Všeobecná kontrola pre istotu...
Napsal: 06 čer 2015 17:19
Dobrý deň, rád by som pre istotu chcel dať skontrolovať bratov PC... ďakujem
prikladám FRST log.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-06-2015
Ran by Stefan (administrator) on STEFAN-PC on 06-06-2015 18:11:04
Running from C:\Users\Stefan\Desktop
Loaded Profiles: Stefan (Available Profiles: Stefan)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Angličtina (USA)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(XTab system) C:\Program Files (x86)\XTab\ProtectService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(© 2015 Microsoft Corporation) C:\Users\Stefan\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [6346464 2013-01-05] (Realtek semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-14] (Avast Software s.r.o.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [429792 2013-02-08] (AppEx Networks Corporation)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31280256 2015-04-17] (Skype Technologies S.A.)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [BingSvc] => C:\Users\Stefan\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-08] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\MountPoints2: {30e0ac73-077e-11e5-9c0a-342387ee0594} - F:\LaunchU3.exe -a
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\MountPoints2: {9f3ed4cc-e81d-11e4-96f1-342387ee0594} - E:\autorun.exe
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-04-14]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-14] (Avast Software s.r.o.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dsp ... earchTerms}
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dsp ... earchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-02] (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-14] (Avast Software s.r.o.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-02] (Microsoft Corporation)
BHO-x32: LuckyTab Class -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> C:\Program Files (x86)\XTab\SupTab.dll [2015-05-29] (Thinknice Co. Limited)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-14] (Avast Software s.r.o.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-02] (Microsoft Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2011-01-20] ()
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2011-01-20] ()
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9HF103545
FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-02] (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-14]
Chrome:
=======
CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast SafePrice) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-04-20]
CHR Extension: (MSN Homepage & Bing Search Engine) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-04-17]
CHR Extension: (Bookmark Manager) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-22]
CHR Extension: (Avast Online Security) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-04-14]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-14]
CHR Extension: (Google Wallet) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-14]
CHR HKU\S-1-5-21-4059302633-955075911-2127840080-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-14]
Opera:
=======
OPR Extension: (Swift Record) - C:\Users\Stefan\AppData\Roaming\Opera Software\Opera Stable\Extensions\hhfjaflcchgcmfnonahdjlcjgajlognd [2015-05-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-14] (Avast Software s.r.o.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [1008344 2013-02-19] (Broadcom Corporation.)
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [157824 2015-05-29] (XTab system)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-03-30] (LogMeIn, Inc.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 Update Swift Record; "C:\Program Files (x86)\Swift Record\updateSwiftRecord.exe" [X]
S2 Util Swift Record; "C:\Program Files (x86)\Swift Record\bin\utilSwiftRecord.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.)
