Prosím o pomoc s havětí
Napsal: 22 črc 2015 16:21
Dobrý den chtěl bych poprosit o pomoc s vyčištěním pc od havěti a virů. Předem děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015
Ran by Kika (administrator) on KIKA-PC on 22-07-2015 17:13:06
Running from C:\Users\Kika\Downloads
Loaded Profiles: UpdatusUser & Kika (Available Profiles: UpdatusUser & Kika)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files (x86)\Spotless Plan\Spotless Plan.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Users\Kika\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Kika\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Dropbox, Inc.) C:\Users\Kika\AppData\Roaming\Dropbox\bin\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\eye perform\bin\utileyeperform.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.PurBrowse64.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.BrowserAdapter.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.BrowserAdapter64.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.expext.exe
() C:\Program Files (x86)\eye perform\updateeyeperform.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2207848 2011-03-21] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831528 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kika\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kika\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [Dropbox Update] => C:\Users\Kika\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-23] (Dropbox, Inc.)
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8358680 2015-06-01] (Piriform Ltd)
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-05-15]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Kika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-06-23]
ShortcutTarget: Dropbox.lnk -> C:\Users\Kika\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {17E1D5B1-75A8-4D14-BF1B-8BE6F91DF441} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {1CA317BC-A9C5-4846-935A-EC059D0B3048} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {1D0753B8-3020-44EC-9195-F179527CA121} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {642339F8-00F3-4D50-AF35-01CFB2D3A835} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {9B8FD237-E2E0-4D41-97AF-360196A1BE8B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {AF5C8BCD-CC14-4342-A927-47AB24445517} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {DADED17B-AD94-4CC7-A461-C796EB87E29E} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {DBBB703C-1787-49AA-9ED7-E4D8AE2FE2F0} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {F044A561-7E6B-4A43-9848-5BD9F69AA635} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-05-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-05-13] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-05-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2014-09-09] (Sun Microsystems, Inc.)
BHO-x32: eye perform 1.0.0.7 -> {7768ecae-6b40-4398-bef1-db0a206f0009} -> C:\Program Files (x86)\eye perform\eyeperformbho.dll [2015-05-05] (eye perform)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-05-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2014-09-09] (Sun Microsystems, Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.154.198.1
Tcpip\..\Interfaces\{2839BEFA-CBCC-4DF2-BD81-73BF649FBC1D}: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{8839C36E-B74F-4944-89FC-A3215A3308EB}: [DhcpNameServer] 10.154.198.1
FireFox:
========
FF ProfilePath: C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.searchfix.info/?unqvl=63&idate=2015/06/05&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Homepage: hxxp://search.gboxapp.com/
FF Keyword.URL: hxxp://websearch.searchfix.info/?unqvl=63&idate=2015/06/05&l=1&q=
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_32 -> C:\Windows\SysWOW64\npdeployJava1.dll [2014-09-09] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2014-09-09] (Sun Microsystems, Inc.)
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2082789063-2545444791-1796617809-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kika\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\user.js [2015-06-07]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\searchplugins\WebSearch.xml [2015-06-05]
FF Extension: bestadblocker - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\08@X5.edu [2015-06-05]
