Prosim o kontrolu logu - vyskakujici reklamy
Napsal: 11 čer 2015 06:07
Dobry den, prosim o kontrolu logu. Zacaly mi v prohlizecich vyskakovat reklamni okna, otevirat se ruzne stranky na browser-hry a informace o vyhrach. Zde je vypis z logu FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-06-2015
Ran by M (administrator) on M-PC on 11-06-2015 06:59:09
Running from C:\Users\M\Desktop
Loaded Profiles: M (Available Profiles: M)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avast Software s.r.o.) D:\= PROGRAMY =\Avast 2014\AvastSvc.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
() C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(QIP.ru) C:\Program Files (x86)\QipGuard\QipGuard.exe
(Saitek) C:\Program Files\Saitek\DirectOutput\DirectOutputService.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(TeamViewer GmbH) D:\= PROGRAMY =\TeamViewer6\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(http://tortoisesvn.net) D:\= PROGRAMY =\SVN\bin\TSVNCache.exe
(Samsung) D:\= PROGRAMY =\Kies\Kies.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\GIGABYTE\GHOST\Tilt.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Avast Software s.r.o.) D:\= PROGRAMY =\Avast 2014\avastui.exe
(Samsung Electronics Co., Ltd.) D:\= PROGRAMY =\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\3\Plugin.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\5\Plugin.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\2\Plugin.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\3\Plugin.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8158240 2009-10-06] (Realtek Semiconductor)
HKLM\...\Run: [ISW] => [X]
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Tilt] => C:\Program Files (x86)\GIGABYTE\GHOST\Tilt.exe [724992 2009-06-26] ()
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [AvastUI.exe] => D:\= PROGRAMY =\Avast 2014\AvastUI.exe [5515496 2015-05-15] (Avast Software s.r.o.)
HKLM-x32\...\Run: [KiesTrayAgent] => D:\= PROGRAMY =\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\...\Run: [DAEMON Tools Lite] => D:\= PROGRAMY =\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\...\Run: [KiesPreload] => D:\= PROGRAMY =\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\...\Run: [] => D:\= PROGRAMY =\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-10-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\= PROGRAMY =\Avast 2014\ashShA64.dll [2015-04-22] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\= PROGRAMY =\Avast 2014\aswWebRepIE64.dll [2015-04-22] (Avast Software s.r.o.)
BHO-x32: Record Page -> {2335267c-dbba-4dd5-a9d0-c4db8e6a75a4} -> C:\Program Files (x86)\Record Page\Extensions\2335267c-dbba-4dd5-a9d0-c4db8e6a75a4.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-20] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\= PROGRAMY =\Avast 2014\aswWebRepIE.dll [2015-04-22] (Avast Software s.r.o.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-20] (Oracle Corporation)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-11-03] (Check Point Software Technologies)
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-11-03] (Check Point Software Technologies)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKU\S-1-5-21-3198219806-2281913311-1279161303-1000 -> ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-11-03] (Check Point Software Technologies)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4BC723EE-012E-4DCC-B992-6B66B96B63B2}: [NameServer] 8.8.8.8,10.10.10.6
FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default
FF NewTab: about:newtab
FF DefaultSearchEngine: Seznam
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?clid=22668
FF SearchEngineOrder.1: Seznam
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll No File
FF Plugin: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelogx64.dll [2015-03-10] (EA Digital Illusions CE AB)
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> D:\= PROGRAMY =\Java\bin\plugin2\npjp2.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll [2015-03-10] (EA Digital Illusions CE AB)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-20] (Oracle Corporation)
FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2015-05-05] (Reto-Moto ApS)
FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll [2013-04-19] (Nexon)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @parallelgraphics.com/Cortona -> C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npCortona.dll [2010-08-09] (ParallelGraphics)
