-22 11:21 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-18 14:52 - 2014-08-18 14:52 - 00001613 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\Riot Games
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-08-18 14:47 - 2014-08-28 16:46 - 01304079 _____ () C:\Windows\WindowsUpdate.log
2014-08-18 14:31 - 2014-08-18 14:52 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2014-08-18 14:28 - 2014-08-18 14:52 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Riot Games
2014-08-17 13:32 - 2014-08-28 18:35 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Skype
2014-08-17 13:29 - 2014-08-17 13:29 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-17 13:29 - 2014-08-17 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-17 13:14 - 2014-08-17 13:14 - 00003078 _____ () C:\Windows\System32\Tasks\{5CCE2703-229C-451D-82CE-98713A6CD5C8}
2014-08-17 12:44 - 2014-08-17 12:44 - 00003078 _____ () C:\Windows\System32\Tasks\{68203B66-BD87-4240-B9A9-0D3B1B6D4BE0}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{CCC4FE44-4A2B-4249-BD1D-BFBABCCD90B3}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{5F31E06F-5496-4AB1-9026-935E303C8D74}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{B7A50EC3-BD99-4476-9A5A-2963184A745C}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B1A8366-E670-4E52-B622-B5415B26FCE7}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B0E5559-2EDA-435E-B64C-B2248FEC58C8}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{633D6B9B-4542-4C51-8B3B-3C7849535F47}
2014-08-15 22:36 - 2014-08-15 22:36 - 00000083 ____H () C:\Users\mimo\Downloads\.~lock.WarCraft---knihy.pdf-(CZ).rar#
2014-08-15 22:16 - 2014-08-15 22:16 - 00003078 _____ () C:\Windows\System32\Tasks\{C2BB5981-4EE0-44A6-9759-A5509F99EFEF}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{CFA3AE39-D0CD-45AC-BC91-FEA5A41C2255}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{304AA370-8240-4E74-82A6-6186035A7436}
2014-08-14 10:39 - 2014-08-14 10:41 - 00000000 ____D () C:\Program Files (x86)\GUM1159.tmp
2014-08-12 17:42 - 2014-08-12 17:42 - 00000000 ____D () C:\Users\mimo\Desktop\strýc
2014-08-10 15:14 - 2014-08-10 15:14 - 00000577 _____ () C:\Users\Public\Desktop\MC Titan Feed the Beast.lnk
2014-08-10 14:21 - 2013-03-19 23:08 - 00001082 _____ () C:\Users\mimo\Dokumenty.lnk
2014-08-10 12:13 - 2014-08-10 12:16 - 00000000 ____D () C:\Users\mimo\AppData\Local\ftblauncher
2014-08-10 12:13 - 2014-08-10 12:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\ftblauncher
2014-08-10 11:53 - 2014-08-19 11:54 - 00003818 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1407664388
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Opera Software
2014-08-10 11:43 - 2014-08-24 20:06 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-10 11:43 - 2014-08-10 11:48 - 00000000 ____D () C:\Program Files (x86)\GUM31B8.tmp
2014-08-06 22:03 - 2014-08-06 22:03 - 00000000 ____D () C:\ProgramData\Riot Games
2014-08-03 22:01 - 2014-08-04 01:14 - 1712860676 _____ () C:\Users\mimo\Downloads\Dead-Snow-Rudý-vs.-Mrtvý-[-Dead-Snow-2-]-2014-[BRRip.XviD.AC3]-tit.sk-v-obraze (1).avi
2014-07-30 19:11 - 2014-07-30 21:02 - 00000123 _____ () C:\spyhunter.fix
2014-07-30 09:33 - 2014-07-30 10:07 - 00000000 ____D () C:\Users\mimo\Desktop\Hanebný pancharti
2014-07-30 09:30 - 2014-07-30 09:31 - 00000000 ____D () C:\Users\mimo\Desktop\sniper elite 2 skidrow
2014-07-30 09:15 - 2014-07-30 09:15 - 00001142 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2014-07-30 09:15 - 2014-07-30 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2014-07-30 09:14 - 2014-07-30 09:17 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer
2014-07-30 09:14 - 2014-07-30 09:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer Pro
2014-07-30 07:43 - 2014-07-30 07:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\system32\NV
2014-07-29 22:34 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 18626304 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 16122344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 15294296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-07-29 22:34 - 2014-07-02 22:48 - 11283344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434052.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434052.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00502232 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00418760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00391640 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00348120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00032544 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2014-07-29 21:53 - 2014-08-09 02:22 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-07-29 21:53 - 2014-08-09 02:22 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 18:39 - 2014-08-28 18:38 - 00023021 _____ () C:\Users\mimo\Desktop\FRST.txt
2014-08-28 18:38 - 2014-08-28 18:38 - 00000000 ____D () C:\Users\mimo\Desktop\FRST-OlderVersion
2014-08-28 18:38 - 2014-07-27 20:44 - 00000000 ____D () C:\FRST
2014-08-28 18:38 - 2014-07-27 20:43 - 02103296 _____ (Farbar) C:\Users\mimo\Desktop\FRST64.exe
2014-08-28 18:35 - 2014-08-17 13:32 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Skype