R2 APXACC; C:\Windows\System32\DRIVERS\appexDrv.sys [217824 2013-03-21] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-04-14] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-14] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-14] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-14] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-04-14] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [271200 2015-04-14] ()
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2012-09-25] (Broadcom Corporation.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2015-04-21] (DT Soft Ltd)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [117912 2012-11-20] (Qualcomm Atheros Co., Ltd.)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8239456 2013-01-05] (Realtek Semiconductor Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2015-04-21] () [File not signed]
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software)
R1 {602b1e7a-d085-42c0-aa31-42f2f8e76963}Gw64; C:\Windows\System32\drivers\{602b1e7a-d085-42c0-aa31-42f2f8e76963}Gw64.sys [48784 2015-05-17] (StdLib)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-06 18:11 - 2015-06-06 18:11 - 00020730 _____ C:\Users\Stefan\Desktop\FRST.txt
2015-06-06 18:10 - 2015-06-06 18:11 - 00000000 ____D C:\FRST
2015-06-06 18:10 - 2015-06-06 18:10 - 02108928 _____ (Farbar) C:\Users\Stefan\Desktop\FRST64.exe
2015-05-29 23:24 - 2015-05-29 23:24 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Quake3
2015-05-29 17:47 - 2015-05-29 17:47 - 00000000 ____H C:\Users\Stefan\Documents\Default.rdp
2015-05-27 20:04 - 2006-10-19 10:28 - 00348092 _____ C:\Users\Public\aim_map.bsp
2015-05-24 13:19 - 2015-05-24 13:19 - 00001080 _____ C:\Users\Stefan\Desktop\Videá - odkaz.lnk
2015-05-22 21:10 - 2015-05-22 21:11 - 00000000 ____D C:\Program Files (x86)\Cossacks
2015-05-20 00:18 - 2015-06-03 16:04 - 00000000 ____D C:\Users\Public\CS
2015-05-17 22:24 - 2015-05-17 22:24 - 00000000 ____D C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07
2015-05-17 22:06 - 2015-05-17 22:23 - 166813300 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part4.rar
2015-05-17 21:50 - 2015-05-17 22:03 - 209715200 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part3.rar
2015-05-17 21:32 - 2015-05-17 21:49 - 209715200 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part2.rar
2015-05-17 21:16 - 2015-05-17 21:32 - 209715200 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part1.rar
2015-05-17 21:04 - 2015-05-17 21:04 - 00000000 ____D C:\Users\Stefan\Downloads\age-of-mythology-crack
2015-05-17 21:03 - 2015-05-17 21:03 - 02159835 _____ C:\Users\Stefan\Downloads\age-of-mythology-crack.rar
2015-05-17 20:52 - 2015-05-17 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-05-17 20:49 - 2015-05-17 20:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-05-17 19:51 - 2015-05-17 20:37 - 531499008 _____ C:\Users\Stefan\Downloads\Age-of-Mythology-Gold---CD-2.iso
2015-05-17 18:36 - 2015-05-17 19:09 - 502269952 _____ C:\Users\Stefan\Downloads\Age-of-Mythology-Gold---CD-1.iso
2015-05-17 18:34 - 2015-05-17 18:35 - 01223680 _____ C:\Users\Stefan\Downloads\Age of Mythology Gold .exe
2015-05-17 18:30 - 2015-05-17 18:30 - 00000464 __RSH C:\ProgramData\ntuser.pol
2015-05-17 15:30 - 2015-05-17 15:31 - 00276576 _____ C:\Windows\Minidump\051715-26208-01.dmp
2015-05-17 15:28 - 2015-05-17 01:51 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{602b1e7a-d085-42c0-aa31-42f2f8e76963}Gw64.sys
2015-05-17 15:26 - 2015-06-02 23:32 - 00000000 ____D C:\Program Files (x86)\XTab
2015-05-17 15:26 - 2015-05-17 18:29 - 00000000 ____D C:\Program Files (x86)\Swift Record
2015-05-17 15:26 - 2015-05-17 15:26 - 00000000 ____D C:\ProgramData\IHProtectUpDate
2015-05-17 15:25 - 2015-06-06 12:44 - 00000000 ____D C:\ProgramData\WindowsMangerProtect
2015-05-17 15:25 - 2015-05-17 15:25 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\istartsurf
2015-05-17 15:25 - 2015-05-17 15:25 - 00000000 ____D C:\CAIMAN
2015-05-17 15:24 - 2015-05-17 15:24 - 00413360 _____ C:\Users\Stefan\Downloads\1001-SundayDrivers_downloader-Qe16xHNJA.exe
2015-05-17 14:34 - 2015-05-17 14:34 - 00021434 _____ C:\Users\Stefan\Downloads\Prince.of.Persia.The.Sands.of.Time - SKIDROW.torrent
2015-05-17 14:20 - 2015-05-17 14:20 - 00034474 _____ C:\Users\Stefan\Downloads\[isoHunt]-commandos-2-men-of-courage.torrent
2015-05-17 14:01 - 2015-05-17 14:01 - 00012421 _____ C:\Users\Stefan\Downloads\stronghold.crusader-2.torrent