FF Plugin-x32: @software602.cz/602XML Filler -> D:\= PROGRAMY =\602\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3198219806-2281913311-1279161303-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\M\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2012-06-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3198219806-2281913311-1279161303-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-05-20] (Ubisoft)
FF SearchPlugin: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\searchplugins\seznam-avast.xml [2015-06-09]
FF Extension: HNG downloader/starter (live) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\npretoxlive@live.heroesandgenerals.com [2012-05-05]
FF Extension: PutLocker Downloader - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\ptl@ptl.com.xpi [2013-06-26]
FF Extension: Adblock Plus - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-05-08]
FF Extension: Record Page - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\{d1b24110-ff8f-46b1-9312-0f9e2783ae7e}.xpi [2015-06-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\= PROGRAMY =\Avast 2014\WebRep\FF
FF Extension: Avast Online Security - D:\= PROGRAMY =\Avast 2014\WebRep\FF [2014-09-03]
FF Extension: No Name - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\extensions\searchffv2@gmail.com [not found]
FF Extension: No Name - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\extensions\searchffv2@gmail.com [not found]
Chrome:
=======
CHR Profile: C:\Users\M\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-30]
CHR Extension: (Google Search) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-30]
CHR Extension: (Tampermonkey) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-11-23]
CHR Extension: (Record Page) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\dphgnejlklokobpandlkclmjldgbjppc [2015-06-09]
CHR Extension: (Heroes & Generals - Charlie) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gedlhmecleleofbcmeikmbnpocenmbof [2015-05-08]
CHR Extension: (AdBlock) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-10-17]
CHR Extension: (Bookmark Manager) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-22]
CHR Extension: (Avast Online Security) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-03]
CHR Extension: (Skype Click to Call) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2012-06-09]
CHR Extension: (Google Wallet) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-30]
CHR HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - D:\= PROGRAMY =\Avast 2014\WebRep\Chrome\aswWebRepChrome.crx [2015-04-22]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
Opera:
=======
OPR Extension: (Record Page) - C:\Users\M\AppData\Roaming\Opera Software\Opera Stable\Extensions\dphgnejlklokobpandlkclmjldgbjppc [2015-06-09]
StartMenuInternet: (HKLM) Opera - C:\Program Files (x86)\Opera\Opera.exe http://www.omniboxes.com/?type=sc&ts=14 ... XX9VP8Z72X
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 avast! Antivirus; D:\= PROGRAMY =\Avast 2014\AvastSvc.exe [343336 2015-04-22] (Avast Software s.r.o.)
S3 AvastVBoxSvc; D:\= PROGRAMY =\Avast 2014\ng\vbox\AvastVBoxSVC.exe [4034896 2015-04-22] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-12-30] ()
R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () [File not signed]
R2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [827520 2011-11-03] (Check Point Software Technologies)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 Origin Client Service; D:\= PROGRAMY =\Origin\OriginClientService.exe [1931632 2015-04-10] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-03-14] ()
R2 QipGuard; C:\Program Files (x86)\QipGuard\QipGuard.exe [191440 2012-01-12] (QIP.ru) [File not signed]
R2 SaiDOutput; C:\Program Files\Saitek\DirectOutput\DirectOutputService.exe [241152 2008-04-04] (Saitek) [File not signed]
R2 Service Mgr RecordPage; C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe [649480 2015-06-11] ()
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2015-05-08] (PS Media s.r.o.)
R2 TeamViewer6; D:\= PROGRAMY =\TeamViewer6\TeamViewer_Service.exe [2228008 2010-12-07] (TeamViewer GmbH)
R2 Update Mgr RecordPage; C:\Program Files (x86)\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe [575240 2015-06-11] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-22] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-22] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-22] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-22] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-22] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-22] ()
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-08-18] (DT Soft Ltd)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () [File not signed]
R1 ISODrive; D:\= PROGRAMY =\UltraISO\drivers\ISODrv64.sys [115600 2009-02-10] (EZB Systems, Inc.)