2014-08-28 18:33 - 2014-01-09 20:16 - 00000000 ____D () C:\Users\mimo\AppData\Local\PMB Files
2014-08-28 18:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-08-28 17:57 - 2014-01-21 21:06 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-28 16:46 - 2014-08-18 14:47 - 01304079 _____ () C:\Windows\WindowsUpdate.log
2014-08-28 15:40 - 2013-12-01 22:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express
2014-08-28 15:39 - 2014-08-28 15:39 - 00000000 ____D () C:\ProgramData\VS
2014-08-28 15:33 - 2014-07-27 00:12 - 00002019 _____ () C:\o.xml
2014-08-28 15:33 - 2014-07-27 00:12 - 00001651 _____ () C:\c.xml
2014-08-28 15:33 - 2014-01-09 20:39 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-28 15:33 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-08-28 15:23 - 2013-11-08 20:03 - 00006101 _____ () C:\Users\mimo\AppData\Local\BTServer.log
2014-08-28 14:24 - 2013-09-07 02:30 - 00000000 ____D () C:\ProgramData\Realtek
2014-08-28 14:22 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-28 14:21 - 2014-05-14 23:04 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Seznam.cz
2014-08-28 14:16 - 2013-11-10 22:57 - 00000406 _____ () C:\Windows\Tasks\AWC AutoSweep.job
2014-08-27 22:19 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-08-27 17:45 - 2014-01-09 20:16 - 00000000 ____D () C:\ProgramData\PMB Files
2014-08-27 14:38 - 2014-08-27 11:31 - 00000000 ____D () C:\Program Files (x86)\DsNET Corp
2014-08-27 11:49 - 2013-07-20 11:29 - 00793838 _____ () C:\Windows\system32\perfh005.dat
2014-08-27 11:49 - 2013-07-20 11:29 - 00172944 _____ () C:\Windows\system32\perfc005.dat
2014-08-27 11:49 - 2012-07-26 09:28 - 01901122 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 11:32 - 2014-08-27 11:32 - 00000000 ____D () C:\Users\mimo\aTubeCatcher
2014-08-27 11:32 - 2013-11-08 20:03 - 00000000 ____D () C:\Users\mimo
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Users\mimo\AppData\Local\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\APN
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-08-27 11:23 - 2014-08-27 11:23 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Youtube to MP3 Converter
2014-08-25 15:57 - 2014-08-25 15:56 - 11864136 _____ () C:\Users\mimo\Documents\Corkscrew incoming.mp4
2014-08-24 22:29 - 2013-11-08 20:10 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1051548242-2753322845-1442528999-1002
2014-08-24 20:06 - 2014-08-10 11:43 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-23 19:21 - 2014-08-23 15:39 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-23 19:14 - 2014-07-05 15:01 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-23 17:10 - 2014-08-23 17:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Adobe
2014-08-23 17:10 - 2013-11-08 20:04 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Adobe
2014-08-23 15:39 - 2014-08-23 15:39 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-08-23 15:39 - 2014-08-23 15:39 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-22 11:21 - 2014-08-22 11:21 - 00000103 _____ () C:\Windows\setupact.log
2014-08-22 11:21 - 2014-08-22 11:21 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-22 11:21 - 2013-11-08 20:54 - 00000000 ____D () C:\Users\mimo\AppData\Local\CrashDumps
2014-08-20 01:59 - 2014-03-15 22:02 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\.minecraft
2014-08-20 00:23 - 2013-12-07 10:49 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\SolidWorks
2014-08-19 11:54 - 2014-08-10 11:53 - 00003818 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1407664388
2014-08-19 11:54 - 2014-01-21 19:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-08-18 16:55 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-08-18 14:52 - 2014-08-18 14:52 - 00001613 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\Riot Games
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-08-18 14:52 - 2014-08-18 14:31 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2014-08-18 14:52 - 2014-08-18 14:28 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Riot Games
2014-08-18 14:47 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-18 14:45 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-08-17 13:29 - 2014-08-17 13:29 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-17 13:29 - 2014-08-17 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-17 13:29 - 2013-11-08 20:49 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-17 13:14 - 2014-08-17 13:14 - 00003078 _____ () C:\Windows\System32\Tasks\{5CCE2703-229C-451D-82CE-98713A6CD5C8}
2014-08-17 12:44 - 2014-08-17 12:44 - 00003078 _____ () C:\Windows\System32\Tasks\{68203B66-BD87-4240-B9A9-0D3B1B6D4BE0}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{CCC4FE44-4A2B-4249-BD1D-BFBABCCD90B3}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{5F31E06F-5496-4AB1-9026-935E303C8D74}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{B7A50EC3-BD99-4476-9A5A-2963184A745C}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B1A8366-E670-4E52-B622-B5415B26FCE7}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B0E5559-2EDA-435E-B64C-B2248FEC58C8}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{633D6B9B-4542-4C51-8B3B-3C7849535F47}