FF Extension: SAVErExtEnsion - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\GlWT@3.edu [2015-07-22]
FF Extension: SAveLots - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\H@eomr.org [2015-06-23]
FF Extension: PriiceMinUUs - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\k@0YFHail.org [2015-06-05]
FF Extension: Seznam lištička - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-06-07]
FF Extension: eye perform 1.0.1 - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\{2ad7fb58-28ea-4906-8ea8-44317ff2d64f}.xpi [2015-06-07]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: No Name - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\extensions\bwkycugv_emexav@fzfzusnmghsnchprx.edu [not found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (BeFunky Photo Editor) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2014-05-16]
CHR Extension: (YouTube) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16]
CHR Extension: (Google Search) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16]
CHR Extension: (Pixlr-o-matic) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2014-05-16]
CHR Extension: (TiltShiftMaker) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjjofhgnhekhkccpcnnloagmdpafifeo [2014-05-16]
CHR Extension: (eye perform) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnbnmgbhcpolnoeejfphmhobapnicfpk [2015-07-22]
CHR Extension: (Webcam Toy) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-05-16]
CHR Extension: (Eiffel Tower Love Theme) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkjfjdpgppkaocjfapgnapbeinkieng [2014-06-02]
CHR Extension: (Google Wallet) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16]
CHR Extension: (My Maths Helper) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\olbfegcikohbecinkfiibmhhbmfblhoc [2015-07-16]
CHR Extension: (Gmail) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 8338240e; c:\Program Files (x86)\PragmaEdit\PragmaEdit.dll [1777152 2015-06-05] () [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [29696 2011-05-26] (Acer Incorporated) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
R2 Spotless Plan; C:\Program Files (x86)\Spotless Plan\Spotless Plan.exe [8016488 2015-07-08] () [File not signed] <==== ATTENTION
R2 Update eye perform; C:\Program Files (x86)\eye perform\updateeyeperform.exe [456432 2015-07-22] ()
R2 Util eye perform; C:\Program Files (x86)\eye perform\bin\utileyeperform.exe [456432 2015-07-22] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
S3 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R1 {027aeb7e-f8c3-4c10-be2c-627699fea100}w64; C:\Windows\System32\drivers\{027aeb7e-f8c3-4c10-be2c-627699fea100}w64.sys [48784 2015-07-10] (StdLib)
R1 {241c48c5-f3a9-4ff5-98b0-c41988c34fff}w64; C:\Windows\System32\drivers\{241c48c5-f3a9-4ff5-98b0-c41988c34fff}w64.sys [48784 2015-06-25] (StdLib)
R1 {2ad7fb58-28ea-4906-8ea8-44317ff2d64f}Gw64; C:\Windows\System32\drivers\{2ad7fb58-28ea-4906-8ea8-44317ff2d64f}Gw64.sys [48784 2015-06-06] (StdLib)
R1 {38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}Gw64; C:\Windows\System32\drivers\{38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}Gw64.sys [48784 2015-06-10] (StdLib)
R1 {38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}w64; C:\Windows\System32\drivers\{38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}w64.sys [48784 2015-06-12] (StdLib)
R1 {4572b88f-b0f6-490d-ac1d-566e27c62495}w64; C:\Windows\System32\drivers\{4572b88f-b0f6-490d-ac1d-566e27c62495}w64.sys [48784 2015-06-29] (StdLib)
R1 {5f18cc55-6d7f-4efe-a0fe-06573b260a1d}w64; C:\Windows\System32\drivers\{5f18cc55-6d7f-4efe-a0fe-06573b260a1d}w64.sys [48784 2015-06-16] (StdLib)
R1 {7188dc29-5fcb-46e6-baeb-fbd8be71d343}w64; C:\Windows\System32\drivers\{7188dc29-5fcb-46e6-baeb-fbd8be71d343}w64.sys [48784 2015-07-14] (StdLib)
R1 {7cd3bedc-d669-4e18-8d13-4e15866f5c72}w64; C:\Windows\System32\drivers\{7cd3bedc-d669-4e18-8d13-4e15866f5c72}w64.sys [48784 2015-06-13] (StdLib)
R1 {8b2ffd7e-1caa-4d9a-8204-31d2d7d49d76}Gw64; C:\Windows\System32\drivers\{8b2ffd7e-1caa-4d9a-8204-31d2d7d49d76}Gw64.sys [48784 2015-06-07] (StdLib)
R1 {972dc55c-c6c0-44f6-8b54-5599004975cf}w64; C:\Windows\System32\drivers\{972dc55c-c6c0-44f6-8b54-5599004975cf}w64.sys [48784 2015-07-17] (StdLib)