2015-05-17 13:59 - 2015-05-17 13:59 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cossacks
2015-05-17 13:59 - 2015-05-17 13:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cossacks
2015-05-17 13:58 - 2015-05-17 13:58 - 00053248 _____ C:\Windows\SysWOW64\unrar.dll
2015-05-17 13:58 - 2014-12-15 23:33 - 04358144 _____ (GSC Game World) C:\Windows\uncsetup.exe
2015-05-17 13:57 - 2015-05-17 13:57 - 00000000 ____D C:\Users\Stefan\Downloads\Cossacks---European-Wars-1.15-M@
2015-05-16 20:24 - 2015-05-16 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
2015-05-16 20:23 - 2015-05-16 20:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
2015-05-16 20:23 - 2015-05-16 20:23 - 00000000 ____D C:\Program Files (x86)\Activision
2015-05-16 19:43 - 2015-05-16 20:17 - 564000768 _____ C:\Users\Stefan\Downloads\spiderman-2.iso
2015-05-16 00:09 - 2015-05-16 00:09 - 00000000 ____D C:\Users\Stefan\Downloads\viliam_klimacek_rozkvitli_sekery
2015-05-15 22:17 - 2015-05-15 22:17 - 17869704 _____ C:\Users\Stefan\Downloads\viliam_klimacek_rozkvitli_sekery.rar
2015-05-12 22:35 - 2015-05-12 13:56 - 00091712 _____ C:\Users\Public\Downloads\gg_dagger.nav
2015-05-12 22:35 - 2015-05-10 23:35 - 00490032 _____ C:\Users\Public\Downloads\gg_dagger.bsp
2015-05-12 22:26 - 2015-05-31 10:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zariadenia Bluetooth
2015-05-10 17:10 - 2015-05-10 17:10 - 00012995 _____ C:\Users\Stefan\Downloads\Hip_Hop_Ejay_6_Full_2_CDs_iso[www.btmon.com].torrent
2015-05-10 17:03 - 2015-05-27 19:18 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Audacity
2015-05-10 17:02 - 2015-05-10 17:02 - 00001019 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-05-10 17:02 - 2015-05-10 17:02 - 00001007 _____ C:\Users\Public\Desktop\Audacity.lnk
2015-05-10 17:02 - 2015-05-10 17:02 - 00000000 ____D C:\Program Files (x86)\Audacity
2015-05-10 16:58 - 2015-05-10 17:00 - 24210616 _____ (Audacity Team ) C:\Users\Stefan\Downloads\audacity.exe
2015-05-09 20:48 - 2015-05-09 20:48 - 00000889 _____ C:\Users\Stefan\Desktop\utorrent - odkaz.lnk
2015-05-09 20:47 - 2015-05-09 20:47 - 00012261 _____ C:\Users\Stefan\Downloads\Battlefield.1942 - SKIDROW.torrent
2015-05-09 09:56 - 2015-05-09 09:57 - 00893882 _____ C:\Users\Stefan\Downloads\Mafia-Crack---No-CD.rar
2015-05-09 09:50 - 2015-05-09 09:50 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mafia
2015-05-09 09:50 - 2015-05-09 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia
2015-05-09 09:50 - 2015-05-09 09:50 - 00000000 ____D C:\Program Files (x86)\Creative
2015-05-09 09:50 - 2002-06-06 14:38 - 00139264 _____ (Creative Technology Ltd) C:\Windows\SysWOW64\eax.dll
2015-05-09 09:50 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2015-05-09 09:45 - 2015-05-09 09:50 - 00000000 ____D C:\Program Files\Mafia
2015-05-07 22:41 - 2015-05-17 14:35 - 00000000 ____D C:\Torrents
2015-05-07 22:39 - 2015-05-24 00:50 - 00000000 ____D C:\uTorrent
2015-05-07 22:38 - 2015-05-07 22:38 - 00763656 _____ (emc) C:\Users\Stefan\Downloads\uTorrentServer221.exe
2015-05-07 22:26 - 2015-05-07 22:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-05-07 22:26 - 2015-05-07 22:26 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2015-05-07 22:26 - 2015-03-30 15:25 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2015-05-07 22:24 - 2015-06-06 18:04 - 00000000 ____D C:\Users\Stefan\AppData\Local\LogMeIn Hamachi
2015-05-07 22:24 - 2015-05-07 22:24 - 00000000 ____D C:\Users\Stefan\AppData\Local\LogMeIn
2015-05-07 22:24 - 2015-05-07 22:24 - 00000000 ____D C:\ProgramData\LogMeIn
2015-05-07 22:19 - 2015-05-07 22:22 - 08544256 _____ C:\Users\Stefan\Downloads\hamachi.msi
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-06 18:06 - 2015-04-14 19:14 - 00307711 _____ C:\Windows\WindowsUpdate.log
2015-06-06 18:04 - 2015-04-17 07:13 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Skype
2015-06-06 18:03 - 2015-04-14 20:18 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-06 18:02 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-06 18:02 - 2009-07-14 06:51 - 00053160 _____ C:\Windows\setupact.log
