Preventivní kontrola logu
Napsal: 28 črc 2015 08:51
Prosím o preventivní kontrolu logu
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:26-07-2015
Ran by Aleš (administrator) on HP-PAVILLION (28-07-2015 01:36:24)
Running from C:\Users\Aleš\Desktop
Loaded Profiles: Aleš (Available Profiles: Aleš)
Platform: Windows 8.1 Pro (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apache Software Foundation) C:\dev\Apache24\bin\httpd.exe
(Comodo) C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Apache Software Foundation) C:\dev\Apache24\bin\httpd.exe
() C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\vc10tray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Spotify Ltd) C:\Users\Aleš\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(forum.viry.cz) C:\Users\Aleš\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-26] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [VC10Player] => C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe [406896 2015-07-16] (H+H Software GmbH)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [GoogleChromeAutoLaunch_826B0B3657125D697BA295572B80DA34] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-14] (Google Inc.)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2895552 2015-07-25] (Valve Corporation)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3097912 2015-07-17] (Nota Inc.)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272840 2015-07-03] (Microsoft Corporation)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3632112 2015-07-15] (Electronic Arts)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-07-15] (Disc Soft Ltd)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Spotify Web Helper] => C:\Users\Aleš\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2008632 2015-07-22] (Spotify Ltd)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Spotify] => C:\Users\Aleš\AppData\Roaming\Spotify\Spotify.exe [7334968 2015-07-22] (Spotify Ltd)
Startup: C:\Users\Aleš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 4.4.lnk [2015-07-01]
ShortcutTarget: LibreOffice 4.4.lnk -> C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-06-30]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-28] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-28] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A9D5C91E-E0A1-4DC1-9D2A-2C2426257D25}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{B749F50C-A0DF-430A-9122-56A1F6889704}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{B749F50C-A0DF-430A-9122-56A1F6889704}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Aleš\AppData\Roaming\Mozilla\Firefox\Profiles\dAcBXjNB.default
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-28] (Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-02] (Adobe Systems)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-02] (Adobe Systems)
FF Extension: Avira Browser Safety - C:\Users\Aleš\AppData\Roaming\Mozilla\Firefox\Profiles\dAcBXjNB.default\Extensions\abs@avira.com [2015-06-30]
Chrome:
=======
CHR Profile: C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-27]
CHR Extension: (Hitbox Emotes) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\afnmabaohnpejlfefcllmiahdgkclckf [2015-06-27]
CHR Extension: (BetterTTV) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-06-27]
CHR Extension: (Hitbox Live!) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnogebjhegkdafjdmnildbdocoobbnh [2015-06-27]
CHR Extension: (Google Docs) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-27]
CHR Extension: (Google Drive) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-27]
CHR Extension: (YouTube) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-27]
CHR Extension: (Adblock for Youtube™) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2015-06-27]
CHR Extension: (Google Search) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-27]
CHR Extension: (Tampermonkey) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2015-06-27]
CHR Extension: (Lounge Assistant) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\enjonnlehciedbcidabdglnnihcncbml [2015-06-27]
CHR Extension: (Google Play Music) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-06-27]
CHR Extension: (Google Sheets) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-27]
CHR Extension: (Avira SafeSearch) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffalmjohbhdhlkajphgkhloccibhmoog [2015-06-30]
CHR Extension: (Avira Browser Safety) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-06-30]
CHR Extension: (AdBlock) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-06-27]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-06-27]
CHR Extension: (CSGO Lounge Bot status indicator) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\inakkfgnoajfhlnlcknnllnnibejhocd [2015-06-27]
CHR Extension: (ReChat for Twitch™) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipplilmaapjjklilmmaccfemdmhkoacd [2015-06-27]
CHR Extension: (Auto HD For YouTube™) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2015-06-27]
CHR Extension: (Window Close Protector) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnpifgapnmpninomacbhdlconlpikdai [2015-06-27]
CHR Extension: (Twitch Now) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2015-06-27]
CHR Extension: (Google Wallet) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-27]
CHR Extension: (Show Apps in new tab) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohbdifokmdgjcbbeobglcbaifinhfip [2015-06-27]
CHR Extension: (Gmail) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-27]