R1 {9c8cca4c-20fb-4af3-ac83-4f7cb79e9eef}w64; C:\Windows\System32\drivers\{9c8cca4c-20fb-4af3-ac83-4f7cb79e9eef}w64.sys [48784 2015-07-07] (StdLib)
R1 {a099f353-be27-4260-8532-0fab017d0e4f}w64; C:\Windows\System32\drivers\{a099f353-be27-4260-8532-0fab017d0e4f}w64.sys [48784 2015-07-07] (StdLib)
R1 {e808f110-c3bd-4b41-9d1e-f200058e16fe}w64; C:\Windows\System32\drivers\{e808f110-c3bd-4b41-9d1e-f200058e16fe}w64.sys [48784 2015-07-22] (StdLib)
R1 {fa79da02-3bd8-4e75-8e32-8cfb65ae6d40}w64; C:\Windows\System32\drivers\{fa79da02-3bd8-4e75-8e32-8cfb65ae6d40}w64.sys [48784 2015-06-22] (StdLib)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-22 17:13 - 2015-07-22 17:14 - 00028196 _____ C:\Users\Kika\Downloads\FRST.txt
2015-07-22 17:12 - 2015-07-22 17:13 - 00000000 ____D C:\FRST
2015-07-22 17:09 - 2015-07-22 17:10 - 02135552 _____ (Farbar) C:\Users\Kika\Downloads\FRST64.exe
2015-07-22 17:09 - 2015-07-22 17:09 - 00000000 _____ C:\Windows\setuperr.log
2015-07-22 17:09 - 2015-07-22 17:09 - 00000000 _____ C:\Windows\setupact.log
2015-07-22 16:31 - 2015-07-22 16:31 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-07-22 16:31 - 2015-07-22 16:31 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-22 16:31 - 2015-07-22 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-22 16:31 - 2015-07-22 16:31 - 00000000 ____D C:\Program Files\CCleaner
2015-07-22 16:30 - 2015-07-22 16:30 - 06565736 _____ (Piriform Ltd) C:\Users\Kika\Downloads\ccsetup507.exe
2015-07-22 15:25 - 2015-07-22 02:43 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{e808f110-c3bd-4b41-9d1e-f200058e16fe}w64.sys
2015-07-20 13:25 - 2015-07-20 13:45 - 367009792 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-2x13-cz-tit.avi
2015-07-20 12:27 - 2015-07-20 12:50 - 367005696 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-2x12-cz-tit.avi
2015-07-20 12:27 - 2015-07-20 12:27 - 00044790 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-S02E10-cze.srt
2015-07-20 11:32 - 2015-07-20 11:54 - 367013888 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-2x11-s-titulkama_arc.avi
2015-07-20 10:39 - 2015-07-20 11:00 - 367093760 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-S02E10.avi
2015-07-17 23:02 - 2015-07-17 13:44 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{972dc55c-c6c0-44f6-8b54-5599004975cf}w64.sys
2015-07-16 22:33 - 2015-07-22 14:51 - 00000000 ____D C:\Program Files (x86)\SaveuroExtensiOnn
2015-07-16 22:33 - 2015-07-16 22:34 - 00000000 ____D C:\Program Files (x86)\SAVErExtEnsion
2015-07-16 22:32 - 2015-07-16 22:32 - 00000000 ____D C:\Program Files (x86)\My Maths Helper
2015-07-15 10:16 - 2015-07-14 17:45 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{7188dc29-5fcb-46e6-baeb-fbd8be71d343}w64.sys
2015-07-13 14:57 - 2015-07-13 14:57 - 00000000 ____D C:\Users\Kika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-07-11 11:15 - 2015-07-10 22:49 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{027aeb7e-f8c3-4c10-be2c-627699fea100}w64.sys
2015-07-08 20:41 - 2015-07-08 20:41 - 00000000 ____D C:\Program Files (x86)\Spotless Plan
2015-07-08 10:41 - 2015-07-07 20:38 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{a099f353-be27-4260-8532-0fab017d0e4f}w64.sys
2015-07-07 20:30 - 2015-07-07 07:40 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{9c8cca4c-20fb-4af3-ac83-4f7cb79e9eef}w64.sys
2015-06-29 18:40 - 2015-06-29 19:21 - 742494208 _____ C:\Users\Kika\Downloads\Teď a tady (cz tit).avi
2015-06-29 15:38 - 2015-06-29 04:38 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{4572b88f-b0f6-490d-ac1d-566e27c62495}w64.sys
2015-06-26 10:49 - 2015-06-25 22:41 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{241c48c5-f3a9-4ff5-98b0-c41988c34fff}w64.sys
2015-06-24 11:04 - 2015-06-24 11:45 - 733820928 _____ C:\Users\Kika\Downloads\Lóve-SK-film-(2011)-NOVINKA.avi
2015-06-23 12:49 - 2015-07-22 17:00 - 00000914 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001UA.job
2015-06-23 12:49 - 2015-07-20 21:29 - 00000862 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001Core.job
2015-06-23 12:49 - 2015-07-19 19:55 - 00003882 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001UA
2015-06-23 12:49 - 2015-07-19 19:55 - 00003486 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001Core
2015-06-23 12:49 - 2015-06-23 12:49 - 00000000 ____D C:\Users\Kika\AppData\Local\Dropbox