2015-06-06 17:41 - 2015-04-14 23:15 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2015-06-06 17:32 - 2015-04-14 20:18 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-06 12:51 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-06 12:51 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-06 12:48 - 2009-07-14 07:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-05 01:42 - 2015-04-26 12:01 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\vlc
2015-06-04 23:39 - 2015-04-26 12:06 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-04 23:35 - 2015-04-14 20:21 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-06-04 22:38 - 2015-04-25 18:41 - 00000000 ____D C:\Program Files (x86)\Call of Duty
2015-05-30 20:18 - 2015-04-25 15:55 - 00000000 ____D C:\Users\Stefan\Desktop\GAMES
2015-05-30 10:03 - 2015-04-19 12:26 - 00000000 ____D C:\Users\Stefan\Desktop\Hudba
2015-05-24 10:22 - 2015-04-26 12:28 - 00003844 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1430044135
2015-05-24 10:16 - 2010-11-21 05:47 - 00016902 _____ C:\Windows\PFRO.log
2015-05-24 10:16 - 2009-07-14 06:45 - 00433672 _____ C:\Windows\system32\FNTCACHE.DAT
2015-05-21 13:55 - 2015-04-14 20:03 - 00000000 ____D C:\Users\Stefan\Documents\Prieèinok na výmenu cez Bluetooth
2015-05-18 17:44 - 2015-04-14 20:17 - 00111920 _____ C:\Users\Stefan\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-17 20:55 - 2015-04-17 06:32 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-05-17 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-05-17 15:32 - 2009-07-14 04:34 - 00000580 _____ C:\Windows\win.ini
2015-05-17 15:30 - 2015-04-26 08:59 - 00000000 ____D C:\Windows\Minidump
2015-05-17 15:30 - 2015-04-26 08:58 - 453171428 _____ C:\Windows\MEMORY.DMP
2015-05-17 15:25 - 2015-04-26 12:28 - 00001413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-05-17 15:25 - 2015-04-14 19:12 - 00001715 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-17 14:13 - 2015-04-17 07:13 - 00000000 ____D C:\ProgramData\Skype
2015-05-16 20:24 - 2015-04-14 19:57 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-05-16 03:26 - 2015-04-14 20:18 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 03:26 - 2015-04-14 20:18 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-09 09:51 - 2015-04-14 19:11 - 00000000 ____D C:\Users\Stefan\AppData\Local\VirtualStore
2015-05-07 16:30 - 2015-04-14 19:11 - 00000000 ____D C:\Users\Stefan
2015-05-07 16:28 - 2015-04-14 20:44 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-05-07 16:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2015-05-07 16:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
==================== Files in the root of some directories =======
2002-08-29 17:33 - 2002-08-29 17:33 - 0319488 ____R () C:\Users\Stefan\AppData\Roaming\MafiaSetup.exe
Files to move or delete:
====================
C:\Users\Public\Alcohol120_trial_2.0.0.1331.exe
C:\Users\Public\DTLite4402-0131.exe
C:\Users\Public\DTLite501-0406.exe
Some files in TEMP:
====================
C:\Users\Stefan\AppData\Local\Temp\1001-SundayDrivers.exe
C:\Users\Stefan\AppData\Local\Temp\appshat_generic.exe
C:\Users\Stefan\AppData\Local\Temp\AxToolbarSetup.exe
C:\Users\Stefan\AppData\Local\Temp\BSvcProcessor.exe
C:\Users\Stefan\AppData\Local\Temp\BSvcUpdater.exe
C:\Users\Stefan\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Stefan\AppData\Local\Temp\EBU2CF.exe
C:\Users\Stefan\AppData\Local\Temp\EBU7AF.DLL
C:\Users\Stefan\AppData\Local\Temp\File.exe
C:\Users\Stefan\AppData\Local\Temp\ICReinstall_Setup.exe
C:\Users\Stefan\AppData\Local\Temp\InstallGenieo.exe
C:\Users\Stefan\AppData\Local\Temp\jreInstall.exe
C:\Users\Stefan\AppData\Local\Temp\SIntf16.dll
C:\Users\Stefan\AppData\Local\Temp\SIntf32.dll
C:\Users\Stefan\AppData\Local\Temp\SIntfNT.dll
C:\Users\Stefan\AppData\Local\Temp\smt_istartsurf.exe
C:\Users\Stefan\AppData\Local\Temp\war3_Install.exe
C:\Users\Stefan\AppData\Local\Temp\{743761E1-8460-4230-9EA2-45743A9047BD}-42.0.2311.152_42.0.2311.135_chrome_updater.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-03 16:39
==================== End of log ============================
prikladám FRST log.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-06-2015
Ran by Stefan (administrator) on STEFAN-PC on 06-06-2015 18:11:04