R2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33672 2011-11-03] (Check Point Software Technologies)
R3 npusbio; C:\Windows\System32\Drivers\npusbio_x64.sys [38400 2012-07-09] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [114016 2004-08-09] (Protection Technology) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [7040 2004-07-19] (Protection Technology) [File not signed]
R3 SaiH0762; C:\Windows\System32\DRIVERS\SaiH0762.sys [178560 2008-04-04] (Saitek)
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [513080 2011-02-08] () [File not signed]
R2 VBoxAswDrv; D:\= PROGRAMY =\Avast 2014\ng\vbox\VBoxAswDrv.sys [273824 2015-04-22] (Avast Software)
U3 a308xopp; C:\Windows\System32\Drivers\a308xopp.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 cpuz130; \??\C:\Users\M\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [X]
S3 NTACCESS; \??\F:\NTACCESS_64.sys [X]
S1 prodrv06; \SystemRoot\System32\drivers\prodrv06.sys [X]
S3 SetupNTGLM7X; \??\F:\NTGLM7X.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-11 06:59 - 2015-06-11 06:59 - 00026288 _____ C:\Users\M\Desktop\FRST.txt
2015-06-11 06:56 - 2015-06-11 06:56 - 02108928 _____ (Farbar) C:\Users\M\Desktop\FRST64.exe
2015-06-11 06:55 - 2015-06-11 06:55 - 00001852 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-09 16:05 - 2015-06-09 16:05 - 00000000 ____D C:\Program Files (x86)\Record Page
2015-06-09 15:55 - 2015-06-09 15:55 - 02231296 _____ C:\Users\M\Desktop\adwcleaner_4.206.exe
2015-06-09 15:34 - 2015-06-09 15:34 - 00003192 _____ C:\Windows\System32\Tasks\avastBCLRestart_chrome.exe
2015-06-08 15:58 - 2015-06-08 15:58 - 00000476 __RSH C:\ProgramData\ntuser.pol
2015-06-08 15:57 - 2015-06-09 16:02 - 00001812 _____ C:\Windows\PFRO.log
2015-06-06 13:36 - 2015-06-11 06:53 - 00000000 ____D C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777
2015-06-01 17:28 - 2015-06-06 13:41 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-06-01 17:28 - 2015-06-01 17:28 - 00003870 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2015-05-29 20:51 - 2015-06-11 06:46 - 00002688 _____ C:\Windows\setupact.log
2015-05-29 20:51 - 2015-05-29 20:51 - 00000000 _____ C:\Windows\setuperr.log
2015-05-28 20:31 - 2015-05-28 20:37 - 00000000 ____D C:\Users\M\Documents\Project CARS
2015-05-25 19:20 - 2015-05-25 19:20 - 00000000 ____D C:\Program Files\avast software
2015-05-21 12:59 - 2015-05-30 21:06 - 00000000 ____D C:\Users\M\Documents\The Witcher 3
2015-05-21 12:45 - 2015-05-21 12:45 - 00000000 ____D C:\Users\M\AppData\Local\Colossal Order
2015-05-21 12:41 - 2015-05-21 12:41 - 00000868 _____ C:\Users\Public\Desktop\Cities Skylines - Deluxe Edition.lnk
2015-05-20 23:06 - 2015-05-20 23:06 - 00000889 _____ C:\Users\M\Desktop\The Witcher 3 Wild Hunt.lnk
2015-05-20 23:06 - 2015-05-20 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 3 Wild Hunt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-11 06:59 - 2014-10-15 20:43 - 00000000 ____D C:\FRST
2015-06-11 06:54 - 2014-09-02 22:31 - 01179457 _____ C:\Windows\WindowsUpdate.log
2015-06-11 06:54 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-11 06:54 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-11 06:52 - 2009-07-14 17:18 - 18748306 _____ C:\Windows\system32\perfh005.dat
2015-06-11 06:52 - 2009-07-14 17:18 - 06378726 _____ C:\Windows\system32\perfc005.dat
2015-06-11 06:52 - 2009-07-14 07:13 - 00006228 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-11 06:51 - 2014-10-14 22:16 - 00003808 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1413316471
2015-06-11 06:47 - 2012-07-04 12:30 - 00004160 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-06-11 06:46 - 2015-05-08 20:02 - 00000000 _____ C:\Windows\SysWOW64\sinstall.log
2015-06-11 06:46 - 2014-10-18 18:50 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-11 06:46 - 2011-11-27 10:32 - 00000000 ____D C:\Users\M\AppData\Local\TSVNCache
2015-06-11 06:46 - 2010-10-16 12:44 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-11 06:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-09 16:00 - 2014-10-15 22:06 - 00000000 ____D C:\AdwCleaner