CHR Extension: (Twitch Giveaways) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd [2015-06-27]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112 2015-06-09] (Adobe Systems Incorporated)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apache24_php56; C:\dev\Apache24\bin\httpd.exe [20992 2015-06-28] (Apache Software Foundation) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2015-07-01] (Microsoft Corporation)
R2 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [1995448 2015-06-30] (Comodo)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-06-30] (Comodo Security Solutions, Inc.)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5541960 2015-06-05] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-06-05] (COMODO)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-07-15] (Disc Soft Ltd)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 MySQL56; C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe [13057024 2015-05-05] () [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2004488 2015-07-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-07-22] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-10-16] (Realtek Semiconductor)
R2 VC10SecS; C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe [147312 2015-07-16] (H+H Software GmbH)
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-07-02] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2015-06-30] (Microsoft Corporation)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2014-06-26] (Windows (R) Win 7 DDK provider)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20672 2015-06-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [820928 2015-06-05] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [35056 2015-06-05] (COMODO)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-07-16] (Disc Soft Ltd)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [126696 2015-06-05] (COMODO)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [290008 2013-07-05] (Realtek Semiconductor Corp.)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204936 2014-02-12] (Ralink Technology, Corp.)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2015-07-01] (Microsoft Corporation)
R1 vdrv1000; C:\Windows\System32\drivers\vdrv1000.sys [226080 2015-07-16] (H+H Software GmbH)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-07-02] (Microsoft Corporation)
S3 HH10Help.sys; \??\C:\Windows\system32\drivers\HH10Help.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-28 01:36 - 2015-07-28 01:36 - 00020142 _____ C:\Users\Aleš\Desktop\FRST.txt
2015-07-28 00:51 - 2015-07-28 01:36 - 00000000 ____D C:\FRST
2015-07-28 00:51 - 2015-07-28 00:51 - 00112640 _____ (forum.viry.cz) C:\Users\Aleš\Desktop\FRSTLauncher.exe
2015-07-28 00:49 - 2015-07-28 00:49 - 02146816 _____ (Farbar) C:\Users\Aleš\Desktop\FRST64.exe
2015-07-25 17:32 - 2015-07-25 17:32 - 00001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk
2015-07-25 17:01 - 2015-07-25 17:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-25 16:56 - 2015-07-25 16:56 - 00001245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2015-07-25 16:56 - 2015-07-25 16:56 - 00001233 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2015-07-23 18:13 - 2015-06-29 08:31 - 00000717 _____ C:\Users\Aleš\Documents\train.cfg
2015-07-23 15:19 - 2015-07-23 15:19 - 00001205 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
2015-07-23 15:19 - 2015-07-23 15:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
2015-07-23 15:02 - 2015-07-23 15:57 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2015-07-23 14:51 - 2015-07-23 15:02 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2015-07-23 14:51 - 2015-07-23 14:51 - 00001197 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2015-07-23 14:51 - 2015-07-23 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2015-07-23 04:02 - 2015-07-28 00:59 - 00000000 ____D C:\Users\Aleš\AppData\Local\Battle.net
2015-07-23 04:02 - 2015-07-23 14:51 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Battle.net
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\Users\Aleš\AppData\Local\Blizzard Entertainment
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-07-23 04:01 - 2015-07-23 04:01 - 00000000 ____D C:\ProgramData\Battle.net
2015-07-22 22:54 - 2015-07-26 01:00 - 00000000 ____D C:\Users\Aleš\AppData\Local\Spotify
2015-07-22 22:54 - 2015-07-22 23:52 - 00002043 _____ C:\Users\Aleš\Desktop\Spotify.lnk
2015-07-22 22:54 - 2015-07-22 22:54 - 00001836 _____ C:\Users\Aleš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-07-22 22:53 - 2015-07-26 00:57 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Spotify
2015-07-22 19:19 - 2015-07-22 19:19 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Wargaming.net
2015-07-22 16:03 - 2015-07-22 16:03 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks
2015-07-22 03:59 - 2015-07-22 04:06 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2015-07-22 03:59 - 2015-07-22 03:59 - 00000000 ____D C:\Users\Aleš\AppData\Local\PunkBuster
2015-07-22 02:52 - 2015-07-22 02:52 - 00000000 ____D C:\Users\Aleš\AppData\Local\CEF
2015-07-21 19:49 - 2015-07-21 19:49 - 615295068 _____ C:\Windows\MEMORY.DMP
2015-07-21 19:49 - 2015-07-21 19:49 - 00280856 _____ C:\Windows\Minidump\072115-30625-01.dmp
2015-07-21 19:49 - 2015-07-21 19:49 - 00000000 ____D C:\Windows\Minidump
2015-07-21 10:33 - 2015-07-21 10:33 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-21 10:33 - 2015-07-21 10:33 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-21 10:33 - 2015-07-21 10:33 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-21 10:33 - 2015-07-21 10:33 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-21 02:41 - 2015-07-21 02:41 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:26-07-2015