Running from C:\Users\Stefan\Desktop
Loaded Profiles: Stefan (Available Profiles: Stefan)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Angličtina (USA)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(XTab system) C:\Program Files (x86)\XTab\ProtectService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(© 2015 Microsoft Corporation) C:\Users\Stefan\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [6346464 2013-01-05] (Realtek semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-14] (Avast Software s.r.o.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [429792 2013-02-08] (AppEx Networks Corporation)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31280256 2015-04-17] (Skype Technologies S.A.)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [BingSvc] => C:\Users\Stefan\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-08] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\MountPoints2: {30e0ac73-077e-11e5-9c0a-342387ee0594} - F:\LaunchU3.exe -a
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\...\MountPoints2: {9f3ed4cc-e81d-11e4-96f1-342387ee0594} - E:\autorun.exe
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-04-14]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-14] (Avast Software s.r.o.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dsp ... earchTerms}
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts ... J9HF103545
HKU\S-1-5-21-4059302633-955075911-2127840080-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dsp ... earchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-4059302633-955075911-2127840080-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-02] (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-14] (Avast Software s.r.o.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-02] (Microsoft Corporation)
BHO-x32: LuckyTab Class -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> C:\Program Files (x86)\XTab\SupTab.dll [2015-05-29] (Thinknice Co. Limited)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-14] (Avast Software s.r.o.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-02] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-02] (Microsoft Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2011-01-20] ()
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2011-01-20] ()
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9HF103545
FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-02] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-02] (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-14]
Chrome:
=======
CHR Profile: C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast SafePrice) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-04-20]
CHR Extension: (MSN Homepage & Bing Search Engine) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-04-17]
CHR Extension: (Bookmark Manager) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-22]
CHR Extension: (Avast Online Security) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-04-14]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-14]
CHR Extension: (Google Wallet) - C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-14]
CHR HKU\S-1-5-21-4059302633-955075911-2127840080-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-14]
Opera:
=======
OPR Extension: (Swift Record) - C:\Users\Stefan\AppData\Roaming\Opera Software\Opera Stable\Extensions\hhfjaflcchgcmfnonahdjlcjgajlognd [2015-05-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-22] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-14] (Avast Software s.r.o.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [1008344 2013-02-19] (Broadcom Corporation.)
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [157824 2015-05-29] (XTab system)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-03-30] (LogMeIn, Inc.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 Update Swift Record; "C:\Program Files (x86)\Swift Record\updateSwiftRecord.exe" [X]
S2 Util Swift Record; "C:\Program Files (x86)\Swift Record\bin\utilSwiftRecord.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.)