2014-08-15 22:36 - 2014-08-15 22:36 - 00000083 ____H () C:\Users\mimo\Downloads\.~lock.WarCraft---knihy.pdf-(CZ).rar#
2014-08-15 22:16 - 2014-08-15 22:16 - 00003078 _____ () C:\Windows\System32\Tasks\{C2BB5981-4EE0-44A6-9759-A5509F99EFEF}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{CFA3AE39-D0CD-45AC-BC91-FEA5A41C2255}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{304AA370-8240-4E74-82A6-6186035A7436}
2014-08-15 09:48 - 2013-11-08 20:49 - 00000000 ____D () C:\ProgramData\Skype
2014-08-14 10:41 - 2014-08-14 10:39 - 00000000 ____D () C:\Program Files (x86)\GUM1159.tmp
2014-08-14 10:38 - 2014-01-21 21:06 - 00003802 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-12 17:42 - 2014-08-12 17:42 - 00000000 ____D () C:\Users\mimo\Desktop\strýc
2014-08-10 15:14 - 2014-08-10 15:14 - 00000577 _____ () C:\Users\Public\Desktop\MC Titan Feed the Beast.lnk
2014-08-10 14:21 - 2013-11-09 00:24 - 00000000 ____D () C:\ProgramData\Stardock
2014-08-10 12:16 - 2014-08-10 12:13 - 00000000 ____D () C:\Users\mimo\AppData\Local\ftblauncher
2014-08-10 12:14 - 2014-08-10 12:13 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\ftblauncher
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Opera Software
2014-08-10 11:53 - 2014-01-21 19:22 - 00000000 ____D () C:\Users\mimo\AppData\Local\Opera Software
2014-08-10 11:48 - 2014-08-10 11:43 - 00000000 ____D () C:\Program Files (x86)\GUM31B8.tmp
2014-08-10 11:43 - 2013-11-08 20:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Deployment
2014-08-10 11:43 - 2013-11-08 20:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Apps\2.0
2014-08-09 02:22 - 2014-07-29 21:53 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-08-09 02:22 - 2014-07-29 21:53 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-08-09 02:22 - 2013-12-03 20:37 - 01283136 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-08-09 02:22 - 2013-12-03 20:37 - 01126480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-08-07 19:37 - 2014-07-26 22:45 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-06 22:03 - 2014-08-06 22:03 - 00000000 ____D () C:\ProgramData\Riot Games
2014-08-04 01:14 - 2014-08-03 22:01 - 1712860676 _____ () C:\Users\mimo\Downloads\Dead-Snow-Rudý-vs.-Mrtvý-[-Dead-Snow-2-]-2014-[BRRip.XviD.AC3]-tit.sk-v-obraze (1).avi
2014-07-31 23:41 - 2014-01-09 20:39 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-30 21:02 - 2014-07-30 19:11 - 00000123 _____ () C:\spyhunter.fix
2014-07-30 21:02 - 2013-11-24 16:17 - 00000000 ____D () C:\Program Files (x86)\BS_Player_ControlBar
2014-07-30 18:20 - 2013-09-07 03:18 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-07-30 18:20 - 2012-07-26 10:12 - 00000000 __RHD () C:\Users\Public\Libraries
2014-07-30 10:07 - 2014-07-30 09:33 - 00000000 ____D () C:\Users\mimo\Desktop\Hanebný pancharti
2014-07-30 09:31 - 2014-07-30 09:30 - 00000000 ____D () C:\Users\mimo\Desktop\sniper elite 2 skidrow
2014-07-30 09:17 - 2014-07-30 09:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer
2014-07-30 09:15 - 2014-07-30 09:15 - 00001142 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2014-07-30 09:15 - 2014-07-30 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2014-07-30 09:14 - 2014-07-30 09:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer Pro
2014-07-30 09:14 - 2013-11-24 16:22 - 00000000 ____D () C:\Program Files (x86)\Webteh
2014-07-30 07:43 - 2014-07-30 07:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-07-30 07:43 - 2013-09-07 02:29 - 00000000 ____D () C:\ProgramData\Bigfoot Networks
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\system32\NV
2014-07-29 22:37 - 2013-09-07 02:26 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-29 22:36 - 2013-09-07 02:25 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-29 22:32 - 2013-12-03 20:38 - 00000000 ____D () C:\Users\mimo\AppData\Local\NVIDIA Corporation
2014-07-29 20:26 - 2013-11-09 00:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2014-07-29 20:26 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-29 15:42 - 2013-11-08 20:06 - 00000000 ___SD () C:\Users\mimo\Desktop\Crypto
Some content of TEMP:
====================
C:\Users\mimo\AppData\Local\Temp\swt-win32-3349.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-25 11:26
==================== End Of Log ============================
ZDE FRST LOG :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by mimo (administrator) on MSI on 28-08-2014 18:38:43
Running from C:\Users\mimo\Desktop
Platform: Windows 8 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Enigma Software Group USA, LLC.) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
() C:\Users\mimo\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\mimo\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Allstar Group, s.r.o.) C:\Program Files\GamePark2\gpcl.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
() C:\Program Files (x86)\Opera\23.0.1522.77\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-09-06] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2889072 2013-09-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-08-22] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [408232 2013-08-22] (MSI)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403288 2014-08-09] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5634800 2012-06-14] (ESET)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-07] (MSI)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-09] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [181208 2013-04-02] (cyberlink)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1974168 2014-08-14] (APN)