2015-06-09 16:00 - 2014-10-15 20:40 - 00000658 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 30.lnk
2015-06-09 16:00 - 2014-10-14 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-09 16:00 - 2014-10-04 09:28 - 00000958 _____ C:\Users\Public\Desktop\IL-2 Sturmovik Battle of Stalingrad.lnk
2015-06-09 16:00 - 2014-04-28 22:04 - 00000000 ____D C:\Users\M\AppData\Local\TB
2015-06-09 16:00 - 2013-03-15 22:27 - 00000961 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-09 16:00 - 2012-08-15 16:09 - 00000665 _____ C:\Users\M\Desktop\War Thunder.lnk
2015-06-09 16:00 - 2012-08-15 16:09 - 00000000 ____D C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
2015-06-09 16:00 - 2011-10-19 11:13 - 00000000 ____D C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Benchmark Sims
2015-06-09 16:00 - 2011-02-02 10:44 - 00000979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-06-09 15:34 - 2015-05-08 20:02 - 00001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-08 16:13 - 2014-10-18 18:50 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-08 16:05 - 2014-11-25 00:21 - 00000000 ___RD C:\Users\M\Desktop\MIRKA
2015-06-06 13:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-06-06 13:35 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
2015-06-01 17:28 - 2014-08-28 22:18 - 00000000 ____D C:\Users\M\AppData\Local\Adobe
2015-06-01 17:28 - 2012-04-04 09:14 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-01 17:28 - 2011-05-14 07:04 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-01 17:27 - 2014-12-01 22:45 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-29 23:54 - 2011-09-29 18:45 - 00000000 ____D C:\ProgramData\Origin
2015-05-28 17:42 - 2011-02-08 20:32 - 00000000 ____D C:\Users\M\AppData\Roaming\DAEMON Tools Lite
2015-05-28 17:42 - 2010-10-16 18:41 - 00000000 ____D C:\Windows\Panther
2015-05-28 17:38 - 2012-02-11 18:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrace uživatele zařízení Canon MG3100 series
2015-05-26 12:57 - 2011-02-08 20:32 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2015-05-21 12:24 - 2010-11-16 18:17 - 00000000 ____D C:\Users\M\Documents\My Games
2015-05-21 12:22 - 2015-02-01 11:44 - 00000000 ____D C:\Users\M\Documents\Ubisoft
2015-05-19 22:08 - 2010-10-30 18:31 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-19 22:08 - 2010-10-30 18:31 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories =======
2012-04-16 21:33 - 2012-04-30 08:14 - 0003584 _____ () C:\Users\M\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-13 10:16 - 2014-12-13 10:16 - 0010293 _____ () C:\Users\M\AppData\Local\recently-used.xbel
2012-04-12 08:42 - 2015-02-07 23:44 - 0027620 _____ () C:\Users\M\AppData\Local\SRDownloader.err
2012-04-06 10:00 - 2015-02-07 23:44 - 0001136 _____ () C:\Users\M\AppData\Local\SRDownloader.nast
2012-01-24 07:01 - 2012-01-24 07:01 - 0000000 _____ () C:\Users\M\AppData\Local\{5A0EF47B-D26B-4CEF-9BFB-556569447A1F}
Some files in TEMP:
====================
C:\Users\M\AppData\Local\Temp\KMP_3.9.1.136.exe
C:\Users\M\AppData\Local\Temp\Quarantine.exe
C:\Users\M\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-24 11:40
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-06-2015
Ran by M (administrator) on M-PC on 11-06-2015 06:59:09
Running from C:\Users\M\Desktop
Loaded Profiles: M (Available Profiles: M)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avast Software s.r.o.) D:\= PROGRAMY =\Avast 2014\AvastSvc.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
() C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(QIP.ru) C:\Program Files (x86)\QipGuard\QipGuard.exe
(Saitek) C:\Program Files\Saitek\DirectOutput\DirectOutputService.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(TeamViewer GmbH) D:\= PROGRAMY =\TeamViewer6\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(http://tortoisesvn.net) D:\= PROGRAMY =\SVN\bin\TSVNCache.exe
(Samsung) D:\= PROGRAMY =\Kies\Kies.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\GIGABYTE\GHOST\Tilt.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Avast Software s.r.o.) D:\= PROGRAMY =\Avast 2014\avastui.exe