R2 APXACC; C:\Windows\System32\DRIVERS\appexDrv.sys [217824 2013-03-21] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-04-14] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-14] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-14] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-14] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-04-14] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [271200 2015-04-14] ()
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2012-09-25] (Broadcom Corporation.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2015-04-21] (DT Soft Ltd)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [117912 2012-11-20] (Qualcomm Atheros Co., Ltd.)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8239456 2013-01-05] (Realtek Semiconductor Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2015-04-21] () [File not signed]
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software)
R1 {602b1e7a-d085-42c0-aa31-42f2f8e76963}Gw64; C:\Windows\System32\drivers\{602b1e7a-d085-42c0-aa31-42f2f8e76963}Gw64.sys [48784 2015-05-17] (StdLib)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-06 18:11 - 2015-06-06 18:11 - 00020730 _____ C:\Users\Stefan\Desktop\FRST.txt
2015-06-06 18:10 - 2015-06-06 18:11 - 00000000 ____D C:\FRST
2015-06-06 18:10 - 2015-06-06 18:10 - 02108928 _____ (Farbar) C:\Users\Stefan\Desktop\FRST64.exe
2015-05-29 23:24 - 2015-05-29 23:24 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Quake3
2015-05-29 17:47 - 2015-05-29 17:47 - 00000000 ____H C:\Users\Stefan\Documents\Default.rdp
2015-05-27 20:04 - 2006-10-19 10:28 - 00348092 _____ C:\Users\Public\aim_map.bsp
2015-05-24 13:19 - 2015-05-24 13:19 - 00001080 _____ C:\Users\Stefan\Desktop\Videá - odkaz.lnk
2015-05-22 21:10 - 2015-05-22 21:11 - 00000000 ____D C:\Program Files (x86)\Cossacks
2015-05-20 00:18 - 2015-06-03 16:04 - 00000000 ____D C:\Users\Public\CS
2015-05-17 22:24 - 2015-05-17 22:24 - 00000000 ____D C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07
2015-05-17 22:06 - 2015-05-17 22:23 - 166813300 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part4.rar
2015-05-17 21:50 - 2015-05-17 22:03 - 209715200 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part3.rar
2015-05-17 21:32 - 2015-05-17 21:49 - 209715200 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part2.rar
2015-05-17 21:16 - 2015-05-17 21:32 - 209715200 _____ C:\Users\Stefan\Downloads\Ego.-Medal-of-Honor-Allied-Assault-Breakthrough.By-HellBoy07.part1.rar
2015-05-17 21:04 - 2015-05-17 21:04 - 00000000 ____D C:\Users\Stefan\Downloads\age-of-mythology-crack
2015-05-17 21:03 - 2015-05-17 21:03 - 02159835 _____ C:\Users\Stefan\Downloads\age-of-mythology-crack.rar
2015-05-17 20:52 - 2015-05-17 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-05-17 20:49 - 2015-05-17 20:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-05-17 19:51 - 2015-05-17 20:37 - 531499008 _____ C:\Users\Stefan\Downloads\Age-of-Mythology-Gold---CD-2.iso
2015-05-17 18:36 - 2015-05-17 19:09 - 502269952 _____ C:\Users\Stefan\Downloads\Age-of-Mythology-Gold---CD-1.iso
2015-05-17 18:34 - 2015-05-17 18:35 - 01223680 _____ C:\Users\Stefan\Downloads\Age of Mythology Gold .exe
2015-05-17 18:30 - 2015-05-17 18:30 - 00000464 __RSH C:\ProgramData\ntuser.pol
2015-05-17 15:30 - 2015-05-17 15:31 - 00276576 _____ C:\Windows\Minidump\051715-26208-01.dmp
2015-05-17 15:28 - 2015-05-17 01:51 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{602b1e7a-d085-42c0-aa31-42f2f8e76963}Gw64.sys
2015-05-17 15:26 - 2015-06-02 23:32 - 00000000 ____D C:\Program Files (x86)\XTab
2015-05-17 15:26 - 2015-05-17 18:29 - 00000000 ____D C:\Program Files (x86)\Swift Record
2015-05-17 15:26 - 2015-05-17 15:26 - 00000000 ____D C:\ProgramData\IHProtectUpDate
2015-05-17 15:25 - 2015-06-06 12:44 - 00000000 ____D C:\ProgramData\WindowsMangerProtect
2015-05-17 15:25 - 2015-05-17 15:25 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\istartsurf
2015-05-17 15:25 - 2015-05-17 15:25 - 00000000 ____D C:\CAIMAN
2015-05-17 15:24 - 2015-05-17 15:24 - 00413360 _____ C:\Users\Stefan\Downloads\1001-SundayDrivers_downloader-Qe16xHNJA.exe
2015-05-17 14:34 - 2015-05-17 14:34 - 00021434 _____ C:\Users\Stefan\Downloads\Prince.of.Persia.The.Sands.of.Time - SKIDROW.torrent