HKLM Group Policy restriction on software: C:\Program Files (x86)\Kaspersky Lab <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\AVG <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Common Files\Symantec Shared <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\AVG <====== ATTENTION
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\.DEFAULT\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\.DEFAULT\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [Advanced SystemCare 3] => C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe [2342608 2010-02-01] (IObit)
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [4287536 2014-01-09] ()
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21653096 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\mimo\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\mimo\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1051548242-2753322845-1442528999-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GamePark klient 2.lnk
ShortcutTarget: GamePark klient 2.lnk -> C:\Program Files\GamePark2\gpcl.exe (Allstar Group, s.r.o.)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {81011E39-A0F7-41EF-96CF-4802A9780789} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {81011E39-A0F7-41EF-96CF-4802A9780789} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {88F7F8C6-6326-4F41-B98B-503043F5E2CD} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {94D3294C-F6D5-4863-ACD0-4536F0459CD6} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {99E01646-4330-4DB3-9F04-9E7CD077F42E} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A734D46C-0FD7-4783-A21D-7EE9F70ED811} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {AE3DE580-CBEC-4FA5-A108-A4CC0D3820B3} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
SearchScopes: HKCU - {CABC489B-4019-487A-9102-91BF4D2C127F} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {D260BBB6-5678-4B02-8836-3D35B7C71B2D} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {EDCF6918-A47D-482B-854A-5DFDC1EFF90F} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
BHO: Ask Toolbar -> {41545534-2D56-3700-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport_x64.dll (APN LLC.)
BHO-x32: Ask Toolbar -> {41545534-2D56-3700-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport.dll (APN LLC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Ask Toolbar - {41545534-2D56-3700-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Ask Toolbar - {41545534-2D56-3700-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ATU4-V7\Passport.dll (APN LLC.)
Winsock: Catalog9 01 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 02 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 03 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 04 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9 16 C:\Windows\SysWOW64\BfLLR.dll [196096] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 16 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-07-26]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-08-14] (APN LLC.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [File not signed]
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [247768 2013-04-03] (CyberLink)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1288104 2012-06-14] (ESET)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [98672 2013-09-06] (ELAN Microelectronics Corp.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-08-22] (Micro-Star International Co., Ltd.) [File not signed]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [154112 2013-02-08] (MSI) [File not signed]
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720792 2014-08-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18973144 2014-08-09] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-11-09] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [214520 2014-07-07] ()
S2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [503296 2013-05-17] () [File not signed]
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-12-07] (SolidWorks) [File not signed]
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [327064 2010-05-18] (Enigma Software Group USA, LLC.)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
R2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [143288 2014-04-04] (Stardock Software, Inc)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-09-07] (Microsoft Corporation)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2013-05-17] (Qualcomm Atheros, Inc.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-06-23] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [211344 2012-06-14] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [149592 2012-06-14] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [138232 2012-06-14] (ESET)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2013-11-29] (LogMeIn Inc.)