2015-06-23 12:49 - 2015-06-23 12:49 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-23 12:47 - 2015-06-22 16:34 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{fa79da02-3bd8-4e75-8e32-8cfb65ae6d40}w64.sys
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-22 17:05 - 2015-06-07 08:02 - 00000000 ____D C:\Program Files (x86)\eye perform
2015-07-22 16:54 - 2014-05-15 10:11 - 01876192 _____ C:\Windows\WindowsUpdate.log
2015-07-22 16:46 - 2014-06-30 13:22 - 00000000 ____D C:\Users\Kika\AppData\Roaming\uTorrent
2015-07-22 16:45 - 2014-11-07 12:47 - 00000000 ____D C:\Windows\Minidump
2015-07-22 16:45 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2015-07-22 16:05 - 2009-07-14 04:34 - 00000612 _____ C:\Windows\win.ini
2015-07-22 15:36 - 2014-11-17 20:08 - 00000000 ___RD C:\Users\Kika\Dropbox
2015-07-22 15:36 - 2014-11-17 20:03 - 00000000 ____D C:\Users\Kika\AppData\Roaming\Dropbox
2015-07-22 15:31 - 2015-06-10 13:42 - 00000024 _____ C:\Users\Kika\AppData\Roaming\appdataFr25.bin
2015-07-22 15:29 - 2009-07-14 06:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-22 15:29 - 2009-07-14 06:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-22 15:16 - 2014-05-15 20:04 - 00670582 _____ C:\Windows\system32\perfh005.dat
2015-07-22 15:16 - 2014-05-15 20:04 - 00142162 _____ C:\Windows\system32\perfc005.dat
2015-07-22 15:16 - 2009-07-14 07:13 - 01583214 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-22 14:54 - 2014-09-14 23:09 - 00000000 ____D C:\Users\Kika\AppData\Roaming\Seznam.cz
2015-07-22 14:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-20 19:42 - 2015-06-05 19:42 - 00000346 _____ C:\Windows\Tasks\Bidaily Synchronize Task[973b].job
2015-07-20 16:08 - 2014-10-11 15:19 - 00000000 ____D C:\Users\Kika\AppData\Roaming\vlc
2015-07-19 16:35 - 2015-06-13 08:39 - 00000000 ____D C:\Program Files (x86)\SaveuLots
2015-07-19 16:35 - 2015-06-13 08:39 - 00000000 ____D C:\Program Files (x86)\SaveLotss
2015-07-19 16:33 - 2014-12-20 16:17 - 00000000 __SHD C:\Users\Kika\AppData\Local\EmieBrowserModeList
2015-07-19 16:33 - 2014-07-25 23:16 - 00000000 __SHD C:\Users\Kika\AppData\Local\EmieUserList
2015-07-19 16:33 - 2014-07-25 23:16 - 00000000 __SHD C:\Users\Kika\AppData\Local\EmieSiteList
2015-07-16 22:34 - 2015-06-05 19:44 - 00000000 ____D C:\ProgramData\8714785319342001401
2015-07-14 21:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-26 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
==================== Files in the root of some directories =======
2015-06-12 18:02 - 2015-06-12 18:02 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-06-10 13:42 - 2015-07-22 15:31 - 0000024 _____ () C:\Users\Kika\AppData\Roaming\appdataFr25.bin
2014-05-15 10:37 - 2014-05-15 10:39 - 0015245 _____ () C:\ProgramData\ArcadeDeluxe5.log
2014-05-15 12:10 - 2014-05-15 12:11 - 0000032 _____ () C:\ProgramData\PS.log
Some files in TEMP:
====================
C:\Users\Kika\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplcdfwf.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-22 16:01
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015
Ran by Kika (administrator) on KIKA-PC on 22-07-2015 17:13:06
Running from C:\Users\Kika\Downloads
Loaded Profiles: UpdatusUser & Kika (Available Profiles: UpdatusUser & Kika)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files (x86)\Spotless Plan\Spotless Plan.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Users\Kika\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Kika\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Dropbox, Inc.) C:\Users\Kika\AppData\Roaming\Dropbox\bin\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\eye perform\bin\utileyeperform.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.PurBrowse64.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.BrowserAdapter.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.BrowserAdapter64.exe
() C:\Program Files (x86)\eye perform\bin\eyeperform.expext.exe
() C:\Program Files (x86)\eye perform\updateeyeperform.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2207848 2011-03-21] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831528 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kika\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kika\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [Dropbox Update] => C:\Users\Kika\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-23] (Dropbox, Inc.)