Ran by Aleš (administrator) on HP-PAVILLION (28-07-2015 01:36:24)
Running from C:\Users\Aleš\Desktop
Loaded Profiles: Aleš (Available Profiles: Aleš)
Platform: Windows 8.1 Pro (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apache Software Foundation) C:\dev\Apache24\bin\httpd.exe
(Comodo) C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Apache Software Foundation) C:\dev\Apache24\bin\httpd.exe
() C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\vc10tray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Spotify Ltd) C:\Users\Aleš\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(forum.viry.cz) C:\Users\Aleš\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-26] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [VC10Player] => C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe [406896 2015-07-16] (H+H Software GmbH)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [GoogleChromeAutoLaunch_826B0B3657125D697BA295572B80DA34] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-14] (Google Inc.)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2895552 2015-07-25] (Valve Corporation)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3097912 2015-07-17] (Nota Inc.)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272840 2015-07-03] (Microsoft Corporation)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3632112 2015-07-15] (Electronic Arts)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-07-15] (Disc Soft Ltd)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Spotify Web Helper] => C:\Users\Aleš\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2008632 2015-07-22] (Spotify Ltd)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\...\Run: [Spotify] => C:\Users\Aleš\AppData\Roaming\Spotify\Spotify.exe [7334968 2015-07-22] (Spotify Ltd)
Startup: C:\Users\Aleš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 4.4.lnk [2015-07-01]
ShortcutTarget: LibreOffice 4.4.lnk -> C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-06-30]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2141545367-3452963406-3658162624-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-28] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-28] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A9D5C91E-E0A1-4DC1-9D2A-2C2426257D25}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{B749F50C-A0DF-430A-9122-56A1F6889704}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{B749F50C-A0DF-430A-9122-56A1F6889704}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Aleš\AppData\Roaming\Mozilla\Firefox\Profiles\dAcBXjNB.default
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-28] (Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-02] (Adobe Systems)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-02] (Adobe Systems)
FF Extension: Avira Browser Safety - C:\Users\Aleš\AppData\Roaming\Mozilla\Firefox\Profiles\dAcBXjNB.default\Extensions\abs@avira.com [2015-06-30]
Chrome:
=======
CHR Profile: C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-27]
CHR Extension: (Hitbox Emotes) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\afnmabaohnpejlfefcllmiahdgkclckf [2015-06-27]
CHR Extension: (BetterTTV) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-06-27]
CHR Extension: (Hitbox Live!) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnogebjhegkdafjdmnildbdocoobbnh [2015-06-27]
CHR Extension: (Google Docs) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-27]
CHR Extension: (Google Drive) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-27]
CHR Extension: (YouTube) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-27]
CHR Extension: (Adblock for Youtube™) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2015-06-27]
CHR Extension: (Google Search) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-27]
CHR Extension: (Tampermonkey) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2015-06-27]
CHR Extension: (Lounge Assistant) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\enjonnlehciedbcidabdglnnihcncbml [2015-06-27]
CHR Extension: (Google Play Music) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-06-27]
CHR Extension: (Google Sheets) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-27]
CHR Extension: (Avira SafeSearch) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffalmjohbhdhlkajphgkhloccibhmoog [2015-06-30]
CHR Extension: (Avira Browser Safety) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-06-30]
CHR Extension: (AdBlock) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-06-27]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-06-27]
CHR Extension: (CSGO Lounge Bot status indicator) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\inakkfgnoajfhlnlcknnllnnibejhocd [2015-06-27]
CHR Extension: (ReChat for Twitch™) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipplilmaapjjklilmmaccfemdmhkoacd [2015-06-27]
CHR Extension: (Auto HD For YouTube™) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2015-06-27]
CHR Extension: (Window Close Protector) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnpifgapnmpninomacbhdlconlpikdai [2015-06-27]
CHR Extension: (Twitch Now) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2015-06-27]
CHR Extension: (Google Wallet) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-27]
CHR Extension: (Show Apps in new tab) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohbdifokmdgjcbbeobglcbaifinhfip [2015-06-27]
CHR Extension: (Gmail) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-27]