(Samsung Electronics Co., Ltd.) D:\= PROGRAMY =\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\3\Plugin.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\5\Plugin.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\2\Plugin.exe
() C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugins\3\Plugin.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8158240 2009-10-06] (Realtek Semiconductor)
HKLM\...\Run: [ISW] => [X]
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Tilt] => C:\Program Files (x86)\GIGABYTE\GHOST\Tilt.exe [724992 2009-06-26] ()
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [AvastUI.exe] => D:\= PROGRAMY =\Avast 2014\AvastUI.exe [5515496 2015-05-15] (Avast Software s.r.o.)
HKLM-x32\...\Run: [KiesTrayAgent] => D:\= PROGRAMY =\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\...\Run: [DAEMON Tools Lite] => D:\= PROGRAMY =\DAEMON Tools Lite\DTLite.exe [4910912 2011-08-02] (DT Soft Ltd)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\...\Run: [KiesPreload] => D:\= PROGRAMY =\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\...\Run: [] => D:\= PROGRAMY =\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung)
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-10-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\= PROGRAMY =\Avast 2014\ashShA64.dll [2015-04-22] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\= PROGRAMY =\Avast 2014\aswWebRepIE64.dll [2015-04-22] (Avast Software s.r.o.)
BHO-x32: Record Page -> {2335267c-dbba-4dd5-a9d0-c4db8e6a75a4} -> C:\Program Files (x86)\Record Page\Extensions\2335267c-dbba-4dd5-a9d0-c4db8e6a75a4.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-20] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\= PROGRAMY =\Avast 2014\aswWebRepIE.dll [2015-04-22] (Avast Software s.r.o.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-20] (Oracle Corporation)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-11-03] (Check Point Software Technologies)
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-11-03] (Check Point Software Technologies)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKU\S-1-5-21-3198219806-2281913311-1279161303-1000 -> ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-11-03] (Check Point Software Technologies)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4BC723EE-012E-4DCC-B992-6B66B96B63B2}: [NameServer] 8.8.8.8,10.10.10.6
FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default
FF NewTab: about:newtab
FF DefaultSearchEngine: Seznam
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?clid=22668
FF SearchEngineOrder.1: Seznam
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll No File
FF Plugin: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelogx64.dll [2015-03-10] (EA Digital Illusions CE AB)
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> D:\= PROGRAMY =\Java\bin\plugin2\npjp2.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll [2015-03-10] (EA Digital Illusions CE AB)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-20] (Oracle Corporation)
FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2015-05-05] (Reto-Moto ApS)
FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll [2013-04-19] (Nexon)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @parallelgraphics.com/Cortona -> C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npCortona.dll [2010-08-09] (ParallelGraphics)
FF Plugin-x32: @software602.cz/602XML Filler -> D:\= PROGRAMY =\602\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3198219806-2281913311-1279161303-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\M\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2012-06-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3198219806-2281913311-1279161303-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-05-20] (Ubisoft)
FF SearchPlugin: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\searchplugins\seznam-avast.xml [2015-06-09]
FF Extension: HNG downloader/starter (live) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\npretoxlive@live.heroesandgenerals.com [2012-05-05]
FF Extension: PutLocker Downloader - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\ptl@ptl.com.xpi [2013-06-26]