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8358680 2015-06-01] (Piriform Ltd)
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-05-15]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Kika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-06-23]
ShortcutTarget: Dropbox.lnk -> C:\Users\Kika\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kika\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-06-26] (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-21-2082789063-2545444791-1796617809-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {17E1D5B1-75A8-4D14-BF1B-8BE6F91DF441} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {1CA317BC-A9C5-4846-935A-EC059D0B3048} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {1D0753B8-3020-44EC-9195-F179527CA121} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {642339F8-00F3-4D50-AF35-01CFB2D3A835} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {9B8FD237-E2E0-4D41-97AF-360196A1BE8B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {AF5C8BCD-CC14-4342-A927-47AB24445517} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {DADED17B-AD94-4CC7-A461-C796EB87E29E} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {DBBB703C-1787-49AA-9ED7-E4D8AE2FE2F0} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKU\S-1-5-21-2082789063-2545444791-1796617809-1001 -> {F044A561-7E6B-4A43-9848-5BD9F69AA635} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-05-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-05-13] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-05-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2014-09-09] (Sun Microsystems, Inc.)
BHO-x32: eye perform 1.0.0.7 -> {7768ecae-6b40-4398-bef1-db0a206f0009} -> C:\Program Files (x86)\eye perform\eyeperformbho.dll [2015-05-05] (eye perform)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-05-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2014-09-09] (Sun Microsystems, Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.154.198.1
Tcpip\..\Interfaces\{2839BEFA-CBCC-4DF2-BD81-73BF649FBC1D}: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{8839C36E-B74F-4944-89FC-A3215A3308EB}: [DhcpNameServer] 10.154.198.1
FireFox:
========
FF ProfilePath: C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.searchfix.info/?unqvl=63&idate=2015/06/05&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Homepage: hxxp://search.gboxapp.com/
FF Keyword.URL: hxxp://websearch.searchfix.info/?unqvl=63&idate=2015/06/05&l=1&q=
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_32 -> C:\Windows\SysWOW64\npdeployJava1.dll [2014-09-09] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2014-09-09] (Sun Microsystems, Inc.)
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2082789063-2545444791-1796617809-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kika\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\user.js [2015-06-07]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\searchplugins\WebSearch.xml [2015-06-05]
FF Extension: bestadblocker - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\08@X5.edu [2015-06-05]
FF Extension: SAVErExtEnsion - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\GlWT@3.edu [2015-07-22]
FF Extension: SAveLots - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\H@eomr.org [2015-06-23]
FF Extension: PriiceMinUUs - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\k@0YFHail.org [2015-06-05]
FF Extension: Seznam lištička - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-06-07]