R3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [19952 2013-02-01] (Windows (R) Win 7 DDK provider)
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [174448 2013-05-17] (Qualcomm Atheros, Inc.)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20440 2014-08-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [532552 2013-09-06] (Realtek Semiconductor Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [407112 2013-09-06] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1549384 2013-09-06] (Realtek Semiconductor Corporation )
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 18:38 - 2014-08-28 18:38 - 00000000 ____D () C:\Users\mimo\Desktop\FRST-OlderVersion
2014-08-28 18:38 - 2014-08-28 18:38 - 00000000 _____ () C:\Users\mimo\Desktop\FRST.txt
2014-08-28 15:39 - 2014-08-28 15:39 - 00000000 ____D () C:\ProgramData\VS
2014-08-27 11:32 - 2014-08-27 11:32 - 00000000 ____D () C:\Users\mimo\aTubeCatcher
2014-08-27 11:31 - 2014-08-27 14:38 - 00000000 ____D () C:\Program Files (x86)\DsNET Corp
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Users\mimo\AppData\Local\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\APN
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-08-27 11:31 - 2014-03-06 01:31 - 00489392 _____ (Ask Partner Network) C:\Users\mimo\Documents\APNSetup1.exe
2014-08-27 11:23 - 2014-08-27 11:23 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Youtube to MP3 Converter
2014-08-25 15:56 - 2014-08-25 15:57 - 11864136 _____ () C:\Users\mimo\Documents\Corkscrew incoming.mp4
2014-08-23 17:10 - 2014-08-23 17:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Adobe
2014-08-23 15:39 - 2014-08-23 19:21 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-23 15:39 - 2014-08-23 15:39 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-08-23 15:39 - 2014-08-23 15:39 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-22 11:21 - 2014-08-22 11:21 - 00000103 _____ () C:\Windows\setupact.log
2014-08-22 11:21 - 2014-08-22 11:21 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-18 14:52 - 2014-08-18 14:52 - 00001613 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\Riot Games
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-08-18 14:47 - 2014-08-28 16:46 - 01304079 _____ () C:\Windows\WindowsUpdate.log
2014-08-18 14:31 - 2014-08-18 14:52 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2014-08-18 14:28 - 2014-08-18 14:52 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Riot Games
2014-08-17 13:32 - 2014-08-28 18:35 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Skype
2014-08-17 13:29 - 2014-08-17 13:29 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-17 13:29 - 2014-08-17 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-17 13:14 - 2014-08-17 13:14 - 00003078 _____ () C:\Windows\System32\Tasks\{5CCE2703-229C-451D-82CE-98713A6CD5C8}
2014-08-17 12:44 - 2014-08-17 12:44 - 00003078 _____ () C:\Windows\System32\Tasks\{68203B66-BD87-4240-B9A9-0D3B1B6D4BE0}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{CCC4FE44-4A2B-4249-BD1D-BFBABCCD90B3}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{5F31E06F-5496-4AB1-9026-935E303C8D74}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{B7A50EC3-BD99-4476-9A5A-2963184A745C}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B1A8366-E670-4E52-B622-B5415B26FCE7}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B0E5559-2EDA-435E-B64C-B2248FEC58C8}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{633D6B9B-4542-4C51-8B3B-3C7849535F47}
2014-08-15 22:36 - 2014-08-15 22:36 - 00000083 ____H () C:\Users\mimo\Downloads\.~lock.WarCraft---knihy.pdf-(CZ).rar#
2014-08-15 22:16 - 2014-08-15 22:16 - 00003078 _____ () C:\Windows\System32\Tasks\{C2BB5981-4EE0-44A6-9759-A5509F99EFEF}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{CFA3AE39-D0CD-45AC-BC91-FEA5A41C2255}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{304AA370-8240-4E74-82A6-6186035A7436}
2014-08-14 10:39 - 2014-08-14 10:41 - 00000000 ____D () C:\Program Files (x86)\GUM1159.tmp
2014-08-12 17:42 - 2014-08-12 17:42 - 00000000 ____D () C:\Users\mimo\Desktop\strýc
2014-08-10 15:14 - 2014-08-10 15:14 - 00000577 _____ () C:\Users\Public\Desktop\MC Titan Feed the Beast.lnk
2014-08-10 14:21 - 2013-03-19 23:08 - 00001082 _____ () C:\Users\mimo\Dokumenty.lnk