FF Extension: Adblock Plus - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-05-08]
FF Extension: Record Page - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\Extensions\{d1b24110-ff8f-46b1-9312-0f9e2783ae7e}.xpi [2015-06-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\= PROGRAMY =\Avast 2014\WebRep\FF
FF Extension: Avast Online Security - D:\= PROGRAMY =\Avast 2014\WebRep\FF [2014-09-03]
FF Extension: No Name - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\extensions\searchffv2@gmail.com [not found]
FF Extension: No Name - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\1abl6ohg.default\extensions\searchffv2@gmail.com [not found]
Chrome:
=======
CHR Profile: C:\Users\M\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-30]
CHR Extension: (Google Search) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-30]
CHR Extension: (Tampermonkey) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-11-23]
CHR Extension: (Record Page) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\dphgnejlklokobpandlkclmjldgbjppc [2015-06-09]
CHR Extension: (Heroes & Generals - Charlie) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gedlhmecleleofbcmeikmbnpocenmbof [2015-05-08]
CHR Extension: (AdBlock) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-10-17]
CHR Extension: (Bookmark Manager) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-22]
CHR Extension: (Avast Online Security) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-03]
CHR Extension: (Skype Click to Call) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2012-06-09]
CHR Extension: (Google Wallet) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-30]
CHR HKU\S-1-5-21-3198219806-2281913311-1279161303-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - D:\= PROGRAMY =\Avast 2014\WebRep\Chrome\aswWebRepChrome.crx [2015-04-22]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
Opera:
=======
OPR Extension: (Record Page) - C:\Users\M\AppData\Roaming\Opera Software\Opera Stable\Extensions\dphgnejlklokobpandlkclmjldgbjppc [2015-06-09]
StartMenuInternet: (HKLM) Opera - C:\Program Files (x86)\Opera\Opera.exe http://www.omniboxes.com/?type=sc&ts=14 ... XX9VP8Z72X
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 avast! Antivirus; D:\= PROGRAMY =\Avast 2014\AvastSvc.exe [343336 2015-04-22] (Avast Software s.r.o.)
S3 AvastVBoxSvc; D:\= PROGRAMY =\Avast 2014\ng\vbox\AvastVBoxSVC.exe [4034896 2015-04-22] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-12-30] ()
R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () [File not signed]
R2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [827520 2011-11-03] (Check Point Software Technologies)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 Origin Client Service; D:\= PROGRAMY =\Origin\OriginClientService.exe [1931632 2015-04-10] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-03-14] ()
R2 QipGuard; C:\Program Files (x86)\QipGuard\QipGuard.exe [191440 2012-01-12] (QIP.ru) [File not signed]
R2 SaiDOutput; C:\Program Files\Saitek\DirectOutput\DirectOutputService.exe [241152 2008-04-04] (Saitek) [File not signed]
R2 Service Mgr RecordPage; C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe [649480 2015-06-11] ()
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2015-05-08] (PS Media s.r.o.)
R2 TeamViewer6; D:\= PROGRAMY =\TeamViewer6\TeamViewer_Service.exe [2228008 2010-12-07] (TeamViewer GmbH)
R2 Update Mgr RecordPage; C:\Program Files (x86)\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe [575240 2015-06-11] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-22] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-22] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-22] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-22] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-22] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-22] ()
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-08-18] (DT Soft Ltd)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () [File not signed]
R1 ISODrive; D:\= PROGRAMY =\UltraISO\drivers\ISODrv64.sys [115600 2009-02-10] (EZB Systems, Inc.)