FF Extension: eye perform 1.0.1 - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\Extensions\{2ad7fb58-28ea-4906-8ea8-44317ff2d64f}.xpi [2015-06-07]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: No Name - C:\Users\Kika\AppData\Roaming\Mozilla\Firefox\Profiles\3xnwlwsm.default\extensions\bwkycugv_emexav@fzfzusnmghsnchprx.edu [not found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (BeFunky Photo Editor) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2014-05-16]
CHR Extension: (YouTube) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16]
CHR Extension: (Google Search) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16]
CHR Extension: (Pixlr-o-matic) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2014-05-16]
CHR Extension: (TiltShiftMaker) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjjofhgnhekhkccpcnnloagmdpafifeo [2014-05-16]
CHR Extension: (eye perform) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnbnmgbhcpolnoeejfphmhobapnicfpk [2015-07-22]
CHR Extension: (Webcam Toy) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-05-16]
CHR Extension: (Eiffel Tower Love Theme) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkjfjdpgppkaocjfapgnapbeinkieng [2014-06-02]
CHR Extension: (Google Wallet) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16]
CHR Extension: (My Maths Helper) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\olbfegcikohbecinkfiibmhhbmfblhoc [2015-07-16]
CHR Extension: (Gmail) - C:\Users\Kika\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 8338240e; c:\Program Files (x86)\PragmaEdit\PragmaEdit.dll [1777152 2015-06-05] () [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [29696 2011-05-26] (Acer Incorporated) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
R2 Spotless Plan; C:\Program Files (x86)\Spotless Plan\Spotless Plan.exe [8016488 2015-07-08] () [File not signed] <==== ATTENTION
R2 Update eye perform; C:\Program Files (x86)\eye perform\updateeyeperform.exe [456432 2015-07-22] ()
R2 Util eye perform; C:\Program Files (x86)\eye perform\bin\utileyeperform.exe [456432 2015-07-22] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
S3 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R1 {027aeb7e-f8c3-4c10-be2c-627699fea100}w64; C:\Windows\System32\drivers\{027aeb7e-f8c3-4c10-be2c-627699fea100}w64.sys [48784 2015-07-10] (StdLib)
R1 {241c48c5-f3a9-4ff5-98b0-c41988c34fff}w64; C:\Windows\System32\drivers\{241c48c5-f3a9-4ff5-98b0-c41988c34fff}w64.sys [48784 2015-06-25] (StdLib)
R1 {2ad7fb58-28ea-4906-8ea8-44317ff2d64f}Gw64; C:\Windows\System32\drivers\{2ad7fb58-28ea-4906-8ea8-44317ff2d64f}Gw64.sys [48784 2015-06-06] (StdLib)
R1 {38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}Gw64; C:\Windows\System32\drivers\{38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}Gw64.sys [48784 2015-06-10] (StdLib)
R1 {38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}w64; C:\Windows\System32\drivers\{38f9a7a9-76b1-4da2-9a2f-bb178cdbe11e}w64.sys [48784 2015-06-12] (StdLib)
R1 {4572b88f-b0f6-490d-ac1d-566e27c62495}w64; C:\Windows\System32\drivers\{4572b88f-b0f6-490d-ac1d-566e27c62495}w64.sys [48784 2015-06-29] (StdLib)
R1 {5f18cc55-6d7f-4efe-a0fe-06573b260a1d}w64; C:\Windows\System32\drivers\{5f18cc55-6d7f-4efe-a0fe-06573b260a1d}w64.sys [48784 2015-06-16] (StdLib)
R1 {7188dc29-5fcb-46e6-baeb-fbd8be71d343}w64; C:\Windows\System32\drivers\{7188dc29-5fcb-46e6-baeb-fbd8be71d343}w64.sys [48784 2015-07-14] (StdLib)
R1 {7cd3bedc-d669-4e18-8d13-4e15866f5c72}w64; C:\Windows\System32\drivers\{7cd3bedc-d669-4e18-8d13-4e15866f5c72}w64.sys [48784 2015-06-13] (StdLib)
R1 {8b2ffd7e-1caa-4d9a-8204-31d2d7d49d76}Gw64; C:\Windows\System32\drivers\{8b2ffd7e-1caa-4d9a-8204-31d2d7d49d76}Gw64.sys [48784 2015-06-07] (StdLib)
R1 {972dc55c-c6c0-44f6-8b54-5599004975cf}w64; C:\Windows\System32\drivers\{972dc55c-c6c0-44f6-8b54-5599004975cf}w64.sys [48784 2015-07-17] (StdLib)