2014-08-10 12:13 - 2014-08-10 12:16 - 00000000 ____D () C:\Users\mimo\AppData\Local\ftblauncher
2014-08-10 12:13 - 2014-08-10 12:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\ftblauncher
2014-08-10 11:53 - 2014-08-19 11:54 - 00003818 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1407664388
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Opera Software
2014-08-10 11:43 - 2014-08-24 20:06 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-10 11:43 - 2014-08-10 11:48 - 00000000 ____D () C:\Program Files (x86)\GUM31B8.tmp
2014-08-06 22:03 - 2014-08-06 22:03 - 00000000 ____D () C:\ProgramData\Riot Games
2014-08-03 22:01 - 2014-08-04 01:14 - 1712860676 _____ () C:\Users\mimo\Downloads\Dead-Snow-Rudý-vs.-Mrtvý-[-Dead-Snow-2-]-2014-[BRRip.XviD.AC3]-tit.sk-v-obraze (1).avi
2014-07-30 19:11 - 2014-07-30 21:02 - 00000123 _____ () C:\spyhunter.fix
2014-07-30 09:33 - 2014-07-30 10:07 - 00000000 ____D () C:\Users\mimo\Desktop\Hanebný pancharti
2014-07-30 09:30 - 2014-07-30 09:31 - 00000000 ____D () C:\Users\mimo\Desktop\sniper elite 2 skidrow
2014-07-30 09:15 - 2014-07-30 09:15 - 00001142 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2014-07-30 09:15 - 2014-07-30 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2014-07-30 09:14 - 2014-07-30 09:17 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer
2014-07-30 09:14 - 2014-07-30 09:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer Pro
2014-07-30 07:43 - 2014-07-30 07:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\system32\NV
2014-07-29 22:34 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 18626304 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 16122344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 15294296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-07-29 22:34 - 2014-07-02 22:48 - 11283344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434052.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434052.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00502232 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00418760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00391640 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00348120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-07-29 22:34 - 2014-07-02 22:48 - 00032544 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2014-07-29 21:53 - 2014-08-09 02:22 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-07-29 21:53 - 2014-08-09 02:22 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 18:39 - 2014-08-28 18:38 - 00023021 _____ () C:\Users\mimo\Desktop\FRST.txt
2014-08-28 18:38 - 2014-08-28 18:38 - 00000000 ____D () C:\Users\mimo\Desktop\FRST-OlderVersion
2014-08-28 18:38 - 2014-07-27 20:44 - 00000000 ____D () C:\FRST
2014-08-28 18:38 - 2014-07-27 20:43 - 02103296 _____ (Farbar) C:\Users\mimo\Desktop\FRST64.exe
2014-08-28 18:35 - 2014-08-17 13:32 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Skype
2014-08-28 18:33 - 2014-01-09 20:16 - 00000000 ____D () C:\Users\mimo\AppData\Local\PMB Files
2014-08-28 18:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-08-28 17:57 - 2014-01-21 21:06 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-28 16:46 - 2014-08-18 14:47 - 01304079 _____ () C:\Windows\WindowsUpdate.log
2014-08-28 15:40 - 2013-12-01 22:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express
2014-08-28 15:39 - 2014-08-28 15:39 - 00000000 ____D () C:\ProgramData\VS
2014-08-28 15:33 - 2014-07-27 00:12 - 00002019 _____ () C:\o.xml
2014-08-28 15:33 - 2014-07-27 00:12 - 00001651 _____ () C:\c.xml
2014-08-28 15:33 - 2014-01-09 20:39 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-28 15:33 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-08-28 15:23 - 2013-11-08 20:03 - 00006101 _____ () C:\Users\mimo\AppData\Local\BTServer.log
2014-08-28 14:24 - 2013-09-07 02:30 - 00000000 ____D () C:\ProgramData\Realtek
2014-08-28 14:22 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-28 14:21 - 2014-05-14 23:04 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Seznam.cz
2014-08-28 14:16 - 2013-11-10 22:57 - 00000406 _____ () C:\Windows\Tasks\AWC AutoSweep.job
2014-08-27 22:19 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-08-27 17:45 - 2014-01-09 20:16 - 00000000 ____D () C:\ProgramData\PMB Files