R2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33672 2011-11-03] (Check Point Software Technologies)
R3 npusbio; C:\Windows\System32\Drivers\npusbio_x64.sys [38400 2012-07-09] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [114016 2004-08-09] (Protection Technology) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [7040 2004-07-19] (Protection Technology) [File not signed]
R3 SaiH0762; C:\Windows\System32\DRIVERS\SaiH0762.sys [178560 2008-04-04] (Saitek)
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [513080 2011-02-08] () [File not signed]
R2 VBoxAswDrv; D:\= PROGRAMY =\Avast 2014\ng\vbox\VBoxAswDrv.sys [273824 2015-04-22] (Avast Software)
U3 a308xopp; C:\Windows\System32\Drivers\a308xopp.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 cpuz130; \??\C:\Users\M\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [X]
S3 NTACCESS; \??\F:\NTACCESS_64.sys [X]
S1 prodrv06; \SystemRoot\System32\drivers\prodrv06.sys [X]
S3 SetupNTGLM7X; \??\F:\NTGLM7X.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-11 06:59 - 2015-06-11 06:59 - 00026288 _____ C:\Users\M\Desktop\FRST.txt
2015-06-11 06:56 - 2015-06-11 06:56 - 02108928 _____ (Farbar) C:\Users\M\Desktop\FRST64.exe
2015-06-11 06:55 - 2015-06-11 06:55 - 00001852 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-09 16:05 - 2015-06-09 16:05 - 00000000 ____D C:\Program Files (x86)\Record Page
2015-06-09 15:55 - 2015-06-09 15:55 - 02231296 _____ C:\Users\M\Desktop\adwcleaner_4.206.exe
2015-06-09 15:34 - 2015-06-09 15:34 - 00003192 _____ C:\Windows\System32\Tasks\avastBCLRestart_chrome.exe
2015-06-08 15:58 - 2015-06-08 15:58 - 00000476 __RSH C:\ProgramData\ntuser.pol
2015-06-08 15:57 - 2015-06-09 16:02 - 00001812 _____ C:\Windows\PFRO.log
2015-06-06 13:36 - 2015-06-11 06:53 - 00000000 ____D C:\ProgramData\87737dd0-ad90-4193-bd48-336966b8d777
2015-06-01 17:28 - 2015-06-06 13:41 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-06-01 17:28 - 2015-06-01 17:28 - 00003870 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2015-05-29 20:51 - 2015-06-11 06:46 - 00002688 _____ C:\Windows\setupact.log
2015-05-29 20:51 - 2015-05-29 20:51 - 00000000 _____ C:\Windows\setuperr.log
2015-05-28 20:31 - 2015-05-28 20:37 - 00000000 ____D C:\Users\M\Documents\Project CARS
2015-05-25 19:20 - 2015-05-25 19:20 - 00000000 ____D C:\Program Files\avast software
2015-05-21 12:59 - 2015-05-30 21:06 - 00000000 ____D C:\Users\M\Documents\The Witcher 3
2015-05-21 12:45 - 2015-05-21 12:45 - 00000000 ____D C:\Users\M\AppData\Local\Colossal Order
2015-05-21 12:41 - 2015-05-21 12:41 - 00000868 _____ C:\Users\Public\Desktop\Cities Skylines - Deluxe Edition.lnk
2015-05-20 23:06 - 2015-05-20 23:06 - 00000889 _____ C:\Users\M\Desktop\The Witcher 3 Wild Hunt.lnk
2015-05-20 23:06 - 2015-05-20 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 3 Wild Hunt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-11 06:59 - 2014-10-15 20:43 - 00000000 ____D C:\FRST
2015-06-11 06:54 - 2014-09-02 22:31 - 01179457 _____ C:\Windows\WindowsUpdate.log
2015-06-11 06:54 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-11 06:54 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-11 06:52 - 2009-07-14 17:18 - 18748306 _____ C:\Windows\system32\perfh005.dat
2015-06-11 06:52 - 2009-07-14 17:18 - 06378726 _____ C:\Windows\system32\perfc005.dat
2015-06-11 06:52 - 2009-07-14 07:13 - 00006228 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-11 06:51 - 2014-10-14 22:16 - 00003808 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1413316471
2015-06-11 06:47 - 2012-07-04 12:30 - 00004160 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-06-11 06:46 - 2015-05-08 20:02 - 00000000 _____ C:\Windows\SysWOW64\sinstall.log