R1 {9c8cca4c-20fb-4af3-ac83-4f7cb79e9eef}w64; C:\Windows\System32\drivers\{9c8cca4c-20fb-4af3-ac83-4f7cb79e9eef}w64.sys [48784 2015-07-07] (StdLib)
R1 {a099f353-be27-4260-8532-0fab017d0e4f}w64; C:\Windows\System32\drivers\{a099f353-be27-4260-8532-0fab017d0e4f}w64.sys [48784 2015-07-07] (StdLib)
R1 {e808f110-c3bd-4b41-9d1e-f200058e16fe}w64; C:\Windows\System32\drivers\{e808f110-c3bd-4b41-9d1e-f200058e16fe}w64.sys [48784 2015-07-22] (StdLib)
R1 {fa79da02-3bd8-4e75-8e32-8cfb65ae6d40}w64; C:\Windows\System32\drivers\{fa79da02-3bd8-4e75-8e32-8cfb65ae6d40}w64.sys [48784 2015-06-22] (StdLib)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-22 17:13 - 2015-07-22 17:14 - 00028196 _____ C:\Users\Kika\Downloads\FRST.txt
2015-07-22 17:12 - 2015-07-22 17:13 - 00000000 ____D C:\FRST
2015-07-22 17:09 - 2015-07-22 17:10 - 02135552 _____ (Farbar) C:\Users\Kika\Downloads\FRST64.exe
2015-07-22 17:09 - 2015-07-22 17:09 - 00000000 _____ C:\Windows\setuperr.log
2015-07-22 17:09 - 2015-07-22 17:09 - 00000000 _____ C:\Windows\setupact.log
2015-07-22 16:31 - 2015-07-22 16:31 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-07-22 16:31 - 2015-07-22 16:31 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-22 16:31 - 2015-07-22 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-22 16:31 - 2015-07-22 16:31 - 00000000 ____D C:\Program Files\CCleaner
2015-07-22 16:30 - 2015-07-22 16:30 - 06565736 _____ (Piriform Ltd) C:\Users\Kika\Downloads\ccsetup507.exe
2015-07-22 15:25 - 2015-07-22 02:43 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{e808f110-c3bd-4b41-9d1e-f200058e16fe}w64.sys
2015-07-20 13:25 - 2015-07-20 13:45 - 367009792 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-2x13-cz-tit.avi
2015-07-20 12:27 - 2015-07-20 12:50 - 367005696 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-2x12-cz-tit.avi
2015-07-20 12:27 - 2015-07-20 12:27 - 00044790 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-S02E10-cze.srt
2015-07-20 11:32 - 2015-07-20 11:54 - 367013888 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-2x11-s-titulkama_arc.avi
2015-07-20 10:39 - 2015-07-20 11:00 - 367093760 _____ C:\Users\Kika\Downloads\The-Vampire-Diaries-S02E10.avi
2015-07-17 23:02 - 2015-07-17 13:44 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{972dc55c-c6c0-44f6-8b54-5599004975cf}w64.sys
2015-07-16 22:33 - 2015-07-22 14:51 - 00000000 ____D C:\Program Files (x86)\SaveuroExtensiOnn
2015-07-16 22:33 - 2015-07-16 22:34 - 00000000 ____D C:\Program Files (x86)\SAVErExtEnsion
2015-07-16 22:32 - 2015-07-16 22:32 - 00000000 ____D C:\Program Files (x86)\My Maths Helper
2015-07-15 10:16 - 2015-07-14 17:45 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{7188dc29-5fcb-46e6-baeb-fbd8be71d343}w64.sys
2015-07-13 14:57 - 2015-07-13 14:57 - 00000000 ____D C:\Users\Kika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-07-11 11:15 - 2015-07-10 22:49 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{027aeb7e-f8c3-4c10-be2c-627699fea100}w64.sys
2015-07-08 20:41 - 2015-07-08 20:41 - 00000000 ____D C:\Program Files (x86)\Spotless Plan
2015-07-08 10:41 - 2015-07-07 20:38 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{a099f353-be27-4260-8532-0fab017d0e4f}w64.sys
2015-07-07 20:30 - 2015-07-07 07:40 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{9c8cca4c-20fb-4af3-ac83-4f7cb79e9eef}w64.sys
2015-06-29 18:40 - 2015-06-29 19:21 - 742494208 _____ C:\Users\Kika\Downloads\Teď a tady (cz tit).avi
2015-06-29 15:38 - 2015-06-29 04:38 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{4572b88f-b0f6-490d-ac1d-566e27c62495}w64.sys
2015-06-26 10:49 - 2015-06-25 22:41 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{241c48c5-f3a9-4ff5-98b0-c41988c34fff}w64.sys