2015-05-17 14:20 - 2015-05-17 14:20 - 00034474 _____ C:\Users\Stefan\Downloads\[isoHunt]-commandos-2-men-of-courage.torrent
2015-05-17 14:01 - 2015-05-17 14:01 - 00012421 _____ C:\Users\Stefan\Downloads\stronghold.crusader-2.torrent
2015-05-17 13:59 - 2015-05-17 13:59 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cossacks
2015-05-17 13:59 - 2015-05-17 13:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cossacks
2015-05-17 13:58 - 2015-05-17 13:58 - 00053248 _____ C:\Windows\SysWOW64\unrar.dll
2015-05-17 13:58 - 2014-12-15 23:33 - 04358144 _____ (GSC Game World) C:\Windows\uncsetup.exe
2015-05-17 13:57 - 2015-05-17 13:57 - 00000000 ____D C:\Users\Stefan\Downloads\Cossacks---European-Wars-1.15-M@
2015-05-16 20:24 - 2015-05-16 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
2015-05-16 20:23 - 2015-05-16 20:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
2015-05-16 20:23 - 2015-05-16 20:23 - 00000000 ____D C:\Program Files (x86)\Activision
2015-05-16 19:43 - 2015-05-16 20:17 - 564000768 _____ C:\Users\Stefan\Downloads\spiderman-2.iso
2015-05-16 00:09 - 2015-05-16 00:09 - 00000000 ____D C:\Users\Stefan\Downloads\viliam_klimacek_rozkvitli_sekery
2015-05-15 22:17 - 2015-05-15 22:17 - 17869704 _____ C:\Users\Stefan\Downloads\viliam_klimacek_rozkvitli_sekery.rar
2015-05-12 22:35 - 2015-05-12 13:56 - 00091712 _____ C:\Users\Public\Downloads\gg_dagger.nav
2015-05-12 22:35 - 2015-05-10 23:35 - 00490032 _____ C:\Users\Public\Downloads\gg_dagger.bsp
2015-05-12 22:26 - 2015-05-31 10:23 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zariadenia Bluetooth
2015-05-10 17:10 - 2015-05-10 17:10 - 00012995 _____ C:\Users\Stefan\Downloads\Hip_Hop_Ejay_6_Full_2_CDs_iso[www.btmon.com].torrent
2015-05-10 17:03 - 2015-05-27 19:18 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Audacity
2015-05-10 17:02 - 2015-05-10 17:02 - 00001019 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-05-10 17:02 - 2015-05-10 17:02 - 00001007 _____ C:\Users\Public\Desktop\Audacity.lnk
2015-05-10 17:02 - 2015-05-10 17:02 - 00000000 ____D C:\Program Files (x86)\Audacity
2015-05-10 16:58 - 2015-05-10 17:00 - 24210616 _____ (Audacity Team ) C:\Users\Stefan\Downloads\audacity.exe
2015-05-09 20:48 - 2015-05-09 20:48 - 00000889 _____ C:\Users\Stefan\Desktop\utorrent - odkaz.lnk
2015-05-09 20:47 - 2015-05-09 20:47 - 00012261 _____ C:\Users\Stefan\Downloads\Battlefield.1942 - SKIDROW.torrent
2015-05-09 09:56 - 2015-05-09 09:57 - 00893882 _____ C:\Users\Stefan\Downloads\Mafia-Crack---No-CD.rar
2015-05-09 09:50 - 2015-05-09 09:50 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mafia
2015-05-09 09:50 - 2015-05-09 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia
2015-05-09 09:50 - 2015-05-09 09:50 - 00000000 ____D C:\Program Files (x86)\Creative
2015-05-09 09:50 - 2002-06-06 14:38 - 00139264 _____ (Creative Technology Ltd) C:\Windows\SysWOW64\eax.dll
2015-05-09 09:50 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2015-05-09 09:45 - 2015-05-09 09:50 - 00000000 ____D C:\Program Files\Mafia
2015-05-07 22:41 - 2015-05-17 14:35 - 00000000 ____D C:\Torrents
2015-05-07 22:39 - 2015-05-24 00:50 - 00000000 ____D C:\uTorrent
2015-05-07 22:38 - 2015-05-07 22:38 - 00763656 _____ (emc) C:\Users\Stefan\Downloads\uTorrentServer221.exe
2015-05-07 22:26 - 2015-05-07 22:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-05-07 22:26 - 2015-05-07 22:26 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2015-05-07 22:26 - 2015-03-30 15:25 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2015-05-07 22:24 - 2015-06-06 18:04 - 00000000 ____D C:\Users\Stefan\AppData\Local\LogMeIn Hamachi
2015-05-07 22:24 - 2015-05-07 22:24 - 00000000 ____D C:\Users\Stefan\AppData\Local\LogMeIn
2015-05-07 22:24 - 2015-05-07 22:24 - 00000000 ____D C:\ProgramData\LogMeIn
2015-05-07 22:19 - 2015-05-07 22:22 - 08544256 _____ C:\Users\Stefan\Downloads\hamachi.msi
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-06 18:06 - 2015-04-14 19:14 - 00307711 _____ C:\Windows\WindowsUpdate.log
2015-06-06 18:04 - 2015-04-17 07:13 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Skype
2015-06-06 18:03 - 2015-04-14 20:18 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-06 18:02 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-06 18:02 - 2009-07-14 06:51 - 00053160 _____ C:\Windows\setupact.log