2014-08-27 14:38 - 2014-08-27 11:31 - 00000000 ____D () C:\Program Files (x86)\DsNET Corp
2014-08-27 11:49 - 2013-07-20 11:29 - 00793838 _____ () C:\Windows\system32\perfh005.dat
2014-08-27 11:49 - 2013-07-20 11:29 - 00172944 _____ () C:\Windows\system32\perfc005.dat
2014-08-27 11:49 - 2012-07-26 09:28 - 01901122 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 11:32 - 2014-08-27 11:32 - 00000000 ____D () C:\Users\mimo\aTubeCatcher
2014-08-27 11:32 - 2013-11-08 20:03 - 00000000 ____D () C:\Users\mimo
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Users\mimo\AppData\Local\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\ProgramData\APN
2014-08-27 11:31 - 2014-08-27 11:31 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-08-27 11:23 - 2014-08-27 11:23 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Youtube to MP3 Converter
2014-08-25 15:57 - 2014-08-25 15:56 - 11864136 _____ () C:\Users\mimo\Documents\Corkscrew incoming.mp4
2014-08-24 22:29 - 2013-11-08 20:10 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1051548242-2753322845-1442528999-1002
2014-08-24 20:06 - 2014-08-10 11:43 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-23 19:21 - 2014-08-23 15:39 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-23 19:14 - 2014-07-05 15:01 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-23 17:10 - 2014-08-23 17:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Adobe
2014-08-23 17:10 - 2013-11-08 20:04 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Adobe
2014-08-23 15:39 - 2014-08-23 15:39 - 00002029 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-08-23 15:39 - 2014-08-23 15:39 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-22 11:21 - 2014-08-22 11:21 - 00000103 _____ () C:\Windows\setupact.log
2014-08-22 11:21 - 2014-08-22 11:21 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-22 11:21 - 2013-11-08 20:54 - 00000000 ____D () C:\Users\mimo\AppData\Local\CrashDumps
2014-08-20 01:59 - 2014-03-15 22:02 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\.minecraft
2014-08-20 00:23 - 2013-12-07 10:49 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\SolidWorks
2014-08-19 11:54 - 2014-08-10 11:53 - 00003818 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1407664388
2014-08-19 11:54 - 2014-01-21 19:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-08-18 16:55 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-08-18 14:52 - 2014-08-18 14:52 - 00001613 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\Riot Games
2014-08-18 14:52 - 2014-08-18 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-08-18 14:52 - 2014-08-18 14:31 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2014-08-18 14:52 - 2014-08-18 14:28 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Riot Games
2014-08-18 14:47 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-18 14:45 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-08-17 13:29 - 2014-08-17 13:29 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-17 13:29 - 2014-08-17 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-17 13:29 - 2013-11-08 20:49 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-17 13:14 - 2014-08-17 13:14 - 00003078 _____ () C:\Windows\System32\Tasks\{5CCE2703-229C-451D-82CE-98713A6CD5C8}
2014-08-17 12:44 - 2014-08-17 12:44 - 00003078 _____ () C:\Windows\System32\Tasks\{68203B66-BD87-4240-B9A9-0D3B1B6D4BE0}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{CCC4FE44-4A2B-4249-BD1D-BFBABCCD90B3}
2014-08-17 12:43 - 2014-08-17 12:43 - 00003072 _____ () C:\Windows\System32\Tasks\{5F31E06F-5496-4AB1-9026-935E303C8D74}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{B7A50EC3-BD99-4476-9A5A-2963184A745C}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B1A8366-E670-4E52-B622-B5415B26FCE7}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{7B0E5559-2EDA-435E-B64C-B2248FEC58C8}
2014-08-17 12:42 - 2014-08-17 12:42 - 00003072 _____ () C:\Windows\System32\Tasks\{633D6B9B-4542-4C51-8B3B-3C7849535F47}
2014-08-15 22:36 - 2014-08-15 22:36 - 00000083 ____H () C:\Users\mimo\Downloads\.~lock.WarCraft---knihy.pdf-(CZ).rar#
2014-08-15 22:16 - 2014-08-15 22:16 - 00003078 _____ () C:\Windows\System32\Tasks\{C2BB5981-4EE0-44A6-9759-A5509F99EFEF}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{CFA3AE39-D0CD-45AC-BC91-FEA5A41C2255}
2014-08-15 15:43 - 2014-08-15 15:43 - 00003078 _____ () C:\Windows\System32\Tasks\{304AA370-8240-4E74-82A6-6186035A7436}
2014-08-15 09:48 - 2013-11-08 20:49 - 00000000 ____D () C:\ProgramData\Skype
2014-08-14 10:41 - 2014-08-14 10:39 - 00000000 ____D () C:\Program Files (x86)\GUM1159.tmp
2014-08-14 10:38 - 2014-01-21 21:06 - 00003802 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-12 17:42 - 2014-08-12 17:42 - 00000000 ____D () C:\Users\mimo\Desktop\strýc
2014-08-10 15:14 - 2014-08-10 15:14 - 00000577 _____ () C:\Users\Public\Desktop\MC Titan Feed the Beast.lnk
2014-08-10 14:21 - 2013-11-09 00:24 - 00000000 ____D () C:\ProgramData\Stardock
2014-08-10 12:16 - 2014-08-10 12:13 - 00000000 ____D () C:\Users\mimo\AppData\Local\ftblauncher
2014-08-10 12:14 - 2014-08-10 12:13 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\ftblauncher
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00001149 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-08-10 11:53 - 2014-08-10 11:53 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\Opera Software
2014-08-10 11:53 - 2014-01-21 19:22 - 00000000 ____D () C:\Users\mimo\AppData\Local\Opera Software
2014-08-10 11:48 - 2014-08-10 11:43 - 00000000 ____D () C:\Program Files (x86)\GUM31B8.tmp
2014-08-10 11:43 - 2013-11-08 20:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Deployment
2014-08-10 11:43 - 2013-11-08 20:10 - 00000000 ____D () C:\Users\mimo\AppData\Local\Apps\2.0
2014-08-09 02:22 - 2014-07-29 21:53 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-08-09 02:22 - 2014-07-29 21:53 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-08-09 02:22 - 2013-12-03 20:37 - 01283136 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-08-09 02:22 - 2013-12-03 20:37 - 01126480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-08-07 19:37 - 2014-07-26 22:45 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-06 22:03 - 2014-08-06 22:03 - 00000000 ____D () C:\ProgramData\Riot Games
2014-08-04 01:14 - 2014-08-03 22:01 - 1712860676 _____ () C:\Users\mimo\Downloads\Dead-Snow-Rudý-vs.-Mrtvý-[-Dead-Snow-2-]-2014-[BRRip.XviD.AC3]-tit.sk-v-obraze (1).avi
2014-07-31 23:41 - 2014-01-09 20:39 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-30 21:02 - 2014-07-30 19:11 - 00000123 _____ () C:\spyhunter.fix
2014-07-30 21:02 - 2013-11-24 16:17 - 00000000 ____D () C:\Program Files (x86)\BS_Player_ControlBar
2014-07-30 18:20 - 2013-09-07 03:18 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-07-30 18:20 - 2012-07-26 10:12 - 00000000 __RHD () C:\Users\Public\Libraries
2014-07-30 10:07 - 2014-07-30 09:33 - 00000000 ____D () C:\Users\mimo\Desktop\Hanebný pancharti
2014-07-30 09:31 - 2014-07-30 09:30 - 00000000 ____D () C:\Users\mimo\Desktop\sniper elite 2 skidrow
2014-07-30 09:17 - 2014-07-30 09:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer
2014-07-30 09:15 - 2014-07-30 09:15 - 00001142 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2014-07-30 09:15 - 2014-07-30 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2014-07-30 09:14 - 2014-07-30 09:14 - 00000000 ____D () C:\Users\mimo\AppData\Roaming\BSplayer Pro
2014-07-30 09:14 - 2013-11-24 16:22 - 00000000 ____D () C:\Program Files (x86)\Webteh
2014-07-30 07:43 - 2014-07-30 07:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\48230029.sys
2014-07-30 07:43 - 2013-09-07 02:29 - 00000000 ____D () C:\ProgramData\Bigfoot Networks
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-07-29 22:37 - 2014-07-29 22:37 - 00000000 ____D () C:\Windows\system32\NV
2014-07-29 22:37 - 2013-09-07 02:26 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-29 22:36 - 2013-09-07 02:25 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-29 22:32 - 2013-12-03 20:38 - 00000000 ____D () C:\Users\mimo\AppData\Local\NVIDIA Corporation
2014-07-29 20:26 - 2013-11-09 00:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2014-07-29 20:26 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-29 15:42 - 2013-11-08 20:06 - 00000000 ___SD () C:\Users\mimo\Desktop\Crypto
Some content of TEMP:
====================
C:\Users\mimo\AppData\Local\Temp\swt-win32-3349.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-25 11:26
==================== End Of Log ============================