2015-06-24 11:04 - 2015-06-24 11:45 - 733820928 _____ C:\Users\Kika\Downloads\Lóve-SK-film-(2011)-NOVINKA.avi
2015-06-23 12:49 - 2015-07-22 17:00 - 00000914 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001UA.job
2015-06-23 12:49 - 2015-07-20 21:29 - 00000862 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001Core.job
2015-06-23 12:49 - 2015-07-19 19:55 - 00003882 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001UA
2015-06-23 12:49 - 2015-07-19 19:55 - 00003486 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2082789063-2545444791-1796617809-1001Core
2015-06-23 12:49 - 2015-06-23 12:49 - 00000000 ____D C:\Users\Kika\AppData\Local\Dropbox
2015-06-23 12:49 - 2015-06-23 12:49 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-23 12:47 - 2015-06-22 16:34 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{fa79da02-3bd8-4e75-8e32-8cfb65ae6d40}w64.sys
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-22 17:05 - 2015-06-07 08:02 - 00000000 ____D C:\Program Files (x86)\eye perform
2015-07-22 16:54 - 2014-05-15 10:11 - 01876192 _____ C:\Windows\WindowsUpdate.log
2015-07-22 16:46 - 2014-06-30 13:22 - 00000000 ____D C:\Users\Kika\AppData\Roaming\uTorrent
2015-07-22 16:45 - 2014-11-07 12:47 - 00000000 ____D C:\Windows\Minidump
2015-07-22 16:45 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2015-07-22 16:05 - 2009-07-14 04:34 - 00000612 _____ C:\Windows\win.ini
2015-07-22 15:36 - 2014-11-17 20:08 - 00000000 ___RD C:\Users\Kika\Dropbox
2015-07-22 15:36 - 2014-11-17 20:03 - 00000000 ____D C:\Users\Kika\AppData\Roaming\Dropbox
2015-07-22 15:31 - 2015-06-10 13:42 - 00000024 _____ C:\Users\Kika\AppData\Roaming\appdataFr25.bin
2015-07-22 15:29 - 2009-07-14 06:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-22 15:29 - 2009-07-14 06:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-22 15:16 - 2014-05-15 20:04 - 00670582 _____ C:\Windows\system32\perfh005.dat
2015-07-22 15:16 - 2014-05-15 20:04 - 00142162 _____ C:\Windows\system32\perfc005.dat
2015-07-22 15:16 - 2009-07-14 07:13 - 01583214 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-22 14:54 - 2014-09-14 23:09 - 00000000 ____D C:\Users\Kika\AppData\Roaming\Seznam.cz
2015-07-22 14:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-20 19:42 - 2015-06-05 19:42 - 00000346 _____ C:\Windows\Tasks\Bidaily Synchronize Task[973b].job
2015-07-20 16:08 - 2014-10-11 15:19 - 00000000 ____D C:\Users\Kika\AppData\Roaming\vlc
2015-07-19 16:35 - 2015-06-13 08:39 - 00000000 ____D C:\Program Files (x86)\SaveuLots
2015-07-19 16:35 - 2015-06-13 08:39 - 00000000 ____D C:\Program Files (x86)\SaveLotss
2015-07-19 16:33 - 2014-12-20 16:17 - 00000000 __SHD C:\Users\Kika\AppData\Local\EmieBrowserModeList
2015-07-19 16:33 - 2014-07-25 23:16 - 00000000 __SHD C:\Users\Kika\AppData\Local\EmieUserList
2015-07-19 16:33 - 2014-07-25 23:16 - 00000000 __SHD C:\Users\Kika\AppData\Local\EmieSiteList
2015-07-16 22:34 - 2015-06-05 19:44 - 00000000 ____D C:\ProgramData\8714785319342001401
2015-07-14 21:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-26 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
==================== Files in the root of some directories =======
2015-06-12 18:02 - 2015-06-12 18:02 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-06-10 13:42 - 2015-07-22 15:31 - 0000024 _____ () C:\Users\Kika\AppData\Roaming\appdataFr25.bin
2014-05-15 10:37 - 2014-05-15 10:39 - 0015245 _____ () C:\ProgramData\ArcadeDeluxe5.log
2014-05-15 12:10 - 2014-05-15 12:11 - 0000032 _____ () C:\ProgramData\PS.log
Some files in TEMP:
====================
C:\Users\Kika\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplcdfwf.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-22 16:01
==================== End of log ============================