2015-06-06 17:41 - 2015-04-14 23:15 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2015-06-06 17:32 - 2015-04-14 20:18 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-06 12:51 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-06 12:51 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-06 12:48 - 2009-07-14 07:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-05 01:42 - 2015-04-26 12:01 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\vlc
2015-06-04 23:39 - 2015-04-26 12:06 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-04 23:35 - 2015-04-14 20:21 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-06-04 22:38 - 2015-04-25 18:41 - 00000000 ____D C:\Program Files (x86)\Call of Duty
2015-05-30 20:18 - 2015-04-25 15:55 - 00000000 ____D C:\Users\Stefan\Desktop\GAMES
2015-05-30 10:03 - 2015-04-19 12:26 - 00000000 ____D C:\Users\Stefan\Desktop\Hudba
2015-05-24 10:22 - 2015-04-26 12:28 - 00003844 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1430044135
2015-05-24 10:16 - 2010-11-21 05:47 - 00016902 _____ C:\Windows\PFRO.log
2015-05-24 10:16 - 2009-07-14 06:45 - 00433672 _____ C:\Windows\system32\FNTCACHE.DAT
2015-05-21 13:55 - 2015-04-14 20:03 - 00000000 ____D C:\Users\Stefan\Documents\Prieèinok na výmenu cez Bluetooth
2015-05-18 17:44 - 2015-04-14 20:17 - 00111920 _____ C:\Users\Stefan\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-17 20:55 - 2015-04-17 06:32 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-05-17 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-05-17 15:32 - 2009-07-14 04:34 - 00000580 _____ C:\Windows\win.ini
2015-05-17 15:30 - 2015-04-26 08:59 - 00000000 ____D C:\Windows\Minidump
2015-05-17 15:30 - 2015-04-26 08:58 - 453171428 _____ C:\Windows\MEMORY.DMP
2015-05-17 15:25 - 2015-04-26 12:28 - 00001413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-05-17 15:25 - 2015-04-14 19:12 - 00001715 _____ C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-17 14:13 - 2015-04-17 07:13 - 00000000 ____D C:\ProgramData\Skype
2015-05-16 20:24 - 2015-04-14 19:57 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-05-16 03:26 - 2015-04-14 20:18 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 03:26 - 2015-04-14 20:18 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-09 09:51 - 2015-04-14 19:11 - 00000000 ____D C:\Users\Stefan\AppData\Local\VirtualStore
2015-05-07 16:30 - 2015-04-14 19:11 - 00000000 ____D C:\Users\Stefan
2015-05-07 16:28 - 2015-04-14 20:44 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-05-07 16:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2015-05-07 16:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
==================== Files in the root of some directories =======
2002-08-29 17:33 - 2002-08-29 17:33 - 0319488 ____R () C:\Users\Stefan\AppData\Roaming\MafiaSetup.exe
Files to move or delete:
====================
C:\Users\Public\Alcohol120_trial_2.0.0.1331.exe
C:\Users\Public\DTLite4402-0131.exe
C:\Users\Public\DTLite501-0406.exe
Some files in TEMP:
====================
C:\Users\Stefan\AppData\Local\Temp\1001-SundayDrivers.exe
C:\Users\Stefan\AppData\Local\Temp\appshat_generic.exe
C:\Users\Stefan\AppData\Local\Temp\AxToolbarSetup.exe
C:\Users\Stefan\AppData\Local\Temp\BSvcProcessor.exe
C:\Users\Stefan\AppData\Local\Temp\BSvcUpdater.exe
C:\Users\Stefan\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Stefan\AppData\Local\Temp\EBU2CF.exe
C:\Users\Stefan\AppData\Local\Temp\EBU7AF.DLL
C:\Users\Stefan\AppData\Local\Temp\File.exe
C:\Users\Stefan\AppData\Local\Temp\ICReinstall_Setup.exe
C:\Users\Stefan\AppData\Local\Temp\InstallGenieo.exe
C:\Users\Stefan\AppData\Local\Temp\jreInstall.exe
C:\Users\Stefan\AppData\Local\Temp\SIntf16.dll
C:\Users\Stefan\AppData\Local\Temp\SIntf32.dll
C:\Users\Stefan\AppData\Local\Temp\SIntfNT.dll
C:\Users\Stefan\AppData\Local\Temp\smt_istartsurf.exe
C:\Users\Stefan\AppData\Local\Temp\war3_Install.exe
C:\Users\Stefan\AppData\Local\Temp\{743761E1-8460-4230-9EA2-45743A9047BD}-42.0.2311.152_42.0.2311.135_chrome_updater.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-03 16:39
==================== End of log ============================