CHR Extension: (Twitch Giveaways) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd [2015-06-27]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112 2015-06-09] (Adobe Systems Incorporated)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apache24_php56; C:\dev\Apache24\bin\httpd.exe [20992 2015-06-28] (Apache Software Foundation) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2015-07-01] (Microsoft Corporation)
R2 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [1995448 2015-06-30] (Comodo)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-06-30] (Comodo Security Solutions, Inc.)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5541960 2015-06-05] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-06-05] (COMODO)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-07-15] (Disc Soft Ltd)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 MySQL56; C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe [13057024 2015-05-05] () [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2004488 2015-07-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-07-22] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-10-16] (Realtek Semiconductor)
R2 VC10SecS; C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe [147312 2015-07-16] (H+H Software GmbH)
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-07-02] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2015-06-30] (Microsoft Corporation)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2014-06-26] (Windows (R) Win 7 DDK provider)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20672 2015-06-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [820928 2015-06-05] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [35056 2015-06-05] (COMODO)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-07-16] (Disc Soft Ltd)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [126696 2015-06-05] (COMODO)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [290008 2013-07-05] (Realtek Semiconductor Corp.)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204936 2014-02-12] (Ralink Technology, Corp.)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2015-07-01] (Microsoft Corporation)
R1 vdrv1000; C:\Windows\System32\drivers\vdrv1000.sys [226080 2015-07-16] (H+H Software GmbH)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-07-02] (Microsoft Corporation)
S3 HH10Help.sys; \??\C:\Windows\system32\drivers\HH10Help.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-28 01:36 - 2015-07-28 01:36 - 00020142 _____ C:\Users\Aleš\Desktop\FRST.txt
2015-07-28 00:51 - 2015-07-28 01:36 - 00000000 ____D C:\FRST
2015-07-28 00:51 - 2015-07-28 00:51 - 00112640 _____ (forum.viry.cz) C:\Users\Aleš\Desktop\FRSTLauncher.exe
2015-07-28 00:49 - 2015-07-28 00:49 - 02146816 _____ (Farbar) C:\Users\Aleš\Desktop\FRST64.exe
2015-07-25 17:32 - 2015-07-25 17:32 - 00001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk
2015-07-25 17:01 - 2015-07-25 17:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-25 16:56 - 2015-07-25 16:56 - 00001245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2015-07-25 16:56 - 2015-07-25 16:56 - 00001233 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2015-07-23 18:13 - 2015-06-29 08:31 - 00000717 _____ C:\Users\Aleš\Documents\train.cfg
2015-07-23 15:19 - 2015-07-23 15:19 - 00001205 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
2015-07-23 15:19 - 2015-07-23 15:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
2015-07-23 15:02 - 2015-07-23 15:57 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2015-07-23 14:51 - 2015-07-23 15:02 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2015-07-23 14:51 - 2015-07-23 14:51 - 00001197 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2015-07-23 14:51 - 2015-07-23 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2015-07-23 04:02 - 2015-07-28 00:59 - 00000000 ____D C:\Users\Aleš\AppData\Local\Battle.net
2015-07-23 04:02 - 2015-07-23 14:51 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Battle.net
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\Users\Aleš\AppData\Local\Blizzard Entertainment
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-07-23 04:02 - 2015-07-23 04:02 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-07-23 04:01 - 2015-07-23 04:01 - 00000000 ____D C:\ProgramData\Battle.net
2015-07-22 22:54 - 2015-07-26 01:00 - 00000000 ____D C:\Users\Aleš\AppData\Local\Spotify
2015-07-22 22:54 - 2015-07-22 23:52 - 00002043 _____ C:\Users\Aleš\Desktop\Spotify.lnk
2015-07-22 22:54 - 2015-07-22 22:54 - 00001836 _____ C:\Users\Aleš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-07-22 22:53 - 2015-07-26 00:57 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Spotify
2015-07-22 19:19 - 2015-07-22 19:19 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Wargaming.net
2015-07-22 16:03 - 2015-07-22 16:03 - 00000000 ____D C:\Users\Aleš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks
2015-07-22 03:59 - 2015-07-22 04:06 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2015-07-22 03:59 - 2015-07-22 03:59 - 00000000 ____D C:\Users\Aleš\AppData\Local\PunkBuster
2015-07-22 02:52 - 2015-07-22 02:52 - 00000000 ____D C:\Users\Aleš\AppData\Local\CEF
2015-07-21 19:49 - 2015-07-21 19:49 - 615295068 _____ C:\Windows\MEMORY.DMP
2015-07-21 19:49 - 2015-07-21 19:49 - 00280856 _____ C:\Windows\Minidump\072115-30625-01.dmp
2015-07-21 19:49 - 2015-07-21 19:49 - 00000000 ____D C:\Windows\Minidump
2015-07-21 10:33 - 2015-07-21 10:33 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-21 10:33 - 2015-07-21 10:33 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-21 10:33 - 2015-07-21 10:33 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-21 10:33 - 2015-07-21 10:33 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-21 02:41 - 2015-07-21 02:41 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client