2015-06-11 06:46 - 2014-10-18 18:50 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-11 06:46 - 2011-11-27 10:32 - 00000000 ____D C:\Users\M\AppData\Local\TSVNCache
2015-06-11 06:46 - 2010-10-16 12:44 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-11 06:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-09 16:00 - 2014-10-15 22:06 - 00000000 ____D C:\AdwCleaner
2015-06-09 16:00 - 2014-10-15 20:40 - 00000658 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 30.lnk
2015-06-09 16:00 - 2014-10-14 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-09 16:00 - 2014-10-04 09:28 - 00000958 _____ C:\Users\Public\Desktop\IL-2 Sturmovik Battle of Stalingrad.lnk
2015-06-09 16:00 - 2014-04-28 22:04 - 00000000 ____D C:\Users\M\AppData\Local\TB
2015-06-09 16:00 - 2013-03-15 22:27 - 00000961 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-09 16:00 - 2012-08-15 16:09 - 00000665 _____ C:\Users\M\Desktop\War Thunder.lnk
2015-06-09 16:00 - 2012-08-15 16:09 - 00000000 ____D C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
2015-06-09 16:00 - 2011-10-19 11:13 - 00000000 ____D C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Benchmark Sims
2015-06-09 16:00 - 2011-02-02 10:44 - 00000979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-06-09 15:34 - 2015-05-08 20:02 - 00001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-08 16:13 - 2014-10-18 18:50 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-08 16:05 - 2014-11-25 00:21 - 00000000 ___RD C:\Users\M\Desktop\MIRKA
2015-06-06 13:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-06-06 13:35 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
2015-06-01 17:28 - 2014-08-28 22:18 - 00000000 ____D C:\Users\M\AppData\Local\Adobe
2015-06-01 17:28 - 2012-04-04 09:14 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-01 17:28 - 2011-05-14 07:04 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-01 17:27 - 2014-12-01 22:45 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-29 23:54 - 2011-09-29 18:45 - 00000000 ____D C:\ProgramData\Origin
2015-05-28 17:42 - 2011-02-08 20:32 - 00000000 ____D C:\Users\M\AppData\Roaming\DAEMON Tools Lite
2015-05-28 17:42 - 2010-10-16 18:41 - 00000000 ____D C:\Windows\Panther
2015-05-28 17:38 - 2012-02-11 18:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrace uživatele zařízení Canon MG3100 series
2015-05-26 12:57 - 2011-02-08 20:32 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2015-05-21 12:24 - 2010-11-16 18:17 - 00000000 ____D C:\Users\M\Documents\My Games
2015-05-21 12:22 - 2015-02-01 11:44 - 00000000 ____D C:\Users\M\Documents\Ubisoft
2015-05-19 22:08 - 2010-10-30 18:31 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-19 22:08 - 2010-10-30 18:31 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories =======
2012-04-16 21:33 - 2012-04-30 08:14 - 0003584 _____ () C:\Users\M\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-13 10:16 - 2014-12-13 10:16 - 0010293 _____ () C:\Users\M\AppData\Local\recently-used.xbel
2012-04-12 08:42 - 2015-02-07 23:44 - 0027620 _____ () C:\Users\M\AppData\Local\SRDownloader.err
2012-04-06 10:00 - 2015-02-07 23:44 - 0001136 _____ () C:\Users\M\AppData\Local\SRDownloader.nast
2012-01-24 07:01 - 2012-01-24 07:01 - 0000000 _____ () C:\Users\M\AppData\Local\{5A0EF47B-D26B-4CEF-9BFB-556569447A1F}
Some files in TEMP:
====================
C:\Users\M\AppData\Local\Temp\KMP_3.9.1.136.exe
C:\Users\M\AppData\Local\Temp\Quarantine.exe
C:\Users\M\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-24 11:40
==================== End of